Certik reported a significant exploit of the Hyperbridge gateway, which allowed the perpetrator to mint 1 billion unauthorized DOT tokens on the Ethereum network.
Key Takeaways:
A hacker used a replay flaw to mint 1 billion fake Polkadot tokens via the Hyperbridge gateway. The price of DOT dropped 6% to $1.16 before recovering, while the hacker netted $237,000 in ether. Hyperbridge developers are now expected to deploy patches to secure administrative smart contract functions. Liquidity Bottleneck Limits LossesSecurity experts were quick to clarify that the breach was localized to the Hyperbridge gateway on Ethereum. Polkadot’s core relay chain and the authentic DOT tokens residing on the Polkadot network remain secure and were not impacted by the incident.
As a result, malicious code propagated unchecked through the system, ultimately enabling the attacker to change the admin of the Polkadot token. As Certik noted:
“The attacker submitted ‘proof’ value is copied from the ‘_stateCommitments’ in a previous txn… thus making the replay possible.”














