Meter Faces Ongoing Exploit on BNB Chain
TREE NEWS reports: Meter, a multi-chain infrastructure protocol that bridges its native MTRG token across networks, is currently under an active and ongoing exploit on BNB Chain. An attacker has leveraged Meter Passport — the protocol’s cross-chain bridge — to mint large quantities of wrapped MTRG (wMTRG) without corresponding collateral backing, then liquidated portions of the ill-gotten tokens on PancakeSwap.
Roughly $2.3 million worth of unbacked wrapped MTRG has been minted across approximately two minting transactions, and the attack is reportedly still in progress. Because wrapped assets are supposed to be 1:1 backed by tokens locked in the bridge contract, the minted wMTRG represents a direct liability with no reserve behind it.
Why Bridge Exploits Keep Happening
Cross-chain bridges remain among the most consistently targeted components in DeFi. They concentrate enormous value in a single contract and often rely on complex verification logic — signature schemes, light clients, or validator sets — that can be manipulated if a key is compromised or a validation check is flawed. Meter Passport’s minting function appears to have been abused to create tokens out of thin air, a classic failure mode that echoes earlier incidents across the bridge landscape.
- Mint-and-dump mechanics: The attacker mints unbacked wMTRG, then swaps it into stablecoins or other liquid assets on a DEX before the market reprices.
- Contagion risk: Liquidity providers on PancakeSwap who supplied the counterparty side of the trades absorb losses as the token’s value collapses.
- Ongoing threat: Because the exploit is described as continuous, further minting could still be occurring, meaning the final damage figure may rise.
Implications for DeFi and the Broader Market
The incident underscores a structural problem: bridge security has not kept pace with the value flowing through these systems. For Meter holders, the immediate concern is whether the protocol can halt the minting function, whether reserves exist to make affected users whole, and how the MTRG price will respond once the market fully digests the dilution. For the wider DeFi ecosystem, it is another reminder that composability cuts both ways — a compromised bridge can push bad debt into lending markets and DEX pools far beyond the original protocol.
Investors and integrators should watch for whether Meter pauses the bridge, whether any emergency governance or rescue plan emerges, and whether the attacker’s addresses are flagged by analytics firms. The episode also strengthens the case for bridges that use rate-limiting, mint caps, and independent monitoring — controls that could have capped losses before $2.3 million left the system.
What to Watch Next
The key questions are whether the exploit is contained, how much additional wMTRG may still be minted, and whether centralized exchanges blacklist the attacker’s funds. Until the minting vector is closed, the risk of further dilution remains live, and the incident will likely feed ongoing regulatory scrutiny of cross-chain infrastructure and the standards governing bridge reserve attestation.




