Back to Blog
Web3 & DeFi Security

Meter's Bridge Mint Bug: $2.3M in Unbacked Tokens, an 88% Price Crash

A flawed validation check in Meter Passport let an attacker mint unbacked wrapped MTR and MTRG, dump them on a DEX, and crater both tokens — forcing the chain and bridge offline.

PyramidLedger Research4 min read
Share

Key Takeaways

  • An attacker exploited a 'block validation flaw' in Meter's cross-chain bridge (Meter Passport) to mint more than $2.3 million in unbacked wrapped MTR and MTRG.
  • Selling part of the haul on PancakeSwap crashed MTRG — and MTR, which is designed to track the cost of 10 kWh of electricity — by more than 88% each.
  • Meter paused its blockchain and bridge and warned that transactions after a specific block may not be honored, signaling a likely rollback.
  • This is Meter's second major bridge-related incident, after a roughly $4.3 million bridge attack in February 2022.

What happened

On 23-24 September 2026, security firm Blockaid flagged an ongoing exploit against Meter, a BNB Chain-connected project, in which an attacker used the project's cross-chain bridge, Meter Passport, to mint wrapped MTR and MTRG tokens with no collateral behind them. Blockaid put the notional value of the unbacked mint at roughly $2.3 million, created across about two mint transactions (Blockaid). Meter itself attributed the root cause to a "block validation flaw" — vague language that, notably, stopped short of a full technical post-mortem at the time of writing (Web3 Is Going Great).

Why the price cratered

The attacker didn't just mint the tokens — they sold a portion on PancakeSwap, a decentralized exchange on BNB Chain, immediately pressuring both sides of the token pair. MTRG's price fell by more than 88%. MTR, which is engineered to hold a stable value pegged to the cost of producing 10 kWh of electricity, dropped by roughly the same percentage, since the peg depends entirely on supply staying within the bounds the protocol controls — an unauthorized, unbacked mint breaks that assumption directly (CryptoTimes).

Meter's response

Meter paused both its mainnet and the Passport bridge and urged users to stop trading the token entirely. Its security update warned that transactions after block 100731417 may not be honored — language that points toward a planned chain rollback to unwind the exploit rather than a simple patch-and-resume (Web3 Is Going Great).

This is not Meter's first bridge incident. The project suffered an earlier bridge attack in February 2022 that cost roughly $4.3 million (Web3 Is Going Great).

The practitioner takeaway

Bridges remain one of the most consistently attacked components in Web3 because minting on the destination chain and locking/burning on the source chain are two separate state machines that must agree perfectly, every time, under adversarial conditions. A "validation flaw" in that mint path is functionally the same bug class behind several of the largest bridge hacks to date: the destination side accepted a mint instruction it should have rejected.

  • Mint authorization logic needs the same scrutiny as fund-custody logic — a bug that lets you print tokens is as dangerous as one that lets you drain a vault.
  • Real-time on-chain monitoring (as Blockaid demonstrated here) matters because it can catch anomalous minting while an exploit is still unfolding, not just after the fact.
  • A chain-level pause plus a threatened rollback is a heavy remedy — it trades off immutability guarantees against loss recovery, and users and integrators should understand that trade-off before treating any chain's finality as absolute.
  • Repeat bridge incidents on the same project are a signal worth weighing independently of any single post-mortem's root-cause explanation.

FAQ

Frequently Asked Questions

What actually let the attacker mint unbacked tokens?

Meter has attributed the exploit to a 'block validation flaw' in its Meter Passport bridge, which allowed the attacker to mint wrapped MTR and MTRG without the collateral or lock/burn event that should normally back that mint. Meter had not published a full technical post-mortem at the time of writing.

Why did MTR crash if it's supposed to track a stable electricity-cost peg?

MTR's peg depends on supply staying within limits the protocol controls. An unauthorized mint injects unbacked supply directly into circulation, and once part of that supply was sold on PancakeSwap, the resulting price pressure broke the peg — MTR fell by roughly the same margin as MTRG.

Is this the first time Meter's bridge has been attacked?

No. Meter suffered an earlier bridge attack in February 2022 that cost roughly $4.3 million, making this the project's second major bridge-related incident.

Sources

  1. 1Meter token prices crash after unauthorized mint — Web3 Is Going Great
  2. 2Blockaid detected an ongoing exploit on Meter_IO on BNB Chain — Blockaid (X/Twitter)
  3. 3Meter Passport Exploit Reportedly Mints $2.3 Million in Unbacked MTRG — CryptoTimes
Share

Read next