Hyperbridge Hacked: 1B DOT Tokens Mined in Vulnerability Exploit
A hacker exploited Hyperbridge, a cross-chain interoperability protocol built on Polkadot, by inserting a forged message to seize admin control of the Polkadot token contract on Ethereum. The attacker then minted 1 billion bridged DOT tokens in a single transaction, but was limited by low liquidity in the bridged DOT pool to approximately $237,000 in proceeds.
Cybersecurity platform CertiK confirmed the attack using blockchain data and identified it as a Merkle Mountain Range proof replay vulnerability caused by missing proof-to-request binding. The protocol had marketed itself specifically as a proof-based interoperability layer offering full node security for cross-chain bridges, but this incident puts that claim under scrutiny.
The broader security picture remains mixed. In the first quarter of 2026, hackers stole more than $168 million from 34 DeFi protocols, a sharp drop from the $1.58 billion taken in the same period of 2025. The attack on Hyperbridge is particularly notable because it targeted a specific aspect of the protocol's design.