The Hyperbridge contract encountered an MMR proof replay vulnerability, resulting in a loss of approximately $242,000
According to market news, the HandlerV1 contract managed by Hyperbridge has a Merkle Mountain Range (MMR) proof replay vulnerability on the Ethereum network, resulting in a loss of approximately $242,000. The vulnerability arises from the proof not being bound to the request, allowing attackers to replay historically valid proofs in conjunction with new forged requests to perform operations such as changing administrator permissions.
In a specific case, the attacker changed the administrator of the Polkadot (DOT) Token and used the permissions to mint additional DOT for profit. Related attack transactions have been observed, including changing the administrator and minting of the DOT Token (loss of approximately $237,400), changing the administrator and minting of the ARGN Token (loss of approximately $3,800), and host withdrawals. The vulnerability was discovered by PhalconSecurity and analyzed through PhalconExplorer. Previously, it was reported that the Hyperbridge gateway contract was attacked, resulting in the minting and dumping of 1 billion DOT on Ethereum.
You may also like

Can the CLARITY Act Become Law by July 4? Everything You Need to Know About the Final Battle

How to exit after asset tokenization?

The foundation of SpaceX's trillion-dollar valuation: Who is dividing Musk's annual capital expenditure of tens of billions?

France vs Senegal World Cup 2026: Mbappe’s New Era Begins Against a Historic Rival

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

What is the connection between Huang Zheng of Pinduoduo and blockchain?

Morning Report | Prediction market platforms like Kalshi and Polymarket jointly sue Kentucky over 14.25% trading tax; Bridgewater founder discusses decision-making in the AI era: principled thinking should run parallel to AI, human insight remains irre...

If the AI bubble has already burst, who will truly remain?

Paul Graham: How to Make a Billion Dollars

After 18 years, blockchain has finally started to head towards the main channel

Claude enforces "facial recognition for household registration," starting in July, no ID card means no access?

On the day of SpaceX's IPO, the first real test of the three perpetual mechanisms

Value Distribution of Stablecoins

Galaxy Deep Dive: Is the Bitcoin Four-Year Cycle Still Valid?

SpaceX IPO, Nvidia, and Bitcoin: Why Traders Are Watching More Than Just Crypto in 2026

The other side of Musk's trillion-dollar fortune: 85% cannot be sold





