On April 13, 2026, a massive exploit hit the Polkadot-Ethereum bridge Hyperbridge, run by Polytope Labs. The attacker exploited a state-proof verification flaw in the TokenGateway contract to mint 1 billion DOT tokens from a null address — essentially creating value out of nothing.
How $0.74 Gas Led to a Billion-Dollar Mint
The hacker first tricked the contract into granting them the AssetAdmin role. Once in control, they minted 1 billion bridged DOT at a cost of just $0.74 in gas fees. Those tokens were immediately dumped via Uniswap V4 and Odos Router, netting roughly 108.2 ETH (~$237,000). Because liquidity for bridged DOT on Ethereum was shallow, the massive sell-off drove the token price from $1.22 to essentially zero within seconds. Trading charts showed a vertical red candle as the line flatlined.
Native DOT Holders Are Safe (But a Panic Dip Hit)
This is not a hack of the Polkadot Relay Chain. Only the wrapped/bridged version of DOT on Ethereum was affected. Native DOT stakers and holders on the Polkadot mainnet saw no loss of funds. However, the news triggered a brief 7% price drop in native DOT before analysts confirmed the core network remained uncompromised and the price recovered.
Why the Hyperbridge Exploit Succeeded
Security firms including CertiK pointed out that Hyperbridge had deployed its contract with a zero-second challenge period. Most cross-chain bridges include a delay that allows the community to dispute suspicious transactions. Without that safety window, forged messages were accepted instantly. This is an especially embarrassing failure for Polytope Labs, which had promoted Hyperbridge as a proof-based bridge that was supposedly more secure than older, trusted models.
Losses were relatively small — around $237,000, compared to the Ronin bridge’s $625 million — but the reputational damage is heavy. The team paused the contract shortly after the attack and promised to compensate affected parties. Security auditors are now reviewing the entire TokenGateway logic to prevent recurrence.
For DeFi users, the lesson is clear: always check whether a cross-chain bridge has an active challenge period before depositing funds. Even the most advanced cryptography can be sidestepped if operational safeguards are disabled in production.

