Hyperbridge Exploit Mints 1B DOT Tokens in Attack, CertiK Reports

CertiK reported that a hacker exploited Hyperbridge, a Polkadot cross-chain bridge, minting 1 billion bridged DOT tokens on Ethereum. The attacker seized admin control via a forged message and cashed out about $237,000, capped at 108.2 ETH by pool liquidity. Hyperbridge paused operations and said only bridged DOT on Ethereum was affected.

Original reporting
Published Jul 26, 2026, 9:16 AM UTC
Analysis
alphai AI DeskAI-generated
Added to alphai Jul 26, 2026, 12:50 PM UTC. Informational, not investment advice.
How this was made
alphai summarizes source reporting and applies a structured AI analysis for relevance, timing, sentiment and ticker impact. Always verify material claims with the original publisher.
Hyperbridge Exploit Mints 1B DOT Tokens in Attack, CertiK Reports — source image
Decision brief

The 30-second read

$DOT-USDBearishMed
01

Why it matters

The exploit involved inserting a forged message to seize admin control of the Polkadot token contract on Ethereum, then minting bridged DOT tokens; Hyperbridge paused operations and is pursuing an upgrade while root-cause hypotheses (Merkle proof replay) are still being assessed.

02

Market read

This is a concrete bridge-security incident with quantified minted amount and proceeds, plus an operational pause, which can drive short-term risk repricing for bridged assets and bridge operators.

03

What to watch

Traders may overfocus on the 1B bridged mint headline; the real tradable risk is whether Hyperbridge’s upgrade and any follow-on audits reduce bridge redemption or liquidity constraints for bridged DOT holders.

Relevance 7/10Novelty 7/10Timing: today, as Hyperbridge paused operations and worked on an upgrade after the exploit report

Background

Hyperbridge is described as a proof-based cross-chain interoperability layer built on Polkadot, marketed around full node security for bridges.

Company-level read

Ticker impact

$DOT-USDBearishMedium confidence
Context

CertiK reports a Hyperbridge exploit minted 1 billion bridged DOT tokens on Ethereum, with proceeds capped by liquidity at 108.2 ETH.

Expected impact

Near-term sentiment pressure on DOT tied to bridge security headlines; magnitude likely limited since article says native DOT and broader Polkadot were not impacted.

Evidence & confidence

The article attributes the exploit to forged admin control over the Polkadot token contract on Ethereum and specifies the impact is limited to DOT bridged through Hyperbridge, which should constrain systemic contagion.

Market effects

Highlights ongoing smart-contract and cross-chain verification weaknesses, potentially increasing scrutiny and risk premia for proof-based interoperability bridges.

No clear regional linkage; crypto bridge risk is global.

Could contribute to broader DeFi security sentiment, though the article frames impact as localized to Hyperbridge bridged DOT on Ethereum.

Counterpoint

Because the article states native DOT and the broader Polkadot ecosystem were not impacted, DOT price reaction may be muted beyond short-lived headline risk.

Key entities

  • Hyperbridge

    Cross-chain interoperability protocol that paused operations after the exploit and is upgrading.

  • CertiK

    Confirmed the attack using blockchain data and described the forged-message admin-control mechanism.

  • Blocksec Falcon

    Identified a likely root cause as a Merkle Mountain Range proof replay vulnerability.

  • SubQuery Network

    Previously exploited on Sunday for about $130,000 due to missing access control data, cited as part of the broader security picture.

Related articles

$BTC-USDMed

Bitcoin Has Broken Through $66K and Is Surging Higher

Bitcoin rose about 3% to trade above $66K, with market cap up to $2.25T (+2.7% in 24 hours). CryptoQuant said large BTC whales have been accumulating while medium wallets sold. Analysts reported stablecoin withdrawals from Binance and Bybit of $2.3B over a month. FTX said $900M payouts are due July 31. Cardano activated the Van Rossem hard fork.

$IBITMed

Bitcoin ETFs See Best Weekly Inflows Since April: Bloomberg

Bloomberg reports US spot Bitcoin ETFs had about $1 billion in net inflows for the week, their strongest since April and third-best since October, citing ETF analyst Eric Balchunas. The rebound follows uneven flows and comes amid ongoing regulatory uncertainty and renewed focus on self-custody after a Coldcard hardware-wallet hack that stole about $116 million in BTC.

$IBITMed

Bitcoin ETFs draw $853.5M in five-day inflow streak

U.S. spot Bitcoin ETFs saw five straight net inflow sessions totaling about $853.5 million from Aug. 3 to Aug. 7, reversing the prior week’s $61.5 million net outflows, according to SoSoValue. BlackRock’s IBIT led with about $693 million. Total spot Bitcoin ETF net assets were $79.50B. U.S. spot Ethereum ETFs added about $244.9M over the same period.

$IBITMed

Bitcoin Price Tops $65k on 5th Day of Spot BTC ETF Inflows

Bitcoin rose above $65,000 and hit an August high near $65,340 after a weaker-than-expected July U.S. jobs report reduced September Fed rate hike odds. The article cites SoSoValue data showing five straight days of net inflows into U.S. spot Bitcoin ETFs totaling $98.85 million on Aug. 7, led by BlackRock’s IBIT ($86.71 million).

$MSBTMed

Morgan Stanley ETF buys $15M Bitcoin during dip

Arkham reported Morgan Stanley’s spot Bitcoin ETF, MSBT, added about 232.5 BTC worth $15.05 million as Bitcoin traded below $65,000. The fund’s holdings rose to 6,563 BTC, over $426 million. Arkham also said BlackRock, Fidelity and Franklin Templeton bought a combined ~$153 million and made no tracked sales.

$BTC-USDMed

Bitcoin ‘9/11’—Urgent New Warning Issued As Wave Of ‘Critical’ Exploits Hits Price

The article says bitcoin security incidents are ongoing after a reported $100 million Coldcard hardware wallet exploit. It also reports volunteer “Bitcoin Red Team” audits using AI found about 5,000 vulnerabilities across nearly 400 projects, including 85 critical and 635 high-severity bugs. It adds BTCPay Server users were urged to update after a critical flaw was reportedly exploited, with funds stolen.