MAP Protocol hit by massive token mint exploit
MAP Protocol’s Butter Bridge exploit led to 1 quadrillion fake MAPO tokens, crashing the price by up to 95%. The protocol paused its bridge to contain the breach and protect liquidity pools.
On May 20, 2026, MAP Protocol and ButterNetwork experienced a significant security breach when attackers exploited a vulnerability in Butter Bridge V3.1’s OmniServiceProxy contract. This flaw enabled the minting of roughly 1 quadrillion counterfeit MAPO tokens—about 4.8 million times the legitimate supply. The exploit was due to a hash collision in the bridge’s retry message verification logic, allowing the attacker to create fake tokens and transfer them to a new wallet. The attacker sold around 1 billion MAPO for approximately 52.21 ETH (valued between $110,000 and $180,000), causing MAPO’s price to plummet by up to 95% and its market cap to drop below $1 million. In response, MAP Protocol paused its bridge between MAPO ERC-20 and the mainnet to contain the breach. Most counterfeit tokens remain with the attacker, posing ongoing risks to liquidity pools on both decentralized and centralized exchanges. This incident underscores persistent vulnerabilities in cross-chain bridge infrastructure.