An attacker exploited Hyperbridge’s gateway contract to mint 1 billion unauthorized bridged DOT tokens on Ethereum.
The exploit reportedly allowed forged messages and administrative control over the token contract, leading to roughly $237,000 in profits.
A cross-chain exploit has hit Hyperbridge, with attackers minting 1 billion unauthorized bridged DOT on Ethereum after compromising a core contract in the protocol’s message flow.
Hyperbridge, an interoperability protocol built on Polkadot, was targeted through its gateway contract, according to onchain analysts and security researchers. The flaw reportedly allowed the attacker to forge messages, seize administrative control of the bridged token contract on Ethereum and mint a massive quantity of fake DOT.
Forged messages turned a bridge function into a minting tool
That is the part that matters most. In cross-chain systems, message verification is the whole game. If an attacker can forge those messages, they do not just bypass