Hyperbridge bridge exploit loss revised to $2.5M from initial $237K
Security & Exploits ·
A forged Merkle proof let an attacker mint 1 billion DOT on Ethereum, and the project's own loss estimate has since grown tenfold.
Hyperbridge's TokenGateway, built by Polytope Labs, was exploited on 2026-04-13 for an initial estimated loss of $237K, according to on-chain data tied to the TokenGateway contract. The attacker forged a cross-chain governance message that appeared to originate from Hyperbridge on POLKADOT-3367, exploiting the HandlerV1 contract by setting leafCount=1 with the proof equal to the stored overlayRoot, which trivially passed Merkle verification. Because the challengePeriod was set to 0, there was no dispute window to catch the forged message before it took effect.
The forged ChangeAssetAdmin message transferred admin rights of the bridged DOT token, an ERC6160Ext20 asset, to the attacker's own contract. From there, the attacker minted 1B DOT and swapped it for roughly 108.2 ETH through OdosRouterV3 via a Uniswap V4 DOT/ETH pool, at a time when DOT traded near $1.23 with a market cap around $2.07B, per CoinGecko.
The team has since revised its loss estimate sharply upward. Reporting from The Block puts the updated figure at $2.5 million, ten times the original $237K estimate, a revision also covered by Decrypt, which notes the team admitted the losses were far worse than first disclosed. Separate coverage from WuBlockchain similarly reports the $2.5M figure alongside the vulnerability's Token Gateway origin, and describes funds being traced toward Binance following the exploit.
The episode also coincided with a reported 7% drop in DOT's price. What remains unresolved is how the discrepancy between the initial $237K estimate and the revised $2.5M figure arose, whether any funds have been recovered or frozen after being traced to Binance, and what remediation Polytope Labs will apply to the challengePeriod and proof-verification logic that allowed the forged message to pass.