The cryptocurrency market witnessed another major security breach this week, as the MAPO token crashed by 96% following an exploit linked to the Butter Network. The incident led to the unauthorized creation of a quadrillion MAPO tokens, flooding the market with a supply far in excess of the legal circulating supply and causing severe disruption to decentralized finance ecosystems connected to ETH and other blockchains.
See also: FBI: Possible threat from ShinyHunters after Canvas breach

According to blockchain security researchers, the exploit allowed the attacker to create tens of thousands of times more MAPO tokens than the official supply. As the sale intensified, the price of the Map Protocol token fell from nearly $0.003 to around $0.0001 within hours, according to market-tracking data from CoinGecko.
The attack primarily targeted the infrastructure of the Butter Network bridge, a cross-chain protocol connected to the Map Protocol. Security platform Blockaid reported that the exploiter used a newly created externally controlled account (EOA) to offload approximately one billion MAPO tokens to decentralized exchanges.
During the process, the attacker reportedly drained nearly 52 million ETH from Uniswap’s liquidity pools, an amount valued at approximately $180,000 at the time of the incident. Despite liquidating some of the tokens, blockchain analysts noted that the attacker still retained nearly a trillion MAPO tokens.
These remaining holdings continue to pose risks to additional liquidity pools and potential exchange listings associated with the Map Protocol token ecosystem. The sudden flood of tokens severely impacted market confidence and highlighted ongoing vulnerabilities in the cross-chain bridge infrastructure.
See also: WordPress: Hackers exploit Burst Statistics vulnerability

The exploit comes during an already disastrous month for decentralized finance projects. Reports indicate that at least 18 DeFi and blockchain protocols have been compromised in recent weeks. Among the affected projects are THORChain, Verus Protocol, Transit Finance, TrustedVolumes, Ekubo, Echo Protocol , and RetoSwap.
Repeated attacks have heightened concerns around interoperability protocols, especially those that handle assets across ETH, Bitcoin, and other blockchain ecosystems. Cross-chain bridges remain frequent targets due to the complexity involved in validating transactions across multiple networks.
How the MAPO Mint Exploitation Happened
Security researchers later described how the attack unfolded. According to Blockaid, the attacker first submitted a valid multisig oracle before deploying a malicious smart contract to a carefully chosen address.
The exploiter then resent a modified “retry” message that appeared identical to the transaction hash but had in fact been manipulated. Because the cross-chain bridge incorrectly verified the modified message as authentic, the system approved the creation of the MAPO bulk supply.
The researchers stressed that no private keys were stolen and no light clients were compromised in the attack. Instead, the incident was described as “a classic Solidity vulnerability involving multiple dynamic fields.”
See also: Latvian hacker convicted for participating in Ransomware campaign

The exploit again demonstrated how weaknesses in smart contract validation can compromise both the MAPO and ETH liquidity ecosystems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
