{"investigation":{"slug":"hyperbridge","entity_name":"Hyperbridge","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Hyperbridge is a cross-chain interoperability protocol built by Polytope Labs (founded by Nigerian engineers Seun Lanlege and David Salami) that uses cryptographic proofs to facilitate asset and message transfers across blockchains. On April 13, 2026, an attacker exploited a Merkle Mountain Range (MMR) proof verification vulnerability in the Token Gateway contract, minting 1 billion fraudulent bridged DOT tokens and extracting losses initially reported at $237,000 but later revised to approximately $2.5 million across Ethereum, Base, BNB Chain, and Arbitrum. The exploit occurred less than two weeks after the project publicly mocked the possibility of being hacked in an April Fools joke, and followed alleged dismissals of security researchers who had flagged vulnerabilities beforehand.","sections":[{"content":"On April 13, 2026, an attacker exploited a critical vulnerability in Hyperbridge's Token Gateway smart contract on Ethereum. The root cause was a flaw in the Merkle Mountain Range (MMR) verifier: the verifier accepted an out-of-bounds leaf index without detecting leftover leaves after processing peaks, allowing a forged proof to pass as valid. A secondary compounding factor was a zero-second challenge period that removed the last safety valve — forged proofs executed immediately without a dispute window. Using this forged proof, the attacker seized administrative control of the bridged DOT token contract on Ethereum and minted approximately 1 billion fake bridged Polkadot (DOT) tokens, nominally worth about $1.19 billion at prevailing prices. The attacker routed the tokens through Odos Router V3 into a Uniswap V4 DOT-ETH pool, cashing out roughly 108.2 ETH (approximately $237,000) limited by shallow pool liquidity. Following a comprehensive review of attacker activity across all four connected EVM chains (Ethereum, Base, BNB Chain, Arbitrum), the two-phase nature of the attack, and associated incentive pool losses, Hyperbridge revised the total realized loss to approximately $2.5 million denominated in ETH and DOT at exploit-time — approximately ten times the initial estimate. Native DOT on the Polkadot relay chain and parachains was not affected. A significant portion of stolen funds was subsequently traced to Binance, and Hyperbridge stated it was cooperating with Binance compliance and law enforcement on potential asset freezes.","heading":"April 13, 2026 Token Gateway Exploit","sources":[{"url":"https://blog.hyperbridge.network/april-13-post-mortem/","name":"blog.hyperbridge.network","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2026/04/13/attacker-mints-usd1-billion-polkadot-tokens-on-ethereum-ends-up-stealing-just-usd250-000","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/hacker-steals-237k-1b-bridged-dot-hyperbridge","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/04/16/hyperbridge-raises-exploit-loss-estimate-to-2-5m-from-237k/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.theblock.co/post/397773/polkadot-hyperbridge-exploit-losses-2-5-million-ten-times-initial-estimate","name":"theblock.co","type":"other","credibility":3},{"url":"https://beincrypto.com/hyperbridge-exploit-losses-revised-25m/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://ambcrypto.com/hyperbridge-revises-exploit-losses-to-2-5m-traces-funds-to-binance/","name":"ambcrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 1, 2026, approximately 12 days before the actual exploit, Hyperbridge published a post on X (formerly Twitter) falsely claiming the North Korean Lazarus Group had drained $37 million from the protocol. A linked blog post contained a Rickroll GIF and an article titled 'Why Hyperbridge Can't Be Hacked,' referencing fictional attack vectors including quantum computing and rogue AI agents. The original prank posts were subsequently deleted after the real exploit occurred. Around April 2, 2026, after a known exploiter address began probing the bridge, a Hyperbridge developer dismissed the attempts with the comment 'hope you have a quantum computer bro.' According to reports, another developer noted at the time: 'Rule #1 dont actively provoke attackers.' The team later acknowledged that early security warnings were dismissed as April Fools' pranks, calling it 'a critical error.' Prior to the exploit, Hyperbridge had publicly marketed itself as 'the world's safest bridge,' stating in September 2025 that it 'replaces multisigs and MPC solutions, which have been at the centre of the largest bridge hacks with secure cryptographic proofs.' These prior claims drew significant scrutiny following the April 2026 incident.","heading":"April Fools Prank and Prior Overconfidence","sources":[{"url":"https://protos.com/hyperbridge-exploited-less-than-two-weeks-after-april-fools-day-hack-prank/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=hyperbridge-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/polkadot-hyperbridge-april-fools-joke-comes-true-as-over-1-billion-fake-dot-tokens-were-minted-on-ethereum/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://ambcrypto.com/hyperbridge-exploit-lets-attacker-mint-1b-bridged-dot-raising-questions-after-safest-bridge-claims/","name":"ambcrypto.com","type":"other","credibility":3},{"url":"https://blog.hyperbridge.network/explained-hack-april-fool/","name":"blog.hyperbridge.network","type":"other","credibility":3}],"severity":"medium"},{"content":"Reports and screenshots circulated in early 2026 indicate that in February 2026 a bug bounty hunter flagged critical vulnerabilities to the Hyperbridge team and allegedly received the response 'exploit them if you found them.' The Hyperbridge team had previously offered a $250,000 bug bounty program across Immunefi, Cantina, and Hacken platforms and claimed no critical vulnerabilities had been reported. Following the April 13 exploit, Hyperbridge launched a new public bug bounty on HackenProof offering up to $50,000 for critical vulnerabilities. A post-exploit independent security audit by Security Research Labs (SRLabs) identified 14 vulnerabilities in total: 1 critical, 3 high, 5 medium, 4 low, and 1 informational, all of which were reported as remediated. The existence of a critical vulnerability discovered post-exploit raises questions about the adequacy of pre-exploit audit coverage. The alleged dismissal of the February 2026 bug report, if accurate, represents a significant failure in security operations. These claims are sourced primarily from secondary media reporting and carry medium confidence absent primary documentation.","heading":"Alleged Pre-Exploit Dismissal of Security Researchers","sources":[{"url":"https://protos.com/hyperbridge-exploited-less-than-two-weeks-after-april-fools-day-hack-prank/","name":"protos.com","type":"other","credibility":3},{"url":"https://crypto.news/hyperbridge-launches-50k-bug-bounty-after-bridge-exploit/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/05/15/hyperbridge-offers-50000-for-critical-vulnerabilities/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.autheo.com/blog/bridge-security-lessons-hyperbridge-exploit-2026","name":"autheo.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Hyperbridge stated it would not resume Token Gateway bridging operations until the vulnerability was fully patched, an independent audit was completed and published, and additional safeguards were operational. A patch was reportedly deployed within 72 hours. Regarding user compensation, Hyperbridge stated that if recovery of stolen funds falls short, affected users will be made whole through a structured distribution of BRIDGE tokens (the protocol's native asset) on April 13, 2027, one year after the exploit. The compensation mechanism details, including disbursement schedule and valuation methodology, were deferred to that date. A discussion thread on the Polkadot governance forum proposed a DOT recovery loan from the Polkadot Treasury to compensate liquidity providers, with Hyperbridge/Polytope Labs assuming repayment obligations. LP losses were estimated at $1.5 to $1.8 million before deducting earned vDOT rewards, with a proposed 12-month linear vesting schedule. Community response was divided: supporters cited Hyperbridge's status as officially designated Polkadot infrastructure; critics raised concerns about setting bailout precedent and questioned the enforceability of Hyperbridge's repayment guarantees. The Polkadot governance proposal had not reached a final vote as of late May 2026.","heading":"Compensation Plan and Recovery Status","sources":[{"url":"https://blog.hyperbridge.network/recovery-and-next-steps/","name":"blog.hyperbridge.network","type":"other","credibility":3},{"url":"https://phemex.com/news/article/hyperbridge-revises-hack-losses-to-25-million-plans-compensation-73722","name":"phemex.com","type":"other","credibility":3},{"url":"https://forum.polkadot.network/t/pre-proposal-discussion-dot-recovery-loan-to-hyperbridge-token-gateway-exploit-victims/17552","name":"forum.polkadot.network","type":"other","credibility":3},{"url":"https://beincrypto.com/hyperbridge-exploit-losses-revised-25m/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Hyperbridge is developed by Polytope Labs, a Nigerian-founded company co-founded by Seun Lanlege and David Salami, both former Ethereum and Polkadot protocol engineers. The protocol launched on Polkadot mainnet in 2024 and raised approximately $5.55 million in total funding, including a seed round and a public sale, with backing from the Polkadot ecosystem fund, Web3 Foundation, and Scytale Digital. The Polkadot DAO voted to designate Hyperbridge as the native bridge for the Polkadot network. As of 2025, the protocol had processed over $180 million in transaction volume and 53,000+ cross-chain messages, and claimed to support over 12 chains including Ethereum, Arbitrum, Base, BNB Chain, and Polkadot. Prior to the April 2026 exploit, Hyperbridge had not reported any significant security incidents. A pre-exploit audit was conducted by Security Research Labs (SRLabs), the same firm that audits the Polkadot chain, with the last engagement in 2024.","heading":"Protocol Background and Prior Track Record","sources":[{"url":"https://techpoint.africa/feature/how-hyperbridge-works-seun-lanlege/","name":"techpoint.africa","type":"other","credibility":3},{"url":"https://techcabal.com/2025/04/17/polytope-labs-raises-over-5-million-to-scale-hyperbridge-backed-by-the-polkadot-ecosystem-fund/","name":"techcabal.com","type":"other","credibility":3},{"url":"https://polkadot.com/newsroom/press-releases/hyperbridge-launches-on-Polkadot/","name":"polkadot.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Hyperbridge","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://bitcoinke.io/2025/11/a-look-at-hyperbridge/","name":"bitcoinke.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 13, 2026 exploit, a portion of the stolen funds — reported as approximately 245 ETH extracted from the TokenGateway contract — was deposited into Tornado Cash, the OFAC-sanctioned Ethereum mixing service. This obfuscation step is consistent with patterns observed in other DeFi exploits and complicates law enforcement recovery efforts. Hyperbridge stated it was working with Binance's compliance team and law enforcement, and cautioned that meaningful recovery could take months to a year.","heading":"Use of Tornado Cash by Attacker","sources":[{"url":"https://protos.com/hyperbridge-exploited-less-than-two-weeks-after-april-fools-day-hack-prank/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.tronweekly.com/hyperbridge-suffers-237000-breach-as-token-gate/","name":"tronweekly.com","type":"other","credibility":3},{"url":"https://ambcrypto.com/hyperbridge-revises-exploit-losses-to-2-5m-traces-funds-to-binance/","name":"ambcrypto.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-11","event":"Polytope Labs publicly launches Hyperbridge cross-chain bridge.","source":"","date_original":"2023-11-01"},{"date":"2024","event":"Hyperbridge launches on Polkadot mainnet.","source":"","date_original":"2024-01-01"},{"date":"2025-04-17","event":"Polytope Labs announces over $5 million in funding backed by the Polkadot Ecosystem Fund, Web3 Foundation, and Scytale Digital.","source":""},{"date":"2025-09-30","event":"Hyperbridge expands to Polygon mainnet; team markets protocol as 'the world's safest bridge' in official materials.","source":""},{"date":"2026-02","event":"Alleged: a bug bounty researcher reports critical vulnerabilities and is reportedly told 'exploit them if you found them' by the team.","source":"","date_original":"2026-02-01"},{"date":"2026-04","event":"Hyperbridge posts April Fools' joke on X claiming the Lazarus Group drained $37 million; linked blog post contains Rickroll GIF and article titled 'Why Hyperbridge Can't Be Hacked.'","source":"","date_original":"2026-04-01"},{"date":"2026-04-02","event":"A known exploiter address begins probing Hyperbridge; a developer dismisses attempts with 'hope you have a quantum computer bro.'","source":""},{"date":"2026-04-13","event":"Exploit occurs: attacker forges an MMR proof to seize admin control of the bridged DOT contract on Ethereum and mints 1 billion fake DOT tokens, extracting approximately 108.2 ETH (~$237,000) and an estimated 245 ETH from the TokenGateway contract, with funds deposited into Tornado Cash.","source":""},{"date":"2026-04-13","event":"Hyperbridge pauses Token Gateway operations; patch deployed within 72 hours; April Fools posts deleted.","source":""},{"date":"2026-04-16","event":"Hyperbridge revises total exploit losses to approximately $2.5 million — ten times the initial estimate — after reconciling activity across Ethereum, Base, BNB Chain, and Arbitrum.","source":""},{"date":"2026-04-16","event":"Stolen funds traced in part to Binance; Hyperbridge states it is cooperating with Binance compliance and law enforcement.","source":""},{"date":"2026-04-25","event":"Polkadot Forum pre-proposal discussion published proposing a DOT recovery loan from the Polkadot Treasury for liquidity providers affected by the exploit.","source":""},{"date":"2026-05-15","event":"Hyperbridge launches $50,000 bug bounty on HackenProof for critical vulnerabilities, following post-exploit SRLabs audit that found 14 vulnerabilities (1 critical, 3 high, 5 medium, 4 low, 1 informational), all reportedly remediated.","source":""}],"sources_used":[{"url":"https://blog.hyperbridge.network/april-13-post-mortem/","name":"blog.hyperbridge.network","type":"other","archive_url":"http://web.archive.org/web/20260514140554/https://blog.hyperbridge.network/april-13-post-mortem/","credibility":3,"archive_timestamp":"2026-05-14T14:05:54+00:00"},{"url":"https://www.coindesk.com/tech/2026/04/13/attacker-mints-usd1-billion-polkadot-tokens-on-ethereum-ends-up-stealing-just-usd250-000","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260414060617/https://www.coindesk.com/tech/2026/04/13/attacker-mints-usd1-billion-polkadot-tokens-on-ethereum-ends-up-stealing-just-usd250-000","credibility":3,"archive_timestamp":"2026-04-14T06:06:17+00:00"},{"url":"https://cointelegraph.com/news/hacker-steals-237k-1b-bridged-dot-hyperbridge","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260726231140/https://cointelegraph.com/news/hacker-steals-237k-1b-bridged-dot-hyperbridge","credibility":3,"archive_timestamp":"2026-07-26T23:11:40+00:00"},{"url":"https://www.cryptotimes.io/2026/04/16/hyperbridge-raises-exploit-loss-estimate-to-2-5m-from-237k/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260728111654/https://www.cryptotimes.io/2026/04/16/hyperbridge-raises-exploit-loss-estimate-to-2-5m-from-237k/","credibility":3,"archive_timestamp":"2026-07-28T11:16:54+00:00"},{"url":"https://www.theblock.co/post/397773/polkadot-hyperbridge-exploit-losses-2-5-million-ten-times-initial-estimate","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260417045953/https://www.theblock.co/post/397773/polkadot-hyperbridge-exploit-losses-2-5-million-ten-times-initial-estimate","credibility":3,"archive_timestamp":"2026-04-17T04:59:53+00:00"},{"url":"https://beincrypto.com/hyperbridge-exploit-losses-revised-25m/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://ambcrypto.com/hyperbridge-revises-exploit-losses-to-2-5m-traces-funds-to-binance/","name":"ambcrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260417081434/https://ambcrypto.com/hyperbridge-revises-exploit-losses-to-2-5m-traces-funds-to-binance/","credibility":3,"archive_timestamp":"2026-04-17T08:14:34+00:00"},{"url":"https://protos.com/hyperbridge-exploited-less-than-two-weeks-after-april-fools-day-hack-prank/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260816110205/https://protos.com/hyperbridge-exploited-less-than-two-weeks-after-april-fools-day-hack-prank/","credibility":3,"archive_timestamp":"2026-08-16T11:02:05+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=hyperbridge-exploit","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260519103836/https://www.web3isgoinggreat.com/?id=hyperbridge-exploit","credibility":3,"archive_timestamp":"2026-05-19T10:38:36+00:00"},{"url":"https://cryptoslate.com/polkadot-hyperbridge-april-fools-joke-comes-true-as-over-1-billion-fake-dot-tokens-were-minted-on-ethereum/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260606232013/https://cryptoslate.com/polkadot-hyperbridge-april-fools-joke-comes-true-as-over-1-billion-fake-dot-tokens-were-minted-on-ethereum/","credibility":3,"archive_timestamp":"2026-06-06T23:20:13+00:00"},{"url":"https://ambcrypto.com/hyperbridge-exploit-lets-attacker-mint-1b-bridged-dot-raising-questions-after-safest-bridge-claims/","name":"ambcrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260414082619/https://ambcrypto.com/hyperbridge-exploit-lets-attacker-mint-1b-bridged-dot-raising-questions-after-safest-bridge-claims/","credibility":3,"archive_timestamp":"2026-04-14T08:26:19+00:00"},{"url":"https://blog.hyperbridge.network/explained-hack-april-fool/","name":"blog.hyperbridge.network","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://crypto.news/hyperbridge-launches-50k-bug-bounty-after-bridge-exploit/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260727093837/https://crypto.news/hyperbridge-launches-50k-bug-bounty-after-bridge-exploit/","credibility":3,"archive_timestamp":"2026-07-27T09:38:37+00:00"},{"url":"https://www.cryptotimes.io/2026/05/15/hyperbridge-offers-50000-for-critical-vulnerabilities/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260727103438/https://www.cryptotimes.io/2026/05/15/hyperbridge-offers-50000-for-critical-vulnerabilities/","credibility":3,"archive_timestamp":"2026-07-27T10:34:38+00:00"},{"url":"https://www.autheo.com/blog/bridge-security-lessons-hyperbridge-exploit-2026","name":"autheo.com","type":"other","archive_url":"http://web.archive.org/web/20260727005431/https://www.autheo.com/blog/bridge-security-lessons-hyperbridge-exploit-2026","credibility":3,"archive_timestamp":"2026-07-27T00:54:31+00:00"},{"url":"https://blog.hyperbridge.network/recovery-and-next-steps/","name":"blog.hyperbridge.network","type":"other","archive_url":"http://web.archive.org/web/20260509111244/https://blog.hyperbridge.network/recovery-and-next-steps/","credibility":3,"archive_timestamp":"2026-05-09T11:12:44+00:00"},{"url":"https://phemex.com/news/article/hyperbridge-revises-hack-losses-to-25-million-plans-compensation-73722","name":"phemex.com","type":"other","archive_url":"http://web.archive.org/web/20260727003135/https://phemex.com/news/article/hyperbridge-revises-hack-losses-to-25-million-plans-compensation-73722","credibility":3,"archive_timestamp":"2026-07-27T00:31:35+00:00"},{"url":"https://forum.polkadot.network/t/pre-proposal-discussion-dot-recovery-loan-to-hyperbridge-token-gateway-exploit-victims/17552","name":"forum.polkadot.network","type":"other","archive_url":"https://web.archive.org/web/20260830115508/https://forum.polkadot.network/t/updated-pre-proposal-discussion-dot-recovery-loan-to-hyperbridge-exploit-victims/17552","credibility":3,"archive_timestamp":"2026-08-30T11:55:08+00:00"},{"url":"https://techpoint.africa/feature/how-hyperbridge-works-seun-lanlege/","name":"techpoint.africa","type":"other","archive_url":"http://web.archive.org/web/20260412000203/https://techpoint.africa/feature/how-hyperbridge-works-seun-lanlege/","credibility":3,"archive_timestamp":"2026-04-12T00:02:03+00:00"},{"url":"https://techcabal.com/2025/04/17/polytope-labs-raises-over-5-million-to-scale-hyperbridge-backed-by-the-polkadot-ecosystem-fund/","name":"techcabal.com","type":"other","archive_url":"http://web.archive.org/web/20260518095144/https://techcabal.com/2025/04/17/polytope-labs-raises-over-5-million-to-scale-hyperbridge-backed-by-the-polkadot-ecosystem-fund/","credibility":3,"archive_timestamp":"2026-05-18T09:51:44+00:00"},{"url":"https://polkadot.com/newsroom/press-releases/hyperbridge-launches-on-Polkadot/","name":"polkadot.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://en.wikipedia.org/wiki/Hyperbridge","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260724041134/https://en.wikipedia.org/wiki/Hyperbridge","credibility":3,"archive_timestamp":"2026-07-24T04:11:34+00:00"},{"url":"https://bitcoinke.io/2025/11/a-look-at-hyperbridge/","name":"bitcoinke.io","type":"other","archive_url":"http://web.archive.org/web/20260419111044/https://bitcoinke.io/2025/11/a-look-at-hyperbridge/","credibility":3,"archive_timestamp":"2026-04-19T11:10:44+00:00"},{"url":"https://www.tronweekly.com/hyperbridge-suffers-237000-breach-as-token-gate/","name":"tronweekly.com","type":"other","archive_url":"https://web.archive.org/web/20260829052637/https://www.tronweekly.com/hyperbridge-suffers-237000-breach-as-token-gate/","credibility":3,"archive_timestamp":"2026-08-29T05:26:37+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:12.236996+00:00","updated_at":"2026-08-30T20:07:19.527815+00:00"}}