Incident case

Meter Passport 2022 false-deposit exploit

An attacker directly called a modified ERC-20 deposit handler that failed to verify the transaction value, enabling unbacked BNB and WETH minting and withdrawal of bridge reserves across multiple networks.

reviewedcurrent

Incident facts

Incident title
Meter Passport 2022 false-deposit exploit
Bridge
Meter Passport
Incident date
2022-02-05
Incident type
Exploit
Major incident
Yes
Affected chains
Meter, Ethereum, BNB Chain, Unknown
Affected assets
BNB, WETH
Attack category
Smart Contract Bug
Reported loss
$4.25 million official estimate; about $4.4 million secondary estimate
Amount confidence
High
Loss amount basis
Official Postmortem Prioritized With Independent Security Estimate Retained
Recovery
Unknown
Reimbursement
In Progress
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Full
Resolution
Unresolved
Last reviewed
2026-06-15
Last verified
2026-06-15

Amount and valuation

Meter's postmortem allocated $4.25 million of direct liabilities; independent security reporting commonly described approximately $4.4 million drained from the bridge.

The larger figure reflects rounded external reporting. Secondary losses at Hundred Finance are not added to the direct Meter Passport amount.

Why this remains unresolved

Timeline events

  • Meter Passport false-deposit exploit disclosed2022-02-05

    Meter identified unauthorized minting and reserve depletion affecting BNB and WETH representations across connected networks.

    Exploit DisclosedHigh
  • Postmortem and compensation plan published2022-02-18

    Meter documented the false-deposit flaw and proposed PASS-token liabilities representing $4.25 million in compensation claims.

    Postmortem And Compensation PlanHigh
  • PASS compensation tokens distributed2022-04-03

    Meter updated the postmortem to state that PASS liability tokens had been distributed to affected users under the approved compensation structure.

    Compensation Instrument DistributedHigh

    Distribution of liability tokens is not treated as proof that all liabilities were repaid in cash or recovered assets.

  • Audited Meter Passport v1.5 went live2022-10-10

    Meter reported that an audited replacement version of Meter Passport had gone live after the exploit response and redesign work.

    Bridge ReopenedHigh

    Current documentation now describes Meter Passport V2.0. Event type normalized from legacy descriptive value bridge_upgrade.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Conflicting claims

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.