T
iTokenly

Meter Passport hack — February 2022

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 5, 2022
Target typeCross-chain bridge
Loss$4,400,000Published estimates range $4,250,000 to $7,700,000Price at time of incident
MethodContract logic errorMissing validation in the ERC20 handler's deposit method. Meter Passport, a fork of ChainSafe's ChainBridge, added automatic wrapping and unwrapping of native gas tokens and assumed that a token identified as a wrapped native token did not need to be burned or locked on deposit. The intended entry point, depositEth, verified that the amount declared in the calldata matched the value actually sent; the underlying generic deposit function was publicly callable and performed no such check. Calling it directly with an arbitrary declared amount caused the bridge to release or mint unbacked assets on the destination chain.
ChainsBNB Chain, Ethereum, Other
OutcomeUsers reimbursed

What happened

Meter Passport, the cross-chain bridge operated by Meter.io, was exploited on 5 February 2022 beginning at 14:30 UTC. The bridge was a fork of ChainSafe's ChainBridge, modified to wrap and unwrap native gas tokens automatically. The modified ERC20 handler assumed that a token identified as a wrapped native token did not need to be burned or locked when deposited. The intended entry point, depositEth, checked that the amount declared in the calldata matched the value actually sent; the underlying generic deposit function was publicly callable and did not. The attacker called it directly with an arbitrary declared amount, causing the bridge to release or mint assets it had never received: per Meter's post-mortem, 3,632.8 BNB were taken from BNB Chain and 422.5 ETH from Ethereum, while 30,000 BNB.bsc were minted on Moonriver and 1,500 WETH.eth on Meter's own network. Meter paused the bridge by 16:00 UTC. PeckShield traced 1,391 ETH and 2.74 wBTC into Tornado Cash.

The size of the loss is reported inconsistently. Meter's post-mortem sets its own liability at $4.25 million, and it issued PASS tokens, each representing one dollar of loss, redeemable in MTRG against foundation revenue; a March 2022 governance vote switched compensation to USD terms. Contemporary reporting put the bridge drain at $4.4 million.

Selling the minted BNB on SushiSwap crashed the BNB price on Moonriver by about 77%. Separate users then bought the discounted tokens and borrowed against them on Hundred Finance, which was still pricing BNB from Chainlink. Meter's post-mortem records two users taking loans this way: the first returned the majority of the funds, while the second took 1.9 million FRAX. Meter puts the total knock-on loss at Hundred Finance at $2.135 million; Cointelegraph and Halborn put it at $3.3 million. Halborn and Cointelegraph describe the combined damage across Meter and Hundred Finance as $7.7 million.

Law enforcement

Meter's post-mortem says it engaged security consultants and law enforcement; no agency was named and no action has been reported.

Sources

  1. Meter.ioPrimary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/meter-io/post-mortem-report-meter-passport-12af6b50393d

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Meter Passport hack — February 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/meter-passport
https://itokenly.com/hacks/meter-passport

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.