Hyperbridge Token Gateway hack — April 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 13, 2026 |
| Target type | Cross-chain bridge |
| Loss | $2,500,000Published estimates range $237,000 to $2,500,000Price at time of incident |
| Method | Signature verification flawThe Token Gateway's Merkle Mountain Range (MMR) proof verifier failed to check that every leaf in a submitted proof fell within the range's bounds, so a proof containing an out-of-bounds leaf index passed verification and a forged cross-chain message was accepted as genuine. A second defect allowed administrative rights on the bridged DOT contract on Ethereum to be transferred instantly with no timelock. Together these let the attacker seize the token contract's admin role and mint roughly 1 billion unbacked synthetic DOT. |
| Chains | Ethereum, Base, BNB Chain, Arbitrum |
| Outcome | Partially recovered |
What happened
Hyperbridge, a cross-chain interoperability protocol built by Polytope Technology to connect Polkadot with EVM chains, lost control of its Token Gateway contracts on 13 April 2026.
The protocol's own post-mortem traces the failure to its Merkle Mountain Range proof verifier, citing a lack of checks on the boundaries of proof indexes and poor linkage of proofs to their respective requests. An attacker could therefore submit a proof whose leaf index fell outside the range's bounds and have a forged cross-chain message accepted as genuine. A second weakness let administrative rights on the bridged DOT contract on Ethereum be transferred instantly, with no timelock. Using both, the attacker reassigned the contract's admin, minted roughly one billion synthetic DOT that had no backing on Polkadot, and sold them into on-chain liquidity. Hyperbridge stressed that these were bugs in the implementation of proof verification, not in the design of the state-proof mechanism itself.
The reported loss changed substantially and the figures are not reconciled. CertiK put the attacker's realised profit at approximately $237,000 from minting and selling the fake tokens, a figure crypto.news reports as 108.2 ETH, and that number was carried by most day-one coverage. The Crypto Times reported on 16 April that Hyperbridge had raised its estimate to approximately $2.5 million, with most of the increase reflecting damage to DeFi Singularity incentive pools deployed on Ethereum, Base, BNB Chain and Arbitrum, which held Cere and Bifrost assets. Hyperbridge's own follow-up post describes realised losses as 'over $2 million'. The larger figures reflect drained pool reserves rather than the attacker's realised profit, so the numbers measure different things; both bounds are recorded here because no party has published a reconciliation.
Hyperbridge paused the gateway on detection, deployed a patch within 72 hours and commissioned an independent audit by Security Research Labs (SRLabs), a Berlin-based firm, which found further issues in upstream libraries. It opened a 14-day return window with no identification and no follow-up for any wallet returning funds voluntarily, after which unreturned assets would be referred to the authorities. The first voluntary return was 5.44346 ETH and 179,624.7394450041 CERE, a small fraction of the total. Polkadot's own network was unaffected.
Law enforcement
Hyperbridge said wallets that did not return funds within its 14-day voluntary return window would be referred to the authorities; it also said it was engaging with Binance over funds routed through the exchange. No named agency case is public.
Sources
- Hyperbridge (Polytope Technology)Primary · retrieved 2026-08-01
- Hyperbridge (Polytope Technology)Primary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.hyperbridge.network/april-13-post-mortem/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Hyperbridge Token Gateway hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/hyperbridgehttps://itokenly.com/hacks/hyperbridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.