MAP Protocol's Butter Bridge suffered a severe exploit on May 20, when an attacker minted 1 quadrillion MAPO tokens — roughly 4.8 million times the legitimate circulating supply of 208 million. The token price dropped nearly 30% within hours, from about $0.003 to $0.001558.
A 1-quadrillion mint
Security firm PeckShield identified the vulnerability in Butter Bridge V3.1's OmniServiceProxy contract. The flaw allowed the attacker to spoof a cross-chain message and mint unauthorized tokens on Ethereum and BSC. The mint originated from the zero address to wallet 0x40592025392BD7d7463711c6E82Ed34241B64279.
Price collapse and liquidity drained
The exploiter swapped portions of the fake supply, extracting roughly 52.2 ETH (~$110,000) and pulling over $180,000 in liquidity from Uniswap pools before the price collapsed. Most of the inflated tokens still sit in the attacker's wallet. The timing isn't great for MAP Protocol, which markets itself as secure infrastructure for BTC, stablecoins, and tokenized assets.
Part of a larger pattern
PeckShield has tracked multiple bridge exploits in 2026, draining hundreds of millions across DeFi. This incident adds to a growing list of cross-chain vulnerabilities that keep drawing attackers.
No formal response yet
The MAP Protocol team has not issued a formal statement on mitigation — no contract pause, no token blacklist, no supply adjustment announced as of May 23. It's unclear whether they're working on a fix or how they plan to handle the inflated supply still out there.



