Minterest hack — July 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 14, 2024 |
| Target type | Lending protocol |
| Loss | $1,400,000Price at time of incident |
| Method | ReentrancyReentrancy into lendRUSDY combined with an exchange rate that updated immediately after a borrow. The attacker took a flash loan of 4.265 million USDY from an external AGNI pool, then borrowed roughly 392,773 USDY through Minterest's own flashLoan function to move the exchange rate; transferring the borrowed tokens lowered the market's cash balance and shifted the rate mid-transfer, and re-entering at the depressed rate minted more mTokens than the deposit justified. Withdrawing the underlying at the correct rate left surplus unbacked mTokens, which were then used as collateral to borrow WETH and mETH. |
| Chains | Other |
| Outcome | Users reimbursed |
What happened
Minterest, a cross-chain lending protocol, lost about $1.4 million on 14 July 2024 in an attack on its mUSDY market on Mantle Network. The project's own post-mortem places the exploit between 16:24 and 16:28 UTC+3, a window of about four minutes.
The attacker took a flash loan of 4.265 million USDY from an AGNI pool and, separately, borrowed roughly 392,773 USDY through Minterest's own flashLoan function to move the exchange rate, then reentered through the lendRUSDY function. Transferring the borrowed tokens lowered the market's cash balance and shifted the exchange rate mid-transfer; re-entering at the depressed rate minted more mTokens than the deposit warranted, and withdrawing the underlying at the correct rate left surplus mTokens with nothing behind them. Minterest says the cycle ran 25 times, building roughly $1.7 million of position value in the USDY market, which was then borrowed against to remove $1.4 million of WETH and mETH. Halborn's independent write-up describes the same two defects: an exchange rate updated immediately after a borrow, and a reentrancy that allowed previously borrowed tokens to be lent back.
Minterest identifies the attacking wallet and the exploit transaction, says the wallet was funded through Tornado Cash, and reports the proceeds were bridged from Mantle to Ethereum via Stargate and converted to ETH through Squid Router. Deployments on Ethereum and Taiko were unaffected.
The protocol suspended operations across chains, flagged the wallet with exchanges and Etherscan, and engaged SEAL 911 and BlockSec. It applied a 15% reduction to WETH and mETH supply balances to account for the stolen funds, refunded liquidation fees by 24 July, and compensated affected suppliers with discounted MINTY tokens vesting 20% at listing and 80% over six months, alongside a 40% boost to MNT and MINTY emissions for three months for suppliers holding over $50 before the exploit.
Sources
- MinterestPrimary · retrieved 2026-08-01
- Minterest documentationPrimary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://minterest.com/blog/minterest-security-incident-post-mortem-report/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Minterest hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/minteresthttps://itokenly.com/hacks/minterestPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.