Hyperbridge Exploit Mints 1B DOT Tokens in Attack, CertiK Reports
CertiK reported that a hacker exploited Hyperbridge, a Polkadot cross-chain bridge, minting 1 billion bridged DOT tokens on Ethereum. The attacker seized admin control via a forged message and cashed out about $237,000, capped at 108.2 ETH by pool liquidity. Hyperbridge paused operations and said only bridged DOT on Ethereum was affected.
How this was made

The 30-second read
Why it matters
The exploit involved inserting a forged message to seize admin control of the Polkadot token contract on Ethereum, then minting bridged DOT tokens; Hyperbridge paused operations and is pursuing an upgrade while root-cause hypotheses (Merkle proof replay) are still being assessed.
Market read
This is a concrete bridge-security incident with quantified minted amount and proceeds, plus an operational pause, which can drive short-term risk repricing for bridged assets and bridge operators.
What to watch
Traders may overfocus on the 1B bridged mint headline; the real tradable risk is whether Hyperbridge’s upgrade and any follow-on audits reduce bridge redemption or liquidity constraints for bridged DOT holders.
Background
Hyperbridge is described as a proof-based cross-chain interoperability layer built on Polkadot, marketed around full node security for bridges.
Ticker impact
CertiK reports a Hyperbridge exploit minted 1 billion bridged DOT tokens on Ethereum, with proceeds capped by liquidity at 108.2 ETH.
Near-term sentiment pressure on DOT tied to bridge security headlines; magnitude likely limited since article says native DOT and broader Polkadot were not impacted.
The article attributes the exploit to forged admin control over the Polkadot token contract on Ethereum and specifies the impact is limited to DOT bridged through Hyperbridge, which should constrain systemic contagion.
Market effects
Highlights ongoing smart-contract and cross-chain verification weaknesses, potentially increasing scrutiny and risk premia for proof-based interoperability bridges.
No clear regional linkage; crypto bridge risk is global.
Could contribute to broader DeFi security sentiment, though the article frames impact as localized to Hyperbridge bridged DOT on Ethereum.
Counterpoint
Because the article states native DOT and the broader Polkadot ecosystem were not impacted, DOT price reaction may be muted beyond short-lived headline risk.
Key entities
- protocolHyperbridge
Cross-chain interoperability protocol that paused operations after the exploit and is upgrading.
- security_firmCertiK
Confirmed the attack using blockchain data and described the forged-message admin-control mechanism.
- security_firmBlocksec Falcon
Identified a likely root cause as a Merkle Mountain Range proof replay vulnerability.
- protocolSubQuery Network
Previously exploited on Sunday for about $130,000 due to missing access control data, cited as part of the broader security picture.




