A Hyperbridge exploit sent bridged DOT on Ethereum into a rapid collapse after an attacker minted a huge batch of unauthorized tokens and sold them into the market. Blockchain security firm CertiK said the breach started with a flaw in Hyperbridge’s gateway contract, allowing the attacker to tamper with internal verification logic and bypass security checks meant to block unauthorized minting.
Contract control was shifted before the mint and dump
CertiK said the attacker used the weakness to forge transaction messages and seize administrative control of the bridged token contract on Ethereum. That opened access to privileged functions that should not have been available. Onchain Lens reported irregular contract activity matching the exploit timeline, adding that ownership of the contract moved to a malicious address before token creation and rapid liquidation began.
1 billion unbacked DOT flooded the Ethereum market
After taking control, the attacker minted 1 billion fake DOT on Ethereum with no legitimate backing and sold a large portion of the supply in short order. Liquidity was overwhelmed fast. Available data show the price of bridged DOT on Ethereum fell from about $1.22 to fractions of a cent, while the attacker is estimated to have made roughly $237,000 before exiting positions.
Polkadot says native DOT was not impacted
Polkadot said in an update on X that the incident was limited to Ethereum-based representations of DOT that depended on Hyperbridge. Native DOT on the Polkadot network remained secure, and DOT bridged through other mechanisms was not disrupted. Hyperbridge operations have been temporarily halted while developers investigate the root cause and review mitigation options.
The fallout still weighed on market sentiment. Native DOT slipped by about 4%, moving from around $1.22 to near $1.18. South Korean exchanges Upbit and Bithumb suspended DOT deposits and withdrawals as a precaution after signs of a possible security issue tied to the incident. For now, users holding bridged DOT on Ethereum face restricted activity while the technical review continues.

