YFarmX

Tools Crypto Exploit Tracker exploit-0058

Exploit record

Hyperbridge

Loss
$3M
Attack vector
Bridge Exploit
Chain
Ethereum
Sector
Bridge

What happened

On 13 April 2026 an attacker submitted forged state proofs to Hyperbridge's Token Gateway on Ethereum, minting 1 billion bridged DOT and draining escrowed assets; losses were later revised from about $237,000 to roughly $2.5 million.

The attacker exploited a flaw in the Merkle Mountain Range proof verification logic of the HandlerV1 contract: the proof was not bound to a specific request and a zero-second challenge period allowed immediate execution, which handed the attacker admin control of the bridged DOT token. DOT pools on Ethereum, Base, BNB Chain and Arbitrum were affected, though Polkadot's core network and native DOT were untouched. Hyperbridge said a significant portion of the funds was traced to Binance and that it was working with the exchange's compliance team and law enforcement on freezes.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026