Butter Bridge V3.1 2026 unauthorized MAPO mint exploit
A flaw in Butter Bridge V3.1’s OmniServiceProxy cross-chain retry path was exploited, resulting in unauthorized MAPO minting on Ethereum and BNB Chain. MAP Protocol states that the flaw was isolated to the affected Butter Bridge path and did not compromise MAP mainnet consensus, native MAPO, light-client verification, Oracle multisig, or project-team keys.
Incident facts
- Incident title
- Butter Bridge V3.1 2026 unauthorized MAPO mint exploit
- Bridge
- Butter Bridge V3.1
- Incident date
- 2026-05-20
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain, Unknown
- Affected assets
- Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- about $180,000 extracted liquidity
- Amount confidence
- Medium
- Loss amount basis
- Reported By Security Firm
- Recovery
- Unknown
- Reimbursement
- Announced
- Restart
- Unknown
- Current outcome
- Limited After Incident
- Postmortem
- Unclear
- Resolution
- Unresolved
- Last reviewed
- 2026-09-01
- Last verified
- 2026-09-01
Amount and valuation
Security reporting estimates roughly $180,000 of liquidity was extracted after the unauthorized mint. The enormous notional quantity of unauthorized MAPO minted is not treated as equivalent to realized USD loss.
Keep unauthorized minted quantity, realized liquidity extraction, and compensation scope separate.
realized liquidity extraction after unauthorized MAPO mintabout $180,000
Secondary security-firm estimate; notional unauthorized MAPO supply is not a USD loss proxy.
Why this remains unresolved
- Final attacker-fund recovery is not established.
- MAP Protocol announced a Foundation-funded protection and compensation framework, but completion is not established.
- Deployment of new audited contracts does not by itself establish unrestricted reopening of the affected V3.1 service.
Timeline events
Butter Bridge V3.1 unauthorized MAPO mint2026-05-20
The affected OmniServiceProxy cross-chain path was manipulated, resulting in unauthorized MAPO minting on Ethereum and BNB Chain.
MAP mainnet consensus and the other explicitly excluded core components are not marked compromised.
Butter cross-chain service suspended for remediation2026-05-20
MAP Protocol reported that the affected Butter cross-chain service was suspended while containment, tracing, audited-contract deployment and user-protection work proceeded.
Later audited-contract deployment does not automatically establish full unrestricted reopening.
Evidence records
- SlowMist Hacked — Butter BridgeSlowMist · Tier 2 · High reliability · secondary · 2026-05-20Claim scope: Amount
Security-firm database corroboration for the Butter Bridge V3.1 exploit and approximately $180K realized liquidity extraction. The notional unauthorized MAPO mint is not treated as realized USD loss.
- Official statement on the MAPO security incidentMAP Protocol · Tier 1 · High reliability · primary · 2026-05-21Claim scope: Incident Case
Syndicated copy preserving MAP Protocol’s first-party statement that Butter Bridge V3.1 was exploited on May 20, causing unauthorized MAPO minting on Ethereum and BSC, while MAP Protocol mainnet consensus and light-client verification were unaffected.
- Official statement on the MAPO security incidentMAP Protocol · Tier 1 · High reliability · primary · 2026-05-21Claim scope: Incident Case
Same first-party statement, linked directly to the exploit event so event-level primary-source coverage remains explicit.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final realized loss beyond the independently reported liquidity extraction is not normalized.
- Final reimbursement and restart outcomes remain unresolved.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.