Meter Passport 2022 false-deposit exploit
An attacker directly called a modified ERC-20 deposit handler that failed to verify the transaction value, enabling unbacked BNB and WETH minting and withdrawal of bridge reserves across multiple networks.
Incident facts
- Incident title
- Meter Passport 2022 false-deposit exploit
- Bridge
- Meter Passport
- Incident date
- 2022-02-05
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Meter, Ethereum, BNB Chain, Unknown
- Affected assets
- BNB, WETH
- Attack category
- Smart Contract Bug
- Reported loss
- $4.25 million official estimate; about $4.4 million secondary estimate
- Amount confidence
- High
- Loss amount basis
- Official Postmortem Prioritized With Independent Security Estimate Retained
- Recovery
- Unknown
- Reimbursement
- In Progress
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Full
- Resolution
- Unresolved
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
Meter's postmortem allocated $4.25 million of direct liabilities; independent security reporting commonly described approximately $4.4 million drained from the bridge.
The larger figure reflects rounded external reporting. Secondary losses at Hundred Finance are not added to the direct Meter Passport amount.
direct bridge liabilities$4.25 million
Canonical direct-loss figure.
bridge assets drainedapproximately $4.4 million
Retained as rounded secondary estimate.
Why this remains unresolved
- The final amount repurchased or paid against PASS-token liabilities is not established in this seed record.
Timeline events
Meter Passport false-deposit exploit disclosed2022-02-05
Meter identified unauthorized minting and reserve depletion affecting BNB and WETH representations across connected networks.
Postmortem and compensation plan published2022-02-18
Meter documented the false-deposit flaw and proposed PASS-token liabilities representing $4.25 million in compensation claims.
PASS compensation tokens distributed2022-04-03
Meter updated the postmortem to state that PASS liability tokens had been distributed to affected users under the approved compensation structure.
Distribution of liability tokens is not treated as proof that all liabilities were repaid in cash or recovered assets.
Audited Meter Passport v1.5 went live2022-10-10
Meter reported that an audited replacement version of Meter Passport had gone live after the exploit response and redesign work.
Current documentation now describes Meter Passport V2.0. Event type normalized from legacy descriptive value bridge_upgrade.
Evidence records
- Post Mortem Report — Meter PassportMeter.io · Tier 1 · High reliability · primary · 2022-02-18Claim scope: Incident Case
Primary postmortem for the exploit, $4.25 million liability allocation, compensation design, and restoration plan.
- The Meter Monthly — February 2022Meter.io · Tier 1 · High reliability · primary · 2022-03-08Claim scope: Reimbursement
Official monthly update describing the exploit response, restoration work, and governance compensation process.
- Explained: The Meter.io Hack (February 2022)Halborn · Tier 1 · High reliability · secondary · 2022-02-08Claim scope: Amount
Independent security analysis supporting the false-deposit mechanism and approximately $4.4 million estimate.
- Meter Passport v1.5 completes a rigorous Audit by HAECHIMeter.io · Tier 1 · High reliability · primary · 2022-10-10Claim scope: Restart
Primary source for the audited replacement implementation and restored operation.
- Post Mortem Report — Meter PassportMeter.io · Tier 1 · High reliability · primary · 2022-02-18Claim scope: Incident Case
Event-scoped duplicate of bir_src_000048: the primary postmortem supports the Meter Passport exploit mechanism, liability amount, shutdown, and response; the original record remains attached to bir_ev_000036.
- Post Mortem Report — Meter PassportMeter.io · Tier 1 · High reliability · primary · 2022-02-18Claim scope: Reimbursement
Event-scoped duplicate of bir_src_000048: the primary postmortem supports the PASS compensation structure and distribution context; the original record remains incident-scoped to bir_ev_000036.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final compensation completion requires later review.
- Secondary losses at Hundred Finance are tracked as downstream impact rather than direct bridge loss.
Conflicting claims
Direct incident amount
Reported values: $4.25 million official liability allocation · Approximately $4.4 million independent estimate
Current treatment: Use $4.25 million as the canonical direct-loss amount and retain $4.4 million as the rounded secondary estimate.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.