← Radar

Incident case file

Sign in to watch

Hyperbridge — MMR Proof Verification Flaw / Forged ISMP PostRequest

Incident date April 13, 2026

0 views

Funds movingEthereumBaseBNB ChainArbitrumBridge exploitCluster: HYPERBRIDGE-MMR-2026-04

Estimated loss

$2.5M

Victims identified

8
Victim group joining is coming soon.

Investigation

40%

Facts and investigation

Attacker: 0xC513E4f5D7a93A1Dd5B7C4D9f6cC2F52d2F1F8E7

Funds moved to: 1B bridged DOT dumped into ~108.2 ETH atomically. Phase 1: 245 ETH extracted from Token Gateway ~1h before main exploit. Funds moving toward Binance.
0x518AB393c3F42613D010b54A9dcBe211E3d48f26. Helper Contract: 0x31a165a956842aB783098641dB25C7a9067ca9AB. Bridged DOT token (ERC-6160): 0x8d010bf9C26881788b4e6bf5Fd1bdC358c8F90b8.

Timeline: April 13, 2026 — Phase 1: attacker extracts 245 ETH from Token Gateway via first proof forgery. ~1 hour later — Phase 2: attacker forges an ISMP PostRequest by exploiting an edge-case in solidity-merkle-trees MerkleMountainRange.CalculateRoot (when leafCount == 1 and leaf_index == 1, stale historical root promoted as valid). Mints 1,000,000,000 bridged DOT, dumps atomically into 108.2 ETH (tx: 0x240aeb…1109). Token Gateway drained. Hyperbridge pauses all bridging operations. BlockSec Phalcon publishes root cause on X. April 16 — Post-mortem revises losses to ~$2.5M across 4 EVM chains. Compensation in BRIDGE token planned for April 13, 2027 if recovery insufficient.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)