Incident case file
Sign in to watchHyperbridge — MMR Proof Verification Flaw / Forged ISMP PostRequest
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xC513E4f5D7a93A1Dd5B7C4D9f6cC2F52d2F1F8E7
Timeline: April 13, 2026 — Phase 1: attacker extracts 245 ETH from Token Gateway via first proof forgery. ~1 hour later — Phase 2: attacker forges an ISMP PostRequest by exploiting an edge-case in solidity-merkle-trees MerkleMountainRange.CalculateRoot (when leafCount == 1 and leaf_index == 1, stale historical root promoted as valid). Mints 1,000,000,000 bridged DOT, dumps atomically into 108.2 ETH (tx: 0x240aeb…1109). Token Gateway drained. Hyperbridge pauses all bridging operations. BlockSec Phalcon publishes root cause on X. April 16 — Post-mortem revises losses to ~$2.5M across 4 EVM chains. Compensation in BRIDGE token planned for April 13, 2027 if recovery insufficient.
Sources and coverage
- Articleblog.hyperbridge.networkhttps://blog.hyperbridge.network/security-update-forged-proofs/
- Articleblog.hyperbridge.networkhttps://blog.hyperbridge.network/recovery-and-next-steps/
- Articlebeincrypto.comhttps://beincrypto.com/hyperbridge-exploit-losses-revised-25m/
- Articlecryip.cohttps://cryip.co/polkadot-bridge-exploit-technical-incident-analysis/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/04/13/hyperbridge-responds-to-237k-exploit-pauses-bridge-activity/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)