{"investigation":{"slug":"minterest","entity_name":"Minterest","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Minterest (formerly using the MNT token, later rebranded to MINTY) was a cross-chain DeFi lending and borrowing protocol founded by Josh Rogers and incorporated as Minterest Labs OÜ in Estonia. The protocol suffered a $1.4 million reentrancy exploit on July 14, 2024 — in a market that went live without a completed security audit — and subsequently announced the sunsetting of all operations in November 2025, explicitly stating that hack victims would receive no refund or token compensation as part of the wind-down.","sections":[{"content":"Minterest was a decentralised lending and borrowing protocol that positioned itself as a value-capturing alternative to established DeFi money markets such as Aave and Compound. It was incorporated as Minterest Labs OÜ, registered in Tallinn, Estonia (CIK: 0001873302 on SEC EDGAR). The founding CEO is Josh Rogers, a serial technology entrepreneur previously associated with Freelancer.com and HeyYou, an Australian cafe app. The protocol's stated differentiator was a built-in buyback mechanism that redistributed 100% of protocol revenues — interest, flash loan fees, and liquidation income — directly to governance participants via the native MNT token (later rebranded MINTY). The protocol was initially planned for the Moonbeam parachain on Polkadot, before pivoting to Mantle Network, Ethereum mainnet, Taiko, and Morph.","heading":"Protocol Overview and History","sources":[{"url":"https://www.prnewswire.com/news-releases/following-a-6-5m-raise-defi-lending-platform-minterest-builds-value-capturing-protocol-to-make-defi-fairer-301377964.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://www.crowdfundinsider.com/2021/11/182633-minterest-a-defi-lending-protocol-to-launch-on-moonbeam-an-ethereum-compatible-smart-contract-parachain-on-polkadot/","name":"crowdfundinsider.com","type":"other","credibility":3},{"url":"https://www.bitcoinisle.com/2021/11/01/interview-with-josh-rogers-ceo-of-minterest-building-defi-lending-platform/","name":"bitcoinisle.com","type":"other","credibility":3},{"url":"https://companiesbio.com/CIK-0001873302-company-minterest-labs-ou-info.html","name":"companiesbio.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In September 2021, Minterest announced the completion of a $6.5 million private fundraising round. Investors included KR1, DFG (Digital Finance Group), CMS Holdings, DigiStrats, FOMOcraft, Bitscale Capital, PNYX Ventures, CMT Digital, and Faculty Capital. Minterest Labs OÜ also filed a Form D/A with the SEC, indicating securities were offered under a Regulation D exemption. A subsequent token sale — the Liquidity Bootstrapping Pool (LBP) event — set a reference price of $3.21 per token for Community Allocation Event (CAE) participants. A separate IDO was conducted on EnjinStarter, concluding on June 24, 2024, at a price of $2.25 per MINTY token. Despite these raises and the LBP, the MINTY token failed to achieve sustained liquid trading on major exchanges.","heading":"Fundraising and Investor Background","sources":[{"url":"https://www.prnewswire.com/news-releases/following-a-6-5m-raise-defi-lending-platform-minterest-builds-value-capturing-protocol-to-make-defi-fairer-301377964.html","name":"prnewswire.com","type":"other","credibility":3},{"url":"https://www.formds.com/issuers/minterest-labs-ou","name":"formds.com","type":"other","credibility":3},{"url":"https://www.streetinsider.com/SEC+Filings/Form++DA++++++++Minterest+Labs+OU/18989013.html","name":"streetinsider.com","type":"other","credibility":3},{"url":"https://cryptorank.io/ico/minterest","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the July 2024 exploit, Minterest had commissioned at least six security audits from firms including Trail of Bits, Hacken, PeckShield, and Zokyo. A PeckShield audit found no critical or high-severity vulnerabilities, though minor issues were noted in liquidation processes when interacting with external decentralised exchanges. In September 2023, Minterest also partnered with CUBE3.AI for real-time transaction monitoring and threat blocking. Despite this multi-layered security posture, the critical mUSDY token market — added specifically for the Mantle Network deployment — was deployed without a completed external audit. Minterest's own post-mortem acknowledged that 'the internal code review process failed to flag the flaw,' and the CUBE3.AI real-time protection did not prevent the exploit from completing.","heading":"Security Audit History and Pre-Hack Posture","sources":[{"url":"https://hacken.io/audits/minterest/","name":"hacken.io","type":"other","credibility":3},{"url":"https://minterest.com/blog/minterest-completes-comprehensive-security-audit-with-peckshield/","name":"minterest.com","type":"other","credibility":3},{"url":"https://blog.cube3.ai/2023/09/14/minterest-protects-decentralized-lending-with-cube3-ai/","name":"blog.cube3.ai","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-minterest-hack-july-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/minterestflashloanreentrancyexploit.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 14, 2024, between approximately 16:24 and 16:28 UTC+3, an attacker executed a flash loan reentrancy exploit against Minterest's mUSDY smart contract on Mantle Network, draining approximately $1.4 million in WETH and mETH tokens. The attacker's wallet (0x618F768aF6291705Eb13E0B2E96600b3851911D1) was initially funded via Tornado Cash, the Ethereum mixing service. The attack exploited two simultaneous vulnerabilities: (1) a reentrancy flaw in the mUSDY contract's flashLoan function, which allowed the attacker to re-enter the lendRUSDY function within the loan callback and accumulate excess mTokens without actually having deposited equivalent collateral; and (2) a price manipulation vulnerability, whereby the protocol's exchange rates were recalculated immediately after each borrow, enabling the attacker to distort rates through successive loops. The attacker cycled this process approximately 25 times, accumulating an estimated $1.7 million in mUSDY market tokens, then used those tokens as collateral to borrow the maximum possible WETH and mETH from separate markets. Stolen funds were bridged to Ethereum mainnet via Stargate and Squid Router, then deposited into Tornado Cash. Unusual liquidations were detected internally at 16:31 UTC+3; the security breach was confirmed at 17:22 UTC+3; supply and borrow operations were suspended at 17:27 UTC+3; all operations were fully paused at 22:32 UTC+3 following identification of the USDY manipulation. The vulnerability was patched and exchange rates corrected on July 18, 2024. All user positions with USDY collateral were forcibly liquidated during the attack window. The incident was covered by Halborn, Web3 Is Going Just Great, and Coinpedia, among other outlets. No ZachXBT attribution to this specific incident has been independently verified; ZachXBT's flag of Minterest as a trust concern appears to relate to the broader pattern of the project's conduct, including the unaudited market deployment and subsequent shutdown without hack victim compensation.","heading":"July 2024 Flash Loan Reentrancy Exploit","sources":[{"url":"https://minterest.com/blog/minterest-security-incident-post-mortem-report/","name":"minterest.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-minterest-hack-july-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=minterest-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/minterestflashloanreentrancyexploit.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://medium.com/@gokun4621/hack-analysis-minterest-0913228a3f6c","name":"medium.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/crypto-hack-weekly-report-years-second-largest-hack-shakes-the-blockchain-world/","name":"coinpedia.org","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the hack, Minterest paused all supply and borrow operations across Mantle, Ethereum, and Taiko. The protocol applied a 15% haircut to WETH and mETH supplier balances to distribute losses across all suppliers rather than concentrating them on the directly affected users. Liquidation fees were returned to impacted users by July 24, 2024. A 10% white-hat bounty was posted for fund recovery, and forensic experts and law enforcement were engaged. Affected WETH and mETH suppliers were offered MINTY token compensation at a stated 25% discount to listing price, with staggered vesting, and a 40% yield farming boost. Base rate APY/APR was set to 0% to ease pressure on borrowers. The protocol reopened on a limited basis after patching. Critically, the recovery of stolen funds via negotiation with the attacker was not publicly confirmed.","heading":"Post-Exploit Response and Compensation","sources":[{"url":"https://minterest.com/blog/minterest-security-incident-post-mortem-report/","name":"minterest.com","type":"other","credibility":3},{"url":"https://docs.minterest.com/minterest-faq/security-audits/minterest-security-incident-documentation","name":"docs.minterest.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/minterestflashloanreentrancyexploit.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Community complaints about repeated token listing delays are a recurring theme in Minterest's history. The native MNT token — later rebranded to MINTY — was delayed across multiple announced timelines between 2021 and 2024. Multiple tokenomics restructurings were carried out, including a January 2023 update that added a 50% uplift in MINTY proportions for long-term holders, and an April 2024 update that changed vesting schedules. A 'Stack or Skip' campaign in April 2024 gave Community Allocation Event (CAE) participants the option to accept updated vesting terms or receive a full refund of their initial contribution. Some community members characterised these repeated adjustments as a pattern of delays rather than genuine improvements. The token never achieved sustained liquid trading on major centralised or decentralised exchanges at the prices implied by the fundraising rounds.","heading":"Token Listing Delays and Community Grievances","sources":[{"url":"https://minterest.com/blog/minterest-roadmap-2023-the-current-state/","name":"minterest.com","type":"other","credibility":3},{"url":"https://docs.minterest.com/minterest-faq/updated-tokenomics-april-2024/cae-stack-or-skip-campaign-faq","name":"docs.minterest.com","type":"other","credibility":3},{"url":"https://minterest.com/blog/tokenomics-update-january-2023/","name":"minterest.com","type":"other","credibility":3},{"url":"https://minterest.com/blog/community-allocation-event-announcement/","name":"minterest.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 19, 2025, Minterest publicly announced it was sunsetting all operations, citing 'market and operational realities' and the impossibility of 'continuing operating the protocol to the standard the users and partners deserve.' The UI front end for Ethereum and Mantle deployments was scheduled to go offline on December 19, 2025 at 23:59 UTC, with official support ending on December 31, 2025. Social channels were muted after December 20, with support transitioning to email only. Critically, the sunsetting announcement explicitly stated that the wind-down 'does not include any token issuance, distribution, or refund for CAE/LBP participants, private investors, or those impacted by the prior security-incident.' This means users who suffered losses in the July 2024 exploit received no meaningful compensation through the protocol shutdown process. Smart contracts remained accessible for users to withdraw remaining deployed assets directly. The Minterest.com website now displays a Legacy Notice confirming that Minterest Labs OÜ is no longer operating the protocol. At the time of shutdown, TVL stood at approximately $100,204 — a fraction of the $16 million TVL reached at peak operation on Mantle.","heading":"Protocol Shutdown and Hack Victim Exclusion","sources":[{"url":"https://minterest.com/blog/minterest-is-sunsetting-operations/","name":"minterest.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/minterest","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The attacker's wallet (0x618F768aF6291705Eb13E0B2E96600b3851911D1) was funded via Tornado Cash prior to the exploit, indicating deliberate effort to obscure the attacker's origin. Stolen WETH and mETH were bridged to Ethereum mainnet via Stargate bridge and Squid Router, then deposited into Tornado Cash, making full recovery effectively impossible through standard on-chain tracing. MINTY token data on BscScan (contract: 0x4d6711FbCf8a6455D916c13EA09a31C9f026F546) shows the token remained illiquid and untradeable on major platforms. Minterest Labs OÜ filed a Form D/A with the SEC, indicating the protocol raised funds under a securities exemption, though no regulatory enforcement action has been publicly identified.","heading":"On-Chain Risk Indicators","sources":[{"url":"https://quadrigainitiative.com/casestudy/minterestflashloanreentrancyexploit.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://bscscan.com/token/0x4d6711FbCf8a6455D916c13EA09a31C9f026F546","name":"bscscan.com","type":"other","credibility":3},{"url":"https://www.formds.com/issuers/minterest-labs-ou","name":"formds.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-09-16","event":"Minterest announces $6.5 million private fundraising round with investors including KR1, DFG, CMS, DigiStrats, FOMOcraft, Bitscale Capital, PNYX Ventures, CMT Digital, and Faculty Capital.","source":""},{"date":"2021-11","event":"Minterest announces planned deployment on Moonbeam, an Ethereum-compatible parachain on Polkadot.","source":"","date_original":"2021-11-01"},{"date":"2021-12-10","event":"Minterest refunds all Community Allocation Event (CAE) participants, including gas fees, following a rescheduling of the event.","source":""},{"date":"2022-02","event":"Minterest completes comprehensive security audit with PeckShield. No critical or high-severity vulnerabilities found.","source":"","date_original":"2022-02-01"},{"date":"2023","event":"Minterest updates tokenomics, giving long-term holders a 50% uplift in MINTY token proportion.","source":"","date_original":"2023-01-01"},{"date":"2023-09-14","event":"Minterest announces partnership with CUBE3.AI for real-time on-chain threat monitoring and transaction blocking.","source":""},{"date":"2024-04","event":"Minterest updates tokenomics again and launches 'Stack or Skip' campaign for CAE participants, offering either a 20% MINTY bonus with new vesting or full refund of initial contribution.","source":"","date_original":"2024-04-01"},{"date":"2024-06-24","event":"Minterest IDO concludes on EnjinStarter at a price of $2.25 per MINTY token.","source":""},{"date":"2024-07-14","event":"Attacker executes flash loan reentrancy exploit against unaudited mUSDY market on Mantle Network between 16:24-16:28 UTC+3. Approximately $1.4 million in WETH and mETH drained. Attacker wallet (0x618F768aF6291705Eb13E0B2E96600b3851911D1) was pre-funded via Tornado Cash.","source":""},{"date":"2024-07-14","event":"Minterest confirms security breach at 17:22 UTC+3, suspends supply/borrow operations at 17:27 UTC+3, and fully pauses all operations at 22:32 UTC+3.","source":""},{"date":"2024-07-18","event":"Minterest patches the reentrancy vulnerability and corrects the mUSDY exchange rate manipulation.","source":""},{"date":"2024-07-24","event":"Minterest completes return of liquidation fees to impacted users. Protocol applies 15% haircut to WETH and mETH suppliers.","source":""},{"date":"2024-08","event":"Minterest protocol partially reopens following patching. Offers MINTY token compensation at 25% discount to hack-affected suppliers.","source":"","date_original":"2024-08-01"},{"date":"2025-11-19","event":"Minterest announces sunsetting of all operations, citing market and operational constraints. Explicitly states no refund or token compensation will be issued to hack victims, private investors, or CAE/LBP participants.","source":""},{"date":"2025-12-19","event":"Minterest UI front end for Ethereum and Mantle deployments goes offline at 23:59 UTC.","source":""},{"date":"2025-12-31","event":"Official support ends. Core infrastructure and solvency engines go offline. Smart contracts remain accessible for direct user interaction.","source":""}],"sources_used":[{"url":"https://www.prnewswire.com/news-releases/following-a-6-5m-raise-defi-lending-platform-minterest-builds-value-capturing-protocol-to-make-defi-fairer-301377964.html","name":"prnewswire.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crowdfundinsider.com/2021/11/182633-minterest-a-defi-lending-protocol-to-launch-on-moonbeam-an-ethereum-compatible-smart-contract-parachain-on-polkadot/","name":"crowdfundinsider.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.bitcoinisle.com/2021/11/01/interview-with-josh-rogers-ceo-of-minterest-building-defi-lending-platform/","name":"bitcoinisle.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://companiesbio.com/CIK-0001873302-company-minterest-labs-ou-info.html","name":"companiesbio.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.formds.com/issuers/minterest-labs-ou","name":"formds.com","type":"other","archive_url":"http://web.archive.org/web/20260830005215/https://www.formds.com/issuers/minterest-labs-ou","credibility":3,"archive_timestamp":"2026-08-30T00:52:15+00:00"},{"url":"https://www.streetinsider.com/SEC+Filings/Form++DA++++++++Minterest+Labs+OU/18989013.html","name":"streetinsider.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptorank.io/ico/minterest","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829235610/https://cryptorank.io/ico/minterest","credibility":3,"archive_timestamp":"2026-08-29T23:56:10+00:00"},{"url":"https://hacken.io/audits/minterest/","name":"hacken.io","type":"other","archive_url":"http://web.archive.org/web/20260414153420/https://hacken.io/audits/minterest/","credibility":3,"archive_timestamp":"2026-04-14T15:34:20+00:00"},{"url":"https://minterest.com/blog/minterest-completes-comprehensive-security-audit-with-peckshield/","name":"minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260317115232/https://minterest.com/blog/minterest-completes-comprehensive-security-audit-with-peckshield/","credibility":3,"archive_timestamp":"2026-03-17T11:52:32+00:00"},{"url":"https://blog.cube3.ai/2023/09/14/minterest-protects-decentralized-lending-with-cube3-ai/","name":"blog.cube3.ai","type":"other","archive_url":"http://web.archive.org/web/20260112172930/https://blog.cube3.ai/2023/09/14/minterest-protects-decentralized-lending-with-cube3-ai/","credibility":3,"archive_timestamp":"2026-01-12T17:29:30+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-minterest-hack-july-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260414120212/https://www.halborn.com/blog/post/explained-the-minterest-hack-july-2024","credibility":3,"archive_timestamp":"2026-04-14T12:02:12+00:00"},{"url":"https://quadrigainitiative.com/casestudy/minterestflashloanreentrancyexploit.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260417185410/https://quadrigainitiative.com/casestudy/minterestflashloanreentrancyexploit.php","credibility":3,"archive_timestamp":"2026-04-17T18:54:10+00:00"},{"url":"https://minterest.com/blog/minterest-security-incident-post-mortem-report/","name":"minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260418034939/https://minterest.com/blog/minterest-security-incident-post-mortem-report/","credibility":3,"archive_timestamp":"2026-04-18T03:49:39+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=minterest-hack","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260112181423/https://www.web3isgoinggreat.com/?id=minterest-hack","credibility":3,"archive_timestamp":"2026-01-12T18:14:23+00:00"},{"url":"https://medium.com/@gokun4621/hack-analysis-minterest-0913228a3f6c","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinpedia.org/news/crypto-hack-weekly-report-years-second-largest-hack-shakes-the-blockchain-world/","name":"coinpedia.org","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://docs.minterest.com/minterest-faq/security-audits/minterest-security-incident-documentation","name":"docs.minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260419090450/https://docs.minterest.com/minterest-faq/security-audits/minterest-security-incident-documentation","credibility":3,"archive_timestamp":"2026-04-19T09:04:50+00:00"},{"url":"https://minterest.com/blog/minterest-roadmap-2023-the-current-state/","name":"minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260418035211/https://minterest.com/blog/minterest-roadmap-2023-the-current-state/","credibility":3,"archive_timestamp":"2026-04-18T03:52:11+00:00"},{"url":"https://docs.minterest.com/minterest-faq/updated-tokenomics-april-2024/cae-stack-or-skip-campaign-faq","name":"docs.minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260204012709/https://docs.minterest.com/minterest-faq/updated-tokenomics-april-2024/cae-stack-or-skip-campaign-faq","credibility":3,"archive_timestamp":"2026-02-04T01:27:09+00:00"},{"url":"https://minterest.com/blog/tokenomics-update-january-2023/","name":"minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260418033021/https://minterest.com/blog/tokenomics-update-january-2023/","credibility":3,"archive_timestamp":"2026-04-18T03:30:21+00:00"},{"url":"https://minterest.com/blog/community-allocation-event-announcement/","name":"minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260517051346/https://minterest.com/blog/community-allocation-event-announcement/","credibility":3,"archive_timestamp":"2026-05-17T05:13:46+00:00"},{"url":"https://minterest.com/blog/minterest-is-sunsetting-operations/","name":"minterest.com","type":"other","archive_url":"http://web.archive.org/web/20260418032204/https://minterest.com/blog/minterest-is-sunsetting-operations/","credibility":3,"archive_timestamp":"2026-04-18T03:22:04+00:00"},{"url":"https://defillama.com/protocol/minterest","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bscscan.com/token/0x4d6711FbCf8a6455D916c13EA09a31C9f026F546","name":"bscscan.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:31.119539+00:00","updated_at":"2026-08-30T05:14:07.315776+00:00"}}