Hyperbridge: The vulnerability in this attack incident originates from a flaw in the Merkle proof verification logic

By: rootdata|2026/04/13 21:42:01
0
Share
copy

The blockchain interoperability protocol Hyperbridge disclosed details of the previous DOT attack incident, resulting in a loss of approximately $237,000. The root of the vulnerability lies in the HandlerV1 contract's VerifyProof() function, which lacks input validation and does not verify the leaf_index leafCount, allowing attackers to forge Merkle proofs.

Using this, the attacker gained administrator privileges for the DOT token bridging contract on Ethereum, subsequently minting 1 billion bridged DOT (which is about 2800 times the legitimate circulation of approximately 356,000) and cashing out on decentralized exchanges. Hyperbridge stated that it is currently working with security partners to trace the funds, and cross-chain functionality will remain suspended until the investigation is completed.

-- Price

--

You may also like

Popular coins

Latest Crypto News

Read more