Back Coinmarketcap Hyperbridge Exploit Mints 1B DOT Tokens in Attack, CertiK Reports
A hacker has exploited Hyperbridge, a cross-chain interoperability protocol built on Polkadot, minting 1 billion bridged DOT tokens in a single transaction on Ethereum and walking away with approximately $237,000 in proceeds.
The exploit affected only DOT bridged through Hyperbridge on Ethereum. Native DOT tokens and the broader Polkadot ecosystem were not impacted, the project confirmed in a post on X.
Hyperbridge paused operations following the attack while its team worked on an upgrade. Contributor Web3 Philosopher said the initial diagnosis pointed to a malicious proof that fooled the protocol's Merkle tree verifier.
Blockchain security firm Blocksec Falcon identified the likely root cause as a Merkle Mountain Range proof replay vulnerability caused by missing proof-to-request binding, though the protocol had not confirmed a final root cause at the time of writing.
The incident carries added weight because Hyperbridge has marketed itself specifically as a proof-based interoperability layer offering full node security for cross-chain bridges. The attack puts that claim under scrutiny.
Security auditor Pashov said in a post on X that the SubQuery vulnerability allowed the attacker to set his own contract as the withdrawal target for staking rewards. The code exposed had been written over two years ago.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
