Skip to content
All library documents

Meta Pool Exploit: Unauthorized mpETH Minting and Liquidity-Limited Losses

Article OKX Learn

Summary

The document describes a June 2025 exploit of Meta Pool, a liquid staking protocol. It says an attacker exploited a vulnerability in an ERC-4626 function associated with fast unstaking to mint mpETH without depositing collateral. The article reports that roughly $27 million worth of tokens were minted, while the attacker extracted 52.5 ETH, valued at $132,000, because liquidity in the affected pools was low.

The protocol reportedly paused the affected contract after detecting suspicious activity, limiting further minting. Meta Pool said staked ETH remained secure and pledged to reimburse affected users, with a post-mortem and recovery plan pending. The episode illustrates how a contract flaw can create a large nominal token supply while available liquidity constrains immediate realized proceeds. The document does not include transaction-level evidence, technical details of the vulnerability, or independent confirmation of the reimbursement and asset-safety claims, so those statements should be treated as reported claims rather than a complete incident analysis.

Key ideas

  • A vulnerability in the fast-unstaking path reportedly enabled mpETH minting without collateral.
  • The article reports about $27 million in unauthorized tokens minted and 52.5 ETH extracted.
  • Low pool liquidity constrained the attacker’s realized proceeds despite the much larger minted amount.
  • Pausing the affected contract reportedly stopped further unauthorized minting.
  • The article recommends audits and monitoring but provides no technical post-mortem or exploit reproduction.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.