Meter said on February 5, 2022 that it had halted Meter Passport after an attacker exploited its cross-chain bridge, created unbacked representations of BNB and wrapped ether, and depleted reserves supporting those assets.
The interruption mattered beyond the approximately $4.25 million loss Meter later calculated. Bridges were becoming critical infrastructure for moving value among otherwise separate blockchains, but their contracts also concentrated assets and translated one network’s deposits into another network’s tokens. A failure in that accounting could leave tokens circulating without the reserves users expected them to represent.
The incident followed the much larger Wormhole bridge exploit disclosed three days earlier. The proximity did not prove that the attacks were connected. It did, however, underscore a shared structural problem visible on February 5: cross-chain systems could inherit risks from custom contract logic even when the underlying blockchains continued operating normally.
Meter stops the bridge
Meter’s later incident timeline placed the attack’s start at 14:30 UTC on February 5. The project said it had paused bridge operations across its supported networks by 16:00 UTC and identified the vulnerable ERC-20 handler by 16:30 UTC. Its first detailed public thread began at approximately 19:36 UTC.
Meter told users that a feature intended to wrap and unwrap native gas tokens such as ETH and BNB had introduced the flaw. The handler treated specified wrapped tokens as though the corresponding native assets had already been transferred. Direct use of a separate deposit path could therefore cause the bridge to recognize value it had not actually received.
The project said the attacker used that faulty assumption to mint BNB and wrapped ether and drain reserves. Meter warned users against trading unbacked BNB circulating on Moonriver and said it was working on compensation. Those were contemporaneous project statements, not proof on February 5 that every affected position had been identified or that users would be made whole.
Why the accounting failure propagated
A bridge generally locks or burns an asset on one chain before releasing or minting its representation on another. The backing relationship depends on the destination token never being created without the corresponding source-side value.
Meter’s implementation broke that invariant for particular wrapped native tokens. The exploit did not require rewriting a blockchain’s history or defeating its consensus. It targeted application code responsible for deciding whether a valid deposit had occurred. Once unsupported tokens entered decentralized exchanges, losses could spread to liquidity providers or other protocols that treated those tokens as properly backed.
The February 5 record established that BNB- and ETH-related representations were affected. Meter said other bridged assets remained backed, but that assurance came from the operator while reconciliation was continuing. The available record does not provide an independent, real-time audit of every reserve and circulating token at the moment operations stopped.
Later technical clarification
Meter’s February 18 postmortem estimated that the attacker withdrew about 1,400 ETH and 2 BTC across Ethereum, Moonriver, BNB Smart Chain and Meter, assigning the incident a value of approximately $4.25 million using CoinGecko prices for February 5. The figures were rounded and valuation-dependent. Separately, PeckShield reported approximately 1,391.25 ETH and 2.74 BTC, worth about $4.3 million when it published its assessment shortly after the event.
ChainSafe, which developed the original open-source ChainBridge code, wrote on February 10 that Meter used an unaffiliated fork containing Meter-specific modifications. Its analysis agreed that the custom wrapped-token handling created a false-deposit path while stating that the original ChainBridge implementation was unaffected.
These later records clarify the mechanism and estimated scope; they do not change what was established on February 5. By that date’s end, the verified development was that Meter had stopped its bridge, identified faulty deposit accounting and warned that certain cross-chain assets were no longer fully backed.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

