Visualização de leitura

Hackers Exploit Butter Network Bridge to Mint Massive MAPO Supply

MAPO token

The cryptocurrency market witnessed another major security breach this week after the MAPO token collapsed by 96% following an exploit tied to the Butter Network cross-chain bridge. The incident resulted in the unauthorized minting of a quadrillion MAPO tokens, flooding the market with a supply vastly larger than the legitimate circulating amount and causing severe disruption across decentralized finance ecosystems connected to ETH and other blockchains.  According to blockchain security researchers, the exploit enabled the attacker to generate tens of thousands of times more MAPO tokens than the official supply. As panic selling intensified, the price of the Map Protocol token dropped from nearly $0.003 to around $0.0001 within hours, based on market tracking data from CoinGecko. 

Attacker Drains ETH From Liquidity Pools 

The attack primarily targeted the Butter Network bridge infrastructure, a cross-chain protocol associated with Map Protocol. Security platform Blockaid reported that the exploiter used a newly created externally-owned account (EOA) to offload approximately one billion MAPO tokens into decentralized exchanges.  During the process, the attacker reportedly drained nearly 52 ETH from Uniswap liquidity pools, an amount valued at roughly $180,000 at the time of the incident. Despite the liquidation of a portion of tokens, blockchain analysts noted that the attacker still retained close to a trillion MAPO tokens.  Those remaining holdings continue to create risks for additional liquidity pools and potential exchange listings linked to the Map Protocol token ecosystem. The sudden flood of tokens severely impacted market confidence and highlighted ongoing vulnerabilities within cross-chain bridge infrastructure. 

MAPO Exploit Adds to Growing List of DeFi Attacks 

The exploit comes during an already damaging month for decentralized finance projects. Reports indicate that at least 18 DeFi and blockchain protocols have been compromised in recent weeks. Among the affected projects are THORChain, Verus Protocol, Transit Finance, TrustedVolumes, Ekubo, Echo Protocol, and RetoSwap.  The repeated attacks have intensified concerns surrounding interoperability protocols, especially those handling assets across ETH, Bitcoin, and other blockchain ecosystems. Cross-chain bridges remain frequent targets because of the complexity involved in validating transactions between multiple networks. 

Map Protocol Pauses Mainnet Operations 

In response to the breach, Map Protocol confirmed that the vulnerability originated in the Solidity contract layer. The project announced that it had paused its mainnet and initiated a migration process while the investigation continues. Butter Network also suspended ButterSwap operations, although the team stated that user funds were not directly at risk. In its latest statement, the Map Protocol team said it would announce a new contract address and later conduct an asset snapshot. The project added that “any remaining tokens held by attacker-controlled addresses will be fully invalidated and will not be included in any future snapshot or conversion process.” Blockchain data further revealed that approximately one billion MAPO tokens were transferred to Uniswap shortly after the quadrillion-token mint occurred.

How the MAPO Mint Exploit Happened 

Security researchers later outlined how the attack unfolded. According to Blockaid, the attacker initially submitted a legitimate oracle multisig-signed message before deploying a malicious smart contract at a carefully chosen address. The exploiter then resent a modified “retry” message that appeared identical in transaction hash but had actually been manipulated. Because the cross-chain bridge incorrectly verified the altered message as authentic, the system approved the minting of the massive MAPO supply. Researchers stressed that no private keys were stolen and no light clients were compromised during the attack. Instead, the incident was described as a “classic Solidity vulnerability involving multiple dynamic fields.”  The exploit once again demonstrated how weaknesses in smart contract validation can place both MAPO and ETH liquidity ecosystems at risk.

Litecoin Hit by Zero-Day Vulnerability, Triggers 13-Block Reorganization

Litecoin Network

The Litecoin network faced a security breach when a zero-day vulnerability triggered a 13-block reorganization, impacting several major mining pools. This disruption led to a temporary halt in transaction finality, drawing attention to the potential risks within the Litecoin ecosystem. The Litecoin team quickly confirmed the bug on their official X account and assured the community that a patch had been fully deployed to resolve the issue. 

The Zero-Day Bug and Its Impact on the Litecoin Network 

A zero-day vulnerability refers to a flaw that is unknown to the developers at the time of its exploitation. In this case, the bug targeted the handling of MimbleWimble Extension Block (MWEB) transactions, a privacy feature on the Litecoin network. The vulnerability allowed an attacker to exploit the network by triggering a Denial-of-Service (DoS) attack, flooding the network with invalid MWEB transactions. MWEB transactions are designed to offer enhanced privacy for Litecoin users by obscuring transaction details. However, due to the zero-day bug, some Litecoin nodes that had not updated their software accepted invalid MWEB transactions, violating the network’s consensus rules. As a result, a block reorganization (or “reorg”) took place when a competing chain of blocks replaced the existing chain, causing 13 blocks to be reorganized. A block reorg of this magnitude is a rare event and presents significant challenges, including the potential for double-spending and undermined user confidence.

Understanding the Denial-of-Service Attack and Its Impact on Miners 

The core target of the attack was the mining pools, which play a critical role in securing the Litecoin network. Mining pools are groups of miners who pool their computational power to increase their chances of successfully finding a block. By launching a DoS attack, the attacker aimed to disrupt the mining process by overwhelming the network with invalid transactions. The impact on miners was particularly severe. Mining pools that failed to update their nodes were unable to process valid blocks during the attack. This resulted in temporary downtime for these pools, contributing to a short-term drop in the network’s hashrate. While the Litecoin network quickly recovered, the event highlighted the vulnerability of mining operations when software updates are delayed or ignored.

Quick Response and Deployment of the Patch 

Despite the severity of the incident, the Litecoin team responded promptly. Within hours, the development team confirmed the bug and rolled out a patch that effectively closed the attack vector. The patch prevented nodes from accepting invalid MWEB transactions, thus stabilizing the network and mitigating further risks. The team urged all node operators to update their software immediately to ensure the security of their operations. Importantly, the Litecoin team confirmed that no funds were lost as a result of the reorganization. While users’ transactions that were part of the reorganized blocks were reversed, the overall integrity of the network remained intact. The incident, although disruptive, demonstrated the resilience and quick action of the Litecoin team.

The Role of MWEB and Zero-Day Bugs 

Launched in 2011, Litecoin has earned a reputation as one of the oldest and most stable cryptocurrencies. As a fork of Bitcoin, it relies on a proof-of-work consensus mechanism to validate transactions. Over the years, Litecoin has faced relatively few security incidents, but the April 25 event serves as a stark reminder that even established networks are susceptible to vulnerabilities.  The introduction of MWEB in 2022 marked a significant upgrade for Litecoin, providing users with enhanced privacy features. However, as seen with this recent zero-day vulnerability, new features can also introduce unforeseen risks

Indian Agency Arrests Key SIM Card Supplier of a Broader Cyber Fraud Network

CBI, Cyber Fraud Network, Chakra-V, SIM Card, Operation Chakra, Covid-19, Fraud

India’s top intelligence agency arrested a suspected key conspirator accused of supplying fraudulently obtained SIM cards to cybercriminal networks, as part of the agency’s ongoing anti-cybercrime initiative, Operation Chakra-V.

According the Central Bureau of Investigation (CBI), the suspect was apprehended in the North Eastern city of Guwahati after allegedly evading authorities since August 2025. Investigators say the accused played a central role in procuring and distributing illegally issued mobile SIM cards that were later used in a range of cyber-enabled fraud schemes.

Also read: CBI Files Chargesheet Against 30 Including Two Chinese Nationals in ₹1,000 Cr Cyber Fraud Network

The law enforcement agencies are now increasingly focusing on the infrastructure that enables digital crime rather than only the individuals carrying out the scams. Fraudulently acquired SIM cards are a valuable tool for cybercriminals because they can be used to create anonymous accounts, bypass identity checks, receive one-time passwords (OTPs), and operate scam call centers with reduced traceability.

The CBI said its broader investigation uncovered a network involving Point of Sale (POS) agents who allegedly issued SIM cards using fake or improperly verified customer identities. These SIM cards were then reportedly supplied to criminals linked to fake “digital arrest” extortion scams, fraudulent loan offers, and investment fraud operations.

Authorities stated that searches were previously conducted at around 45 locations across eight Indian states, resulting in the arrest of 10 accused POS agents. The latest suspect is believed to have acted as an aggregator within the network.

Also read: India Dismantles ‘Phishing SMS Factory’ Infrastructure Sending Lakhs of Fraud Messages Daily

Investigators allege the accused transferred nearly ₹67 lakh through multiple bank accounts to procure approximately 10,000 illegally issued SIM cards. Evidence related to courier shipments used for distributing the cards has also reportedly been recovered, suggesting a structured logistics chain behind the operation.

From a cybersecurity perspective, the case underscores how telecom identity abuse remains a critical threat vector. Even sophisticated fraud campaigns often depend on simple enablers such as fraudulent SIM issuance, mule bank accounts, and compromised identity records.

The CBI said investigations into additional conspirators are ongoing. As cyber fraud grows more industrialized, dismantling support networks like these may prove just as important as arresting the scammers who interact directly with victims.

Also read: 12 Lakh SIM Cards Cancelled, over 3 Lakh IMEI Numbers Blocked as Centre Intensifies Crackdown on Cybercrime
❌