Polkadot (DOT) experienced a brief 6% price drop to $1.16 on April 13 following a security report by Certik, which revealed that a malicious attacker exploited a vulnerability in the Hyperbridge gateway on the Ethereum network to mint 1 billion unauthorized DOT tokens. As of press time, DOT has recovered to $1.19.
Exploit Details: Replay Attack Mints 1 Billion Tokens
According to Certik's post-mortem analysis, the attacker leveraged a replay vulnerability in the Hyperbridge gateway smart contract. By sending a forged message to obtain administrative control over the bridged DOT contract on Ethereum, the attacker triggered a transaction that generated 1 billion tokens. Certik noted that the attacker copied the 'proof' value from the '_stateCommitments' of a previous transaction, enabling the replay attack. Furthermore, the downstream function tokengateway.handlechangeadmin failed to enforce strict checks, allowing the attacker to input arbitrary request data. This allowed malicious code to propagate unimpeded, ultimately granting the attacker the ability to change the administrator of the Polkadot token.
Liquidity Constraints Limited Losses
Despite the massive volume of tokens minted, the shallow liquidity of the bridged DOT on Ethereum prevented the attacker from cashing out at market value. On-chain analytics firm Lookonchain confirmed that the attacker liquidated all 1 billion tokens in a single swap, receiving approximately 108.2 ETH, worth about $237,000 at the time of the transaction. Had the bridge asset been more liquid, the financial damage could have been significantly higher.
Core Relay Chain Remains Unaffected
Security experts quickly clarified that the vulnerability was confined to the Hyperbridge gateway on Ethereum. The Polkadot core relay chain and the genuine DOT tokens on the Polkadot network remain secure and unaffected. The Hyperbridge development team has not yet published a full post-mortem report specifically addressing the gateway smart contract vulnerability, but it is expected that developers will deploy patches to strengthen administrative smart contract functionality and prevent similar attacks in the future.

