Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    MicroStrategy Stock Mirrors Bitcoin's Wildest Swings 7 Times BTC Moved MSTR
    MicroStrategy Stock Mirrors Bitcoin’s Wildest Swings: 7 Times BTC Moved MSTR
    Beyond Bitcoin Treasuries How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    Beyond Bitcoin Treasuries: How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    Exclusive Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Exclusive: Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Crypto PACs Reshape US Elections: Trump's Pro-Crypto Agenda Takes Shape
    Crypto PACs Reshape US Elections: Trump’s Pro-Crypto Agenda Takes Shape
  • Opinion
    OpinionShow More
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Polkadot Hack: Attacker Exploits Ethereum Contract and Mints 1B DOT Tokens

The incident unfolded through Hyperbridge’s ISMP (Interoperable State Machine Protocol), which facilitates secure messaging between chains like Polkadot and Ethereum.

Written By:
Gopal Solanky

Last updated: April 13, 2026 12:37 PM
Published 2026-04-13
Share
Last updated: April 13, 2026 12:37 PM
Published 2026-04-13
Polkadot Hack: Attacker Exploins Ethereum Contract and Mints 1B DOT Tokens

Key Highlights

  • CertiK flagged an attack on the Hyperbridge gateway contract on Ethereum, where the attacker forged a cross-chain message from Polkadot. By deploying a master + helper contract and submitting fake state proofs, they bypassed verification to steal admin/minter rights over the official DOT token contract. 
  • The attacker minted ~1 billion DOT tokens (roughly 2,805× the reported ERC-20 supply of 356K tokens), immediately swapped them via OdosRouter and Uniswap V4 for 108.2 ETH, and sent the funds to their EOA. 
  • This is the second exploit of the same system within hours — an earlier one resulted in ~$12K in MANTA and CERE tokens, with the vulnerability lying in insufficient verification of state proofs in Hyperbridge’s ISMP pipeline.

Blockchain security firm CertiK has flagged a fresh exploit targeting the Hyperbridge gateway contract on Ethereum. According to the alert, an attacker successfully forged an incoming cross-chain message to seize control of the Polkadot (DOT) token contract deployed on Ethereum.

The incident unfolded through Hyperbridge’s ISMP (Interoperable State Machine Protocol), which facilitates secure messaging between chains like Polkadot and Ethereum. The attacker deployed a master contract and a helper contract in a single transaction. 

#CertiKInsight 🚨

We have seen an exploit on the @hyperbridge gateway contract. https://t.co/h27iDm1JGd

The attacker slipped through a forged message to change the admin of Polkadot token contract on Ethereum and profited ~$237K from minting and selling 1B tokens.

Stay… pic.twitter.com/3t2n4uq5hy

— CertiK Alert (@CertiKAlert) April 13, 2026

The helper then submitted forged state proofs to the vulnerable HandlerV1 contract (address: 0x6c8…4E6D64), bypassing verification checks. This allowed a malicious “ChangeAssetAdmin” action to be executed via the TokenGateway.onAccept() path, transferring admin and minter privileges of the DOT token contract (0x8d…8F90b8) to the exploiter. 

Following the exploit, DOT token price dropped by roughly 4.8% to $1.16—as per CoinMarketCap data. 

Polkadot Price Chart
Source: CoinMarketCap

Yet another token mint exploit

Data from Etherscan, the blockchain explorer for Ethereum, shows that the attacker minted a staggering 1 billion DOT tokens—approximately 2,805 times the reported total supply of around 356,000 tokens (ERC-20) on Ethereum.

The newly minted tokens were immediately swapped through OdosRouter and Uniswap V4 pools for roughly 108.2 ETH, which was forwarded to the attacker’s externally owned account (EOA: 0xc513…f1f8e7) and funds remain in this wallet as of publishing. 

Screenshot of ETH and DOT transaction details
Source: Etherscan

At current prices, the profit stands at approximately $237,000. Despite such a huge token supply (1 billion DOT), the actual amount scale in this exploit remains modest due to low liquidity on Hyperbridge pools. The fallout would have been much larger if tokens were bridged to native DOT on the Polkadot network. 

This marks the second exploit of the same system on the same day. An earlier attack reportedly drained around $12K in MANTA and CERE tokens using a similar vector. The root cause appears to stem from insufficient verification of state proofs in the ISMP pipeline, enabling unauthorized governance actions on connected token contracts.

Hyperbridge, developed by Polytope Labs, positions itself as a secure, trust-minimized interoperability layer that relies on cryptographic proofs from source chains rather than multisig committees. 

The project has previously emphasized resistance to common bridge hacks, which have collectively cost the ecosystem billions. However, today’s incident highlights ongoing challenges in cross-chain messaging security, particularly around proof validation and admin control in token gateways.

As of now, no official statement from Hyperbridge or Polytope Labs has been widely circulated regarding mitigations, pauses, or fund recovery efforts. 

This is a developing story and more information will be added as the event unfolds.

Also read: WLFI Drops 15% After $75M DeFi Borrow Sparks Concerns

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackEthereum (ETH)Polkadot (DOT)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

Zcash Block Halt Rumor Debunked After Faulty Node Confusion
Zcash Block Halt Rumor Debunked After Faulty Node Confusion
a16z Pushes for Uniform Stablecoin Rules Under GENIUS Act
a16z Pushes for Uniform Stablecoin Rules Under GENIUS Act
Trezor Discloses Vulnerability in Safe 7’s TROPIC01 Chip — Funds Remain Secure
Trezor Discloses Vulnerability in Safe 7’s TROPIC01 Chip — Funds Remain Secure
ENA Surges 22% in 24 Hours as Ethena's Institutional Push Drives 414% Volume Spike
ENA Surges 22% in 24 Hours as Ethena’s Institutional Push Drives 414% Volume Spike
This 2-Cent Crypto Transaction Ended in a Hyperliquid Ban
This 2-Cent Crypto Transaction Ended in a Hyperliquid Ban

Find Us on Socials

You may also like

Ethena Taps Anchorage Digital Bank to Shield DeFi Credit

Ethena Taps Anchorage Digital Bank to Shield DeFi Credit

Cardano Analytics Giant TapTools Begins Final Shutdown Countdown

Cardano Analytics Giant TapTools Begins Final Shutdown Countdown

Bridge Breach Unpacked: Alephium Traces $815K Hack Step by Step

Bridge Breach Unpacked: Alephium Traces $815K Hack Step by Step

Zodiac Reveals Flaw Behind Gnosis Pay Exploit, Safe Unaffected

Zodiac Reveals Flaw Behind Gnosis Pay Exploit, Safe Unaffected

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information