Hyperbridge, the cross-chain gateway connecting Polkadot and Ethereum, was exploited after an attacker used a forged cross-chain message to seize admin control of a DOT-linked token contract on Ethereum. With that access, the attacker minted roughly 1 billion fake DOT-equivalent tokens and extracted about $237,000. The breach was disclosed on April 13, and the failure centered on message verification inside the bridge rather than the Polkadot base layer.
Forged message opened the door to admin takeover
Blockchain security firm CertiK said the attacker changed the admin of the Polkadot token contract on Ethereum through a forged message, then profited by minting and selling the tokens. A control that should have been blocked by multisig protection or on-chain verification did not hold. One lapse was enough to create near-unlimited minting power. AMBCrypto reported that the attacker used Hyperbridge’s Interoperable State Machine Protocol to bypass state-proof verification in the smart contract.
Huge fake supply, limited real proceeds
Intellectia.AI described the issue as a vulnerability in the Hyperbridge gateway smart contract on Ethereum that allowed the creation of 1 billion unauthorized DOT tokens through message forgery. The position was then liquidated in a single transaction for about 108.2 ETH, or roughly $237,000. The mismatch between the token amount and the final proceeds came down to liquidity. It was thin.
Because available pool depth was limited, the flood of counterfeit tokens crushed the price of the bridged DOT representation instead of causing direct technical damage to the underlying Polkadot network. The base chain itself remained unaffected, while the impact was concentrated on the wrapped asset and the liquidity sitting around it.
Confidence hit the bridge layer, not the base chain
Polkadot’s native DOT was trading near $1.20 at the time and saw only modest spillover as the market processed the incident. A TradingView recap said the episode shook confidence in Polkadot’s cross-chain ecosystem because the compromised component was presented as critical infrastructure, not as a small experimental product on the edge of the network.
The case also points back to a familiar weakness in bridge design: concentrated admin authority. When a single contract or a small governance surface controls asset issuance and release, forged messages can let attackers unlock or mint assets far beyond any real collateral backing them.
Another bridge failure in a year full of them
The Hyperbridge exploit adds to a string of bridge-related incidents in 2026. Those include a $3 million CrossCurve exploit and an Aethir bridge incident where user losses were kept below $90,000 after rapid containment. Taken together, the pattern is hard to miss. In many multi-chain systems, the bridge remains the weakest point, especially when verification logic can be bypassed or trust is concentrated in too few hands.

