Nerve Bridge 2021 metapool exploit
An attacker exploited an inconsistent exchange-amount calculation in Saddle-derived metapool code used by Nerve Bridge. BlockSec reported that the fUSDT and UST pools were drained and that the attacker gained approximately 900 BNB.
Incident facts
- Incident title
- Nerve Bridge 2021 metapool exploit
- Bridge
- NerveNetwork
- Incident date
- 2021-11-15
- Incident type
- Metapool Exploit
- Major incident
- Yes
- Affected chains
- BNB Chain, NerveNetwork
- Affected assets
- fUSDT, UST, BNB
- Attack category
- Metapool Exchange Amount Calculation Bug
- Reported loss
- Approximately 900 BNB attacker profit
- Amount confidence
- Medium
- Loss amount basis
- Independent BlockSec Technical Analysis
- Recovery
- Unknown
- Reimbursement
- Unknown
- Restart
- Unknown
- Current outcome
- Protocol Active After Incident
- Postmortem
- None
- Resolution
- Unresolved
- Last reviewed
- 2026-06-16
- Last verified
- 2026-06-16
Amount and valuation
BlockSec reported that the attacker exhausted the affected fUSDT and UST pool liquidity and gained approximately 900 BNB.
The canonical amount remains denominated in BNB because no reviewed official incident statement supplied a fixed fiat loss value.
approximately 900 BNB attacker profit
Attacker profit and exhausted pool liquidity are not assumed to be identical accounting measures.
Why this remains unresolved
- A stable official postmortem, reimbursement statement, and final pool-restoration outcome were not located in the reviewed sources.
Timeline events
Nerve Bridge metapools exploited2021-11-15
An attacker exploited the fUSDT and UST metapools on BNB Chain, exhausted their liquidity, and gained approximately 900 BNB according to BlockSec.
BlockSec published Nerve Bridge root-cause analysis2021-11-18
BlockSec attributed the incident to an inconsistent exchange-amount calculation in a Saddle-derived metapool implementation and compared it with the earlier Synapse vulnerability.
Evidence records
- The Analysis of Nerve Bridge Security IncidentBlockSec · Tier 2 · High reliability · secondary · 2021-11-18Claim scope: Incident Case
Primary reviewed technical source for the 900 BNB amount and root cause.
- Explained: The Synapse and Nerve Bridge HacksHalborn · Tier 2 · High reliability · secondary · 2021-11-24Claim scope: Root Cause
Independent comparison of the Synapse and Nerve metapool attacks.
- Explained: The Synapse and Nerve Bridge HacksHalborn · Tier 2 · High reliability · secondary · 2021-11-24Claim scope: Incident Case
Event-scoped duplicate independently supporting the Nerve metapool exploit and amount.
- The Analysis of Nerve Bridge Security IncidentBlockSec · Tier 2 · High reliability · secondary · 2021-11-18Claim scope: Root Cause
Event-scoped duplicate supporting the inconsistent exchange-amount calculation root cause.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact user-loss allocation and final reimbursement outcome remain unverified.
- The exact restart date for the affected pools was not established.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.