Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Polkadot Hack: Attacker Exploits Ethereum Contract and Mints 1B DOT Tokens

The incident unfolded through Hyperbridge’s ISMP (Interoperable State Machine Protocol), which facilitates secure messaging between chains like Polkadot and Ethereum.

Written By Gopal Solanky
Published April 13, 2026 11:05 AM·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
Polkadot Hack: Attacker Exploins Ethereum Contract and Mints 1B DOT Tokens

Key Highlights

  • CertiK flagged an attack on the Hyperbridge gateway contract on Ethereum, where the attacker forged a cross-chain message from Polkadot. By deploying a master + helper contract and submitting fake state proofs, they bypassed verification to steal admin/minter rights over the official DOT token contract. 
  • The attacker minted ~1 billion DOT tokens (roughly 2,805× the reported ERC-20 supply of 356K tokens), immediately swapped them via OdosRouter and Uniswap V4 for 108.2 ETH, and sent the funds to their EOA. 
  • This is the second exploit of the same system within hours — an earlier one resulted in ~$12K in MANTA and CERE tokens, with the vulnerability lying in insufficient verification of state proofs in Hyperbridge’s ISMP pipeline.

Blockchain security firm CertiK has flagged a fresh exploit targeting the Hyperbridge gateway contract on Ethereum. According to the alert, an attacker successfully forged an incoming cross-chain message to seize control of the Polkadot (DOT) token contract deployed on Ethereum.

The incident unfolded through Hyperbridge’s ISMP (Interoperable State Machine Protocol), which facilitates secure messaging between chains like Polkadot and Ethereum. The attacker deployed a master contract and a helper contract in a single transaction. 

#CertiKInsight 🚨

We have seen an exploit on the @hyperbridge gateway contract. https://t.co/h27iDm1JGd

The attacker slipped through a forged message to change the admin of Polkadot token contract on Ethereum and profited ~$237K from minting and selling 1B tokens.

Stay… pic.twitter.com/3t2n4uq5hy

— CertiK Alert (@CertiKAlert) April 13, 2026

The helper then submitted forged state proofs to the vulnerable HandlerV1 contract (address: 0x6c8…4E6D64), bypassing verification checks. This allowed a malicious “ChangeAssetAdmin” action to be executed via the TokenGateway.onAccept() path, transferring admin and minter privileges of the DOT token contract (0x8d…8F90b8) to the exploiter. 

Following the exploit, DOT token price dropped by roughly 4.8% to $1.16—as per CoinMarketCap data. 

Polkadot Price Chart
Source: CoinMarketCap

Yet another token mint exploit

Data from Etherscan, the blockchain explorer for Ethereum, shows that the attacker minted a staggering 1 billion DOT tokens—approximately 2,805 times the reported total supply of around 356,000 tokens (ERC-20) on Ethereum.

The newly minted tokens were immediately swapped through OdosRouter and Uniswap V4 pools for roughly 108.2 ETH, which was forwarded to the attacker’s externally owned account (EOA: 0xc513…f1f8e7) and funds remain in this wallet as of publishing. 

Screenshot of ETH and DOT transaction details
Source: Etherscan

At current prices, the profit stands at approximately $237,000. Despite such a huge token supply (1 billion DOT), the actual amount scale in this exploit remains modest due to low liquidity on Hyperbridge pools. The fallout would have been much larger if tokens were bridged to native DOT on the Polkadot network. 

This marks the second exploit of the same system on the same day. An earlier attack reportedly drained around $12K in MANTA and CERE tokens using a similar vector. The root cause appears to stem from insufficient verification of state proofs in the ISMP pipeline, enabling unauthorized governance actions on connected token contracts.

Hyperbridge, developed by Polytope Labs, positions itself as a secure, trust-minimized interoperability layer that relies on cryptographic proofs from source chains rather than multisig committees. 

The project has previously emphasized resistance to common bridge hacks, which have collectively cost the ecosystem billions. However, today’s incident highlights ongoing challenges in cross-chain messaging security, particularly around proof validation and admin control in token gateways.

As of now, no official statement from Hyperbridge or Polytope Labs has been widely circulated regarding mitigations, pauses, or fund recovery efforts. 

This is a developing story and more information will be added as the event unfolds.

Also read: WLFI Drops 15% After $75M DeFi Borrow Sparks Concerns

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackEthereum (ETH)Polkadot (DOT)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Crypto Market Live: LAB Token Collapses 85% to $2

Prediction Market Fight May Reach Supreme Court CFTC Chair Selig

Prediction Market Fight May Reach Supreme Court: CFTC Chair Selig

Anchorage Bets Big on AI Economy With New Banking Model

Anchorage Bets Big on AI Economy With New Banking Model

Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria

Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria

Clarity Act on Fast Track Senator Moreno Sets July 4 Deadline

Clarity Act on Fast Track? Senator Moreno Sets July 4 Deadline

Find Us on Socials

You may also like

Crypto Market Today Utya, Dogs, LAB Top Gainers as Bitcoin Reclaims $81K

Crypto Market Today: Utya, Dogs, LAB Top Gainers as Bitcoin Reclaims $81K

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

Aave vs Gerstein: Harrow Court Clash Over $71M Stolen ETH Linked to Kelp DAO Hack

Aave vs Gerstein Harrow: Court Clash Over $71M Stolen ETH Linked to Kelp DAO Hack

Ripple Teams Up with Crypto ISAC to Stop North Korean Hackers

Ripple Teams Up with Crypto ISAC to Stop North Korean Hackers

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information