Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    Exclusive: Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    CLARITY Act Markup Vote Today
    CLARITY Act Markup Vote Today: What Happens If It Passes and Could Crypto Rules Arrive by June?
    US Inflation Hits 3.8% Here's the Exact Crypto Playbook Smart Money Is Using to Hedge It
    US Inflation Hits 3.8%: Here’s the Exact Crypto Playbook Smart Money Is Using to Hedge It
    Terra Luna Crash $60 Billion Lost, Do Kwon Jailed, Wall Street Sued
    The $60B Ghost: Four Years After Terra Luna’s Collapse, Do Kwon Is in Prison, and Wall Street Faces a Reckoning
    How the TXEX and DSJ Syndicates Built a $150M Empire on Trafficked Labor and Fabricated Lives
    $150M TXEX-DSJ Empire Exposed: 813 Fake Sites, Human Trafficking Camps, 276 Arrests
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Forged Proof, Drained Funds: Hyperbridge Breaks Down April 13 Exploit

Security audits identified 14 vulnerabilities across Hyperbridge’s verification stack, prompting patches, refactoring, and a new bug bounty program.

Written By:
Sharmistha Suman

Reviewed By:
Shubham Soni

Last updated: 14 minutes ago
Published 24 minutes ago
Share
Last updated: 14 minutes ago
Published 24 minutes ago
Forged Proof, Drained Funds Hyperbridge Breaks Down April 13 Exploit

Key Highlights

  • Hyperbridge’s April 13 exploit stemmed from a vulnerability in its MMR verifier logic.
  • Attackers used forged proofs with out-of-bounds leaf indexes to drain token gateway funds.
  • Hyperbridge launched a public bug bounty program with rewards up to $50,000 following the incident.

Hyperbridge, a decentralized and permissionless protocol, today published a detailed post-mortem on the security incident that occurred on April 13, 2026, in which an attacker exploited a vulnerability in the protocol’s Merkle Mountain Range (MMR) verifier to drain funds from the Token Gateway contract.

According to the report, the attacker submitted a forged proof containing a leaf with an out-of-bounds index. The MMR verifier incorrectly accepted the proof because it failed to check for leftover leaves after processing peaks in the Merkle structure. This resulted in downstream components treating the forged message as legitimate, allowing the extraction of funds from the Token Gateway settlement layer.

Hyperbridge also:

— removed additional attack surface

— tightened settlement validation

— improved escrow accounting

— strengthened proof verification rules

— launched a public bug bounty program ($200–$50,000) on HackenProofhttps://t.co/WEgHNKV3Do

— Hyperbridge (@hyperbridge) May 14, 2026

Internal review and security audits 

Following the incident, Polytope Labs conducted an internal review and an independent security audit from Security Research Labs (SR Labs). Altogether, the audits recognized 14 vulnerabilities across the verification and settlement stack: 1 critical, 3 high, 5 medium, 4 low, and 1 informational. 

Parallelly, Polytope Labs conducted an internal audit of the entire Hyperbridge protocol, and the audits revealed the same class of flaw in two broadly used open-source libraries across the Polkadot ecosystem. Both were revealed privately to their maintainers and have since been patched and include the following: 

  • paritytech/merkle-mountain-range (used in Polkadot’s pallet-beefy-mmr): Fixed by Parity.
  • antouhou/rs-merkle: Hyperbridge is currently running on a patched fork while upstream review continues.

Other issues unveiled comprised duplicate leaf index attacks, empty leaf proofs that returned success, and problems with fee-on-transfer tokens and escrow accounting in the IntentGatewayV2. 

Response and bug bounty program 

In response, Hyperbridge tightened proof verification rules, reduced the attack surface through code refactoring, and improved settlement logic. The team also launched a public bug bounty program on Hacken Proof with rewards ranging from $200 to $50,000. 

Researchers can submit vulnerability reports, including the complete Hyperbridge protocol repository, to earn rewards. All vulnerability classes that could compromise the integrity of messages or funds crossing through Hyperbridge are in scope. The platform will acknowledge, classify, and reward the researchers within three days of approval.

In the X thread, Hyperbridge highlighted transparency and proactive ecosystem responsibility. The exploit was isolated to the Token Gateway and did not compromise the broader cross-chain messaging infrastructure. No further losses have been reported since the pause.

Difficulties in cross-chain solution

The security loophole exploited on April 13 in the MMR Verifier system of Hyperbridge made it possible to extract funds from the Token Gateway through the Merkle proof validation flaw.

Although there was money lost during the hack, the team acted swiftly to stop the system, fix the problems, and conduct security audits that led to addressing many other issues. By making the information about what happened publicly available and sharing it with the wider Polkadot network, the company acted responsibly in terms of security. 

The incident highlights the difficulties that persist in developing a safe cross-chain solution. With the protocol restarting its work based on audited code, increased testing, and bug bounties, time will tell how effective it is going to be.

Also Read: Sen. Warren Drops Epstein Bombshell During CLARITY Act Showdown

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Cryptocurrency
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Sharmistha Suman - Crypto Journalist
By Sharmistha Suman
 
A crypto writer with a strong foundation in storytelling and digital media, Sharmistha holds a Bachelor’s degree in Creative Writing and a Master’s in Digital Journalism. Since entering the crypto industry in 2022, she has been actively covering developments across blockchain, digital assets, and emerging financial technologies. Her work focuses on breaking down complex topics into clear, engaging narratives, helping readers stay informed in a fast-evolving space.
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

Crypto’s CLARITY Act Survives Senate Showdown, Advances 15-9
Crypto’s CLARITY Act Survives Senate Showdown, Advances 15-9
Bitcoin Rallies to $82K as CLARITY Act Clears Senate Banking
CLARITY Act Live Senate Banking Committee debates amendments
CLARITY Act Live: Senate Banking Committee debates amendments
Sen. Warren Drops Epstein Bombshell During CLARITY Act Showdown
Sen. Warren Drops Epstein Bombshell During CLARITY Act Showdown
Interactive Brokers Brings Kalshi, CME, and ForecastEx Under One Roof
Interactive Brokers Brings Kalshi, CME, and ForecastEx Under One Roof

Find Us on Socials

You may also like

Platov Expands African Footprint With Nigerian Naira (NGN) Support

Platov Expands African Footprint With Nigerian Naira (NGN) Support

$450M Frozen: Tether, TRON, and TRM Tighten the Net on Crypto Crime

$450M Frozen: Tether, TRON, and TRM Tighten the Net on Crypto Crime

Beyond Bitcoin: 21Shares Launches Actively Managed Crypto ETF

Beyond Bitcoin: 21Shares Launches Actively Managed Crypto ETF

Why India’s Parliament Panel Called Binance, WazirX & ZebPay for the May 20 Meet

Why India’s Parliament Panel Called Binance, WazirX & ZebPay for the May 20 Meet

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information