An attacker exploited a flaw in Mezo's veBTC vote-escrow contract on October 5, 2026, moving 37 veBTC positions out of 36 holders' wallets and bridging roughly 5.52 BTC off the Mezo chain. Mezo says the vulnerability has been fixed, funds are at no further risk, and all affected users will be made whole from protocol-owned sources.
- The exploit abused the interaction between the contract's trusted meta-transaction forwarder and external Solidity libraries, letting the attacker impersonate the sender of a
safeTransferFrom call; they targeted unlocked-but-unredeemed positions so proceeds could be redeemed and bridged out.
- Mezo paused bridge withdrawals within 33 minutes, halted all chain transactions the same morning, and re-enabled everything after the fix; SEAL 911, exchanges and law enforcement were notified.
- A review found three other functions with more constrained access-control exposure, all covered by the same fix; the vulnerability was never reported via the Cantina bug bounty program.
- Reimbursed BTC will be sent directly to affected wallets — Mezo warns users not to follow any links promising recovery.