Tools Crypto Exploit Tracker exploit-0058
Exploit record
Hyperbridge
- Loss
- $3M
- Attack vector
- Bridge Exploit
- Chain
- Ethereum
- Sector
- Bridge
What happened
On 13 April 2026 an attacker submitted forged state proofs to Hyperbridge's Token Gateway on Ethereum, minting 1 billion bridged DOT and draining escrowed assets; losses were later revised from about $237,000 to roughly $2.5 million.
The attacker exploited a flaw in the Merkle Mountain Range proof verification logic of the HandlerV1 contract: the proof was not bound to a specific request and a zero-second challenge period allowed immediate execution, which handed the attacker admin control of the bridged DOT token. DOT pools on Ethereum, Base, BNB Chain and Arbitrum were affected, though Polkadot's core network and native DOT were untouched. Hyperbridge said a significant portion of the funds was traced to Binance and that it was working with the exchange's compliance team and law enforcement on freezes.
Sources
- Hyperbridge post-mortemblog.hyperbridge.network/april-13-post-mortem/
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
