Map Protocol token drops 96% after quadrillion token minting exploit

The MAPO token, belonging to the Map Protocol, suffered a 96% drop after an attacker exploited a vulnerability in the Butter Network's cross-chain bridge. The exploit allowed for the fraudulent minting of approximately one quadrillion MAPO tokens, a vastly greater amount than the legitimate supply. As a result, the token's price plummeted from around $0.003 to just $0.0001 in a matter of hours.

According to blockchain security reports, the attacker used a new external account EOA to sell around one billion MAPO tokens on Uniswap liquidity pools, managing to extract approximately 52 ETH, equivalent to about $180,000. However, the attacker still holds nearly one trillion tokens, posing a potential threat to other markets and exchanges where the token may be listed.

The vulnerability did not involve the theft of private keys or complex cryptographic flaws. Blockaid experts indicated that the issue stemmed from a classic Solidity vulnerability related to the improper validation of multiple dynamic fields within cross-chain bridge retry messages. The attacker managed to reuse and modify a seemingly valid message to deceive the system and execute the mass minting.

Following the incident, Map Protocol temporarily paused its mainnet and began a migration process while investigating the attack. Butter Network also suspended ButterSwap and assured users that their funds were not at risk. Furthermore, the project announced it would launch a new contract address and conduct an asset capture to invalidate all tokens controlled by the attacker.

This incident adds to a growing wave of attacks against DeFi and blockchain protocols recently, reflecting the ongoing security risks present in the crypto ecosystem.

Source:

Komentarze

Ładuję komentarze…