Hyperbridge Exploit: Hacker Mints 1 Billion DOT, Price Crashes to Zero

Hyperbridge Exploit: Hacker Mints 1 Billion DOT, Price Crashes to Zero

N
News Editor 01
2026-07-23 22:40:15
A critical vulnerability in Hyperbridge's TokenGateway contract allowed an attacker to mint 1 billion DOT tokens from thin air, drain liquidity via Uniswap V4, netting ~108.2 ETH ($237K). Bridged DOT price collapsed 100%; native Polkadot remained secure.
cross-chain bridge securityPolkadotHyperbridge exploittoken minting vulnerabilityDeFi hack

On April 13, 2026, a massive exploit hit the Polkadot-Ethereum bridge Hyperbridge, run by Polytope Labs. The attacker exploited a state-proof verification flaw in the TokenGateway contract to mint 1 billion DOT tokens from a null address — essentially creating value out of nothing.

How $0.74 Gas Led to a Billion-Dollar Mint

The hacker first tricked the contract into granting them the AssetAdmin role. Once in control, they minted 1 billion bridged DOT at a cost of just $0.74 in gas fees. Those tokens were immediately dumped via Uniswap V4 and Odos Router, netting roughly 108.2 ETH (~$237,000). Because liquidity for bridged DOT on Ethereum was shallow, the massive sell-off drove the token price from $1.22 to essentially zero within seconds. Trading charts showed a vertical red candle as the line flatlined.

Native DOT Holders Are Safe (But a Panic Dip Hit)

This is not a hack of the Polkadot Relay Chain. Only the wrapped/bridged version of DOT on Ethereum was affected. Native DOT stakers and holders on the Polkadot mainnet saw no loss of funds. However, the news triggered a brief 7% price drop in native DOT before analysts confirmed the core network remained uncompromised and the price recovered.

Why the Hyperbridge Exploit Succeeded

Security firms including CertiK pointed out that Hyperbridge had deployed its contract with a zero-second challenge period. Most cross-chain bridges include a delay that allows the community to dispute suspicious transactions. Without that safety window, forged messages were accepted instantly. This is an especially embarrassing failure for Polytope Labs, which had promoted Hyperbridge as a proof-based bridge that was supposedly more secure than older, trusted models.

Losses were relatively small — around $237,000, compared to the Ronin bridge’s $625 million — but the reputational damage is heavy. The team paused the contract shortly after the attack and promised to compensate affected parties. Security auditors are now reviewing the entire TokenGateway logic to prevent recurrence.

For DeFi users, the lesson is clear: always check whether a cross-chain bridge has an active challenge period before depositing funds. Even the most advanced cryptography can be sidestepped if operational safeguards are disabled in production.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.