Blockchain security firm CertiK has reported a major exploit involving the Hyperbridge gateway, enabling an attacker to mint approximately 1 billion unauthorized Polkadot (DOT) tokens on the Ethereum network.
According to CertiK’s analysis, the vulnerability stemmed from the Hyperbridge gateway smart contract, which allowed the attacker to forge cross-chain messages.
This flaw effectively granted unauthorized control over the minting mechanism, enabling the creation of a massive number of wrapped DOT tokens on Ethereum.
Despite the scale of the exploit, the impact on the broader Polkadot ecosystem appears limited. The unauthorized tokens were confined to the Ethereum-based bridged version of DOT and did not affect the native Polkadot network or its total token supply.
On-chain data suggests that the attacker moved quickly to liquidate a portion of the minted tokens. However, due to relatively low liquidity in the affected trading pools, the exploiter was only able to extract an estimated $200,000 to $250,000 in value.
The incident briefly impacted market sentiment, with DOT experiencing a short-term price dip before stabilizing.
Analysts note that such exploits highlight ongoing risks associated with cross-chain bridge infrastructure, which has historically been a frequent target for attackers due to its complexity and high-value asset flows.
Security experts emphasize the importance of rigorous auditing and real-time monitoring for bridge protocols, as vulnerabilities in these systems can lead to disproportionate headline risks even when actual financial damage is contained.
The Hyperbridge exploit adds to a growing list of bridge-related incidents in the crypto industry, reinforcing concerns around interoperability security as decentralized finance continues to expand across multiple blockchain networks.
