Incident case

Butter Bridge V3.1 2026 unauthorized MAPO mint exploit

A flaw in Butter Bridge V3.1’s OmniServiceProxy cross-chain retry path was exploited, resulting in unauthorized MAPO minting on Ethereum and BNB Chain. MAP Protocol states that the flaw was isolated to the affected Butter Bridge path and did not compromise MAP mainnet consensus, native MAPO, light-client verification, Oracle multisig, or project-team keys.

reviewedcurrent

Incident facts

Incident title
Butter Bridge V3.1 2026 unauthorized MAPO mint exploit
Bridge
Butter Bridge V3.1
Incident date
2026-05-20
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, BNB Chain, Unknown
Affected assets
Unknown
Attack category
Smart Contract Bug
Reported loss
about $180,000 extracted liquidity
Amount confidence
Medium
Loss amount basis
Reported By Security Firm
Recovery
Unknown
Reimbursement
Announced
Restart
Unknown
Current outcome
Limited After Incident
Postmortem
Unclear
Resolution
Unresolved
Last reviewed
2026-09-01
Last verified
2026-09-01

Amount and valuation

Security reporting estimates roughly $180,000 of liquidity was extracted after the unauthorized mint. The enormous notional quantity of unauthorized MAPO minted is not treated as equivalent to realized USD loss.

Keep unauthorized minted quantity, realized liquidity extraction, and compensation scope separate.

Why this remains unresolved

Timeline events

  • Butter Bridge V3.1 unauthorized MAPO mint2026-05-20

    The affected OmniServiceProxy cross-chain path was manipulated, resulting in unauthorized MAPO minting on Ethereum and BNB Chain.

    Exploit OccurredHigh

    MAP mainnet consensus and the other explicitly excluded core components are not marked compromised.

  • Butter cross-chain service suspended for remediation2026-05-20

    MAP Protocol reported that the affected Butter cross-chain service was suspended while containment, tracing, audited-contract deployment and user-protection work proceeded.

    Bridge PausedHigh

    Later audited-contract deployment does not automatically establish full unrestricted reopening.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.