A new security incident has occurred in the cryptocurrency sector. According to a statement by the security company BlockAid, the Meter Passport bridge in the Meter.io ecosystem was attacked, and the attackers minted approximately $2.3 million worth of wMTRG on the $BNB Chain, which has no real backing.

Initial findings indicate that attackers minted a large amount of uncollateralized wrapped MTRG (wMTRG) using a cross-chain bridging mechanism. It was noted that some of the tokens produced were sold via PancakeSwap, and the attack was reportedly carried out through approximately two transactions in its initial phase.

Meter.io stated that the incident was not limited to the bridge on the $BNB Chain, but involved an abuse of a block validation vulnerability on the Meter mainnet. According to the project, the attack began on September 23 at 18:14. The attacker exploited the vulnerability to create worthless MTR and MTRG tokens, sold them on decentralized exchanges, and transferred some of the proceeds to other networks.

As a security measure, bridge operations on the Meter mainnet have been temporarily suspended. The team requests that users refrain from conducting any transactions on the Meter network until further notice; including sending, exchanging, or transferring MTR or MTRG via the bridge.

Meter.io also warned users against buying MTR or MTRG through exchanges and DEXs. The project explained that transactions made after block number 100731417 may not be considered valid in the recovery process.

The team reported that the current state of the supply chain has been secured, but the method for recovering the assets has not yet been finalized. They stated that they are in contact with central exchanges to work on suspending MTR and MTRG deposit and withdrawal transactions.

The project team stated that they are working with exchanges, security companies, and law enforcement to track the attacker’s funds and freeze any possible assets.

On the other hand, Meter.io also made a notable offer to the attacker. It was stated that if the attacker returned the stolen funds to the specified address within 72 hours, the incident would be considered a “white hat” recovery operation and a 10% reward would be given. After the deadline, all available legal avenues would be pursued.

*This is not investment advice.