Polkadot Bridge Exploit Mints 1 Billion DOT, Dumps for 108.2 ETH

Polkadot Bridge Exploit Mints 1 Billion DOT, Dumps for 108.2 ETH

N
News Editor 01
2026-07-23 22:00:15
An attacker exploited a vulnerable Hyperbridge contract on Ethereum, seized control of the bridged DOT token, minted 1 billion DOT, and sold it for 108.2 ETH. Upbit has suspended DOT deposits and withdrawals.
PolkadotDOTbridge exploitHyperbridgesecurity vulnerability

A security breach hit Polkadot-linked bridge infrastructure after an attacker exploited the Hyperbridge gateway contract on Ethereum, took control of the bridged DOT token contract, minted 1 billion DOT, and sold the entire amount in one move on Uniswap V4 for 108.2 ETH, or about $237,000 based on the source material.

The sell-off immediately disrupted the bridged asset’s price. According to the report, DOT fell from around $1.22 to nearly $1 within the same transaction block. Exchanges moved quickly after the incident, with Upbit suspending DOT deposits and withdrawals as a precaution.

Forged proof passed verification and shifted contract control

The exploit dates to April 13, 2026, when the attacker submitted a fake proof to a vulnerable contract on Ethereum. The system treated that proof as legitimate, allowing it to pass security checks and trigger a critical bridge function. The failure occurred at the cross-chain message verification layer.

Once the forged proof was accepted, the contract executed automatically and changed the bridged DOT token contract’s admin to the attacker’s wallet. That gave the attacker direct authority over token management, including minting rights.

1 billion DOT minted and dumped into Uniswap V4

After gaining control, the attacker minted 1 billion DOT and transferred the tokens to a new wallet. The source says this amount was about 2,805 times the real supply at that time. The full balance was then sold into Uniswap V4 in a single action, draining roughly 108.2 ETH from the liquidity pool.

The funds were routed through Odos Router V3 and sent back to the attacker’s wallet. At the same time, the fake supply flooded the market for the bridged asset, pushing its price sharply lower.

Hyperbridge verification flaw is at the center of the incident

The report attributes the exploit to a flaw in how Hyperbridge verified cross-chain messages. The system was designed to rely on cryptographic proofs rather than human intervention, but the forged proof was still accepted as valid. That single mistake opened the door for admin changes and unauthorized minting.

At the time covered by the source, developers were investigating the exploit and working on a fix. The report also states that Hyperbridge and Polytope Labs had not yet issued a detailed official statement on mitigation measures, recovery plans, or any broader system pause. More exchange restrictions may depend on what the teams find as they assess the remaining risk.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.