Articles
Ethereum

Hyperbridge attacker mints 1B bridged Polkadot tokens in $237K exploit

User Image

অ্যাননিমাস দ্বারা

তৈরি করা হয়েছে April 13, 2026|2 মিনিট পড়ুন
Main Image

A Hyperbridge exploit let an attacker mint 1 billion bridged Polkadot tokens on Ethereum and cash out about $237,000, reviving debate over bridge security.

A hacker exploited the Polkadot-based cross-chain interoperability protocol Hyperbridge, netting about $237,000 and raising renewed security concerns about blockchain bridge infrastructure.

An attacker minted 1 billion bridged Polkadot (DOT) tokens in a single transaction on Hyperbridge, according to blockchain data shared by cybersecurity platform CertiK. The exploit only affected DOT on Ethereum that was bridged through Hyperbridge, while native DOT tokens and the wider Polkadot ecosystem remain unaffected, Polkadot noted in a Monday X post.

CertiK said the attacker managed to mint the tokens after “slipping through a forged message to change the admin of the Polkadot token contract on Ethereum.” Limited liquidity in the bridged DOT pool capped the proceeds at 108.2 Ether (ETH), worth around $237,000.

Hyperbridge paused operations after the attack while the team worked on an upgrade, with contributor Web3 Philosopher saying the initial diagnosis pointed to a malicious proof that fooled the protocol’s Merkle tree verifier.

The exploit is notable because Hyperbridge has marketed itself as a proof-based interoperability layer built to deliver “full node security” for crosschain bridges. The incident also follows Aethir’s disclosure last week that it had contained a separate bridge exploit and kept user losses below $90,000.

Cybersecurity research company Blocksec Falcon said the likely root cause of the exploit was a Merkle Mountain Range (MMR) proof replay vulnerability caused by missing proof-to-request binding, though the final root cause has not yet been confirmed by the protocol.

The native DOT token briefly dipped to a daily low of $1.16 on Monday, before recovering to trade above $1.19 at the time of writing, according to CoinGecko.

Security incidents continue to hit crypto protocols despite a sharp year-over-year drop in DeFi exploit losses.

Related: New AI cybercrime tool targets crypto, bank KYC systems via deepfakes

On Sunday, the data indexing protocol SubQuery Network was also exploited for around $130,000 due to missing access control data that exposed the code written over two years ago.

The vulnerability enabled the attacker to set their own contract as the withdrawal target for staking rewards, blockchain security auditor Pashov said in a Sunday X post.

Hackers stole over $168 million from 34 decentralized finance (DeFi) protocols in the first quarter of 2026, marking a significant decline from the $1.58 billion stolen in the first quarter of 2025, when the record $1.4 billion Bybit hack occurred.

Cointelegraph has contacted Hyperbridge for comment on the root cause of the exploit.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Source: CoinTelegraph


সাম্প্রতিকতরে প্রকাশিত অন্যান্য নিবন্ধগুলি

AI agent development hasn’t accelerated as expected, Zuckerberg says
AI agent development hasn’t accelerated as expected, Zuckerberg says

Crypto Market Analysis

Mark Zuckerberg’s comments came on the same day that Meta expanded its Meta Business Agent globall...

Teen ‘Scattered Spider’ suspect extradited to US over $8M crypto ransom
Teen ‘Scattered Spider’ suspect extradited to US over $8M crypto ransom

Crypto Market Analysis

Peter Stokes, 19, has been charged in the US for allegedly taking part in a hacking group’s unsucc...

US spot Bitcoin ETFs top $200M in daily inflows for first time since May
US spot Bitcoin ETFs top $200M in daily inflows for first time since May

Bitcoin

US spot Bitcoin ETFs post $221.7 million inflows, the strongest daily intake since early May, as Bit...

Irish authorities seize another 500 Bitcoin, bringing 2026 total to 1,500 BTC
Irish authorities seize another 500 Bitcoin, bringing 2026 total to 1,500 BTC

Bitcoin

Irish authorities recovered 500 Bitcoin in criminal proceeds, bringing the total seized by the Crimi...

India's central bank revives push to isolate banks from crypto: Report
India's central bank revives push to isolate banks from crypto: Report

Crypto Market Analysis

The Indian central bank reportedly urged lawmakers to keep banks insulated from crypto and private s...

Defendant files to dismiss New York lawsuit seeking ownership of 39,069 Bitcoin wallets
Defendant files to dismiss New York lawsuit seeking ownership of 39,069 Bitcoin wallets

Bitcoin

A defendant who owns one of the dormant Bitcoin wallets filed to dismiss the New York case, which se...