Incident case

Nerve Bridge 2021 metapool exploit

An attacker exploited an inconsistent exchange-amount calculation in Saddle-derived metapool code used by Nerve Bridge. BlockSec reported that the fUSDT and UST pools were drained and that the attacker gained approximately 900 BNB.

reviewedcurrent

Incident facts

Incident title
Nerve Bridge 2021 metapool exploit
Bridge
NerveNetwork
Incident date
2021-11-15
Incident type
Metapool Exploit
Major incident
Yes
Affected chains
BNB Chain, NerveNetwork
Affected assets
fUSDT, UST, BNB
Attack category
Metapool Exchange Amount Calculation Bug
Reported loss
Approximately 900 BNB attacker profit
Amount confidence
Medium
Loss amount basis
Independent BlockSec Technical Analysis
Recovery
Unknown
Reimbursement
Unknown
Restart
Unknown
Current outcome
Protocol Active After Incident
Postmortem
None
Resolution
Unresolved
Last reviewed
2026-06-16
Last verified
2026-06-16

Amount and valuation

BlockSec reported that the attacker exhausted the affected fUSDT and UST pool liquidity and gained approximately 900 BNB.

The canonical amount remains denominated in BNB because no reviewed official incident statement supplied a fixed fiat loss value.

Why this remains unresolved

Timeline events

  • Nerve Bridge metapools exploited2021-11-15

    An attacker exploited the fUSDT and UST metapools on BNB Chain, exhausted their liquidity, and gained approximately 900 BNB according to BlockSec.

    Metapool ExploitHigh
  • BlockSec published Nerve Bridge root-cause analysis2021-11-18

    BlockSec attributed the incident to an inconsistent exchange-amount calculation in a Saddle-derived metapool implementation and compared it with the earlier Synapse vulnerability.

    Root Cause Analysis PublishedHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.