Skip to content
Crypto Hacker Mints $1.1 Billion in Polkadot via Ethereum Bridge, But Can Only Cash Out $237K

Crypto Hacker Mints $1.1 Billion in Polkadot via Ethereum Bridge, But Can Only Cash Out $237K

Decrypt.Co • April 13, 2026

A technical exploit of blockchain token bridge Hyperbridge led to the artificial creation of 1 billion Polkadot (DOT) tokens valued above $1.1 billion—but it only saw around $237,000 in losses due to limited liquidity, the firm reported on Monday.

The protocol, which allows users to transfer funds to and from distinct blockchains—like Ethereum to Polkdaot—said the exploit was as a result of a vulnerability in its proof verification logic. The malicious actor has not yet been identified.

“This flaw allowed invalid proofs to be incorrectly accepted as valid,” Hyperbridge posted on X. “As a result, a malicious message was processed that granted the attacker administrative control of the bridged DOT token contract on Ethereum.”

Once the exploiter gained access to the bridged DOT token contract, they proceeded to mint 1 billion bridged DOT tokens—which exceeded the actual bridged DOT token supply by around 2,800 times. For reference, the total native, non-bridged DOT supply is only 1.6 billion tokens.

The firm and the team behind the Polkadot blockchain confirmed the exploit was confined to only bridged DOT on the Ethereum blockchain.

After minting the tokens, the attacker then sold them directly on decentralized exchanges, making away with around $237,000—the amount that was available in trading liquidity.

Should there have been sufficient liquidity, someone with around 1 billion DOT tokens could stand to gain more than $1 billion as the token trades around $1.17, down 4.6% in the last 24 hours.

At that mark, DOT has now fallen more than 68% in the last year of trading and is nearly 98% off its November 2021 all-time high of $54.98. DOT is currently just above its all-time low price of $1.15, set in February.

The protocol’s app is down for maintenance as it adds “additional safeguards” and works with security partners in an attempt to recover swiped funds.

Bridge protocols have been at the center of multiple exploits over the years, highlighted by Ronin Network’s $552 million exploit in 2022 when hackers attacked its native bridge to Ethereum. The exploit remains one of the largest crypto hacks of all-time , and was linked by U.S. government agencies to North Korea’s infamous state- Lazarus hacking group.

The latest exploit adds to a mounting list of concerns surrounding the security of DeFi protocols , following the recent exploit of Solana’s Drift Protocol, which lost more than $285 million on April 1 to a North Korean-linked hacker.

A criminal group is threatening to release stolen customer data from crypto exchange Kraken, the firm reported Monday, publicly disclosing the conflict via social media. “We will not pay these criminals; we will not ever negotiate with bad actors,” Kraken Chief Security Officer Nick Percoco posted on X. “We are currently being extorted by a criminal group threatening to release videos of our internal systems with client data shown if we do not comply with their demands,” Percoco added. “We are...

The UK's AI Security Institute evaluated Anthropic's Claude Mythos Preview to assess its purportedly substantial cybersecurity capabilities, finding the AI model can autonomously execute sophisticated cyber attacks with unprecedented success rates. The existence of Claude Mythos was first revealed in late March via a website leak, with Anthropic confirming that the powerful -generation model is capable of finding and exploiting cybersecurity exploits at a level never seen before by any avai...

In August 2022, Mark Zuckerberg posted what was supposed to be a triumphant selfie. His Horizon Worlds avatar—a blocky, legless, dead-eyed cartoon that Kotaku memorably described as "a legless knock-off of a Nintendo Mii with the eyes of a corpse"—standing before a tiny Eiffel Tower. The internet buried him in memes. Even Meta's own employees reportedly refused to use Horizon Worlds. That was then. Now, according to a Financial Times report, Meta is building a photorealistic, AI-powered 3D vers...

This website or its third-party tools use cookies. By clicking the accept button, you agree to the use of cookies.

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Platforms (1)

Ransomware Groups (1)