Hyperbridge: The vulnerability in this attack incident originates from a flaw in the Merkle proof verification logic
The blockchain interoperability protocol Hyperbridge disclosed details of the previous DOT attack incident, resulting in a loss of approximately $237,000. The root of the vulnerability lies in the HandlerV1 contract's VerifyProof() function, which lacks input validation and does not verify the leaf_index leafCount, allowing attackers to forge Merkle proofs.
Using this, the attacker gained administrator privileges for the DOT token bridging contract on Ethereum, subsequently minting 1 billion bridged DOT (which is about 2800 times the legitimate circulation of approximately 356,000) and cashing out on decentralized exchanges. Hyperbridge stated that it is currently working with security partners to trace the funds, and cross-chain functionality will remain suspended until the investigation is completed.
You may also like

Congratulations to Carl Moon on His Historic Ferrari Challenge Le Mans Podium Triumph

A16Z: The sun bears witness, SpaceX is worth 7.5 trillion

The stablecoin positioning battle escalates: When compliance is just a ticket to entry, will USD1 become the biggest winner?

Can the CLARITY Act Become Law by July 4? Everything You Need to Know About the Final Battle

How to exit after asset tokenization?

The foundation of SpaceX's trillion-dollar valuation: Who is dividing Musk's annual capital expenditure of tens of billions?

France vs Senegal World Cup 2026: Mbappe’s New Era Begins Against a Historic Rival

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

What is the connection between Huang Zheng of Pinduoduo and blockchain?

Morning Report | Prediction market platforms like Kalshi and Polymarket jointly sue Kentucky over 14.25% trading tax; Bridgewater founder discusses decision-making in the AI era: principled thinking should run parallel to AI, human insight remains irre...

If the AI bubble has already burst, who will truly remain?

Paul Graham: How to Make a Billion Dollars

After 18 years, blockchain has finally started to head towards the main channel

Claude enforces "facial recognition for household registration," starting in July, no ID card means no access?

On the day of SpaceX's IPO, the first real test of the three perpetual mechanisms

Value Distribution of Stablecoins


