Polkadot Bridge Exploit Mints 1B DOT on Ethereum, Nets $237K

Polkadot bridge exploit Hyperbridge Ethereum DOT tokens

An attacker exploited a state proof vulnerability in Hyperbridge’s Ethereum gateway contract on April 13, 2026, minting roughly 1 billion bridged Polkadot (DOT) tokens before dumping them for approximately $237,000 in ether. The theft — capped by thin liquidity in the Ethereum DOT pool — represents one of the more technically precise bridge attacks this year, and marks the second exploit of the same system within a single day. A separate earlier attack using identical methodology drained around $12,000 in MANTA and CERE tokens.

A blockchain bridge is a protocol that lets tokens move between two separate networks — in this case, between Polkadot’s relay chain and Ethereum — by locking assets on one side and minting equivalent tokens on the other.

Key Takeaways

  • An attacker forged cross-chain state proofs to seize admin and minting rights over the bridged DOT token contract on Ethereum, minting approximately 1 billion tokens against an existing supply of just 356,000.
  • The exploiter dumped the minted tokens via OdosRouter and Uniswap V4, netting roughly 108.2 ETH (~$237,000); shallow pool liquidity prevented a significantly larger theft.
  • Native DOT on Polkadot’s relay chain was unaffected, though the token’s price dropped approximately 4.8% to $1.16 following news of the exploit.
  • Hyperbridge and its developer Polytope Labs had not issued an official mitigation statement at the time of publication.

Published: April 13, 2026 UTC

How the attacker got in

Hyperbridge uses the Interoperable State Machine Protocol (ISMP) to relay verified messages between Polkadot and Ethereum. The vulnerability sat in the HandlerV1 contract (0x6c8…4E6D64), which is responsible for validating incoming cross-chain state proofs before passing them to the TokenGateway.

The attacker deployed a master contract and a helper contract in a single transaction. The helper submitted forged state proofs to HandlerV1, bypassing verification checks in the ISMP pipeline. The malicious payload included a ChangeAssetAdmin action, which was routed through TokenGateway.onAccept() and transferred admin and minter privileges on the DOT ERC-20 contract (0x8d…8F90b8) to the attacker’s wallet (0xc513…f1f8e7). From there, minting 1 billion tokens took seconds.

Security firms CertiK and PeckShield both flagged the exploit via on-chain alerts within hours of the first transaction hitting the mempool.

Why the damage was limited — and why that’s not reassuring

The attacker’s actual take was constrained by one thing: not enough buyers. The Ethereum DOT pool held limited liquidity, and the sudden dump of nearly 1 billion tokens against a supply of 356,000 collapsed the bridged token price from around $1.22 to fractions of a cent. Total profit: roughly $237,000. Had the same attack targeted a higher-liquidity pool or a larger-cap bridged asset, the losses would have scaled accordingly.

That’s the concern security analysts are raising. According to Chainalysis data, centralized bridge failures account for more than 60% of all crypto hack losses, with cumulative thefts exceeding $2 billion. March 2026 alone saw approximately $52 million stolen across around 20 separate incidents — nearly double February’s total.

This exploit follows a pattern. In August 2022, Polkadot’s ecosystem saw the Acala DeFi hub exploited when attackers minted over 1.2 billion aUSD stablecoins through a liquidity pool misconfiguration. The playbook — identify a minting permission flaw, inflate supply, dump before the market reacts — has not changed. The targets have.

What happens next for Hyperbridge

Hyperbridge was built by Polytope Labs, a Nigerian-founded startup that positioned the protocol as a more secure alternative to earlier bridge designs. As of publication, neither Polytope Labs nor the Hyperbridge team had circulated a post-mortem or announced a contract pause or patch. That silence has drawn criticism from the on-chain security community given that the same attack vector was used twice in one day.

For protocols currently bridging assets through Hyperbridge, the immediate question is whether the HandlerV1 contract will be patched or whether a new deployment will be required. A contract migration would mean pausing all in-flight cross-chain transactions — a disruptive but necessary step if the root proof-verification flaw is confirmed at the ISMP layer.

For the broader Web3 space, the incident is another data point in the ongoing argument that cross-chain interoperability, while necessary, remains the industry’s most reliably exploited attack surface.

Was Polkadot’s native DOT token stolen in this exploit?

No. The exploit targeted only the ERC-20 bridged version of DOT on Ethereum managed by Hyperbridge. Polkadot’s native relay chain and the native DOT token were unaffected. The native DOT price dropped about 4.8% in the hours after the incident, reflecting market concern rather than any direct security breach of the Polkadot network itself.

What is Hyperbridge and who built it?

Hyperbridge is a cross-chain interoperability protocol built by Polytope Labs, a startup founded in Nigeria. It uses the Interoperable State Machine Protocol (ISMP) to relay cryptographically verified messages between Polkadot and other networks including Ethereum. The project launched on Polkadot’s mainnet and was designed to address security weaknesses in older bridge designs — an aim now under scrutiny after two exploits in one day.

How did liquidity cap the attacker’s profit?

The attacker minted approximately 1 billion bridged DOT tokens against an existing circulating supply of just 356,000 — about 2,805 times the prior supply. When those tokens were sold via OdosRouter and Uniswap V4, the pool couldn’t absorb the volume. The bridged DOT price collapsed from around $1.22 to near zero, and the attacker extracted only about 108.2 ETH (~$237,000) before liquidity ran out. A deeper pool would have produced a proportionally larger theft.


Frequently asked questions

What is a blockchain bridge and why is it a target?

A bridge lets tokens move between two separate networks by locking assets on one side and minting equivalents on the other. That minting authority is the prize: an attacker who compromises it can create tokens that were never backed by anything.

How did the attacker mint a billion DOT?

They submitted forged cross-chain state proofs to Hyperbridge's HandlerV1 contract, bypassing verification in the ISMP pipeline. The payload carried a ChangeAssetAdmin action that handed admin and minter rights on the bridged DOT contract to the attacker's wallet.

Was native DOT on Polkadot affected?

No. Only the bridged representation on Ethereum was compromised; DOT on Polkadot's relay chain was untouched. The token's price still fell around 4.8% to $1.16 on the news.

Why did the attacker only realise about $237,000?

Liquidity, not security, capped the loss. The Ethereum DOT pool was too thin to absorb the dump, so roughly 1 billion minted tokens converted to only about 108.2 ETH. A deeper pool would have meant a far larger theft from the same exploit.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *