Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    From BitMEX to Leap Wallet 100+ Crypto Projects Have Shut Down in H1 2026
    From BitMEX to Leap Wallet: 100+ Crypto Projects Have Shut Down in H1 2026
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Forged Proof, Drained Funds: Hyperbridge Breaks Down April 13 Exploit

Security audits identified 14 vulnerabilities across Hyperbridge’s verification stack, prompting patches, refactoring, and a new bug bounty program.

Written By Sharmistha Suman
Fact Checked by Shubham Soni
Published 2026-05-14·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Forged Proof, Drained Funds Hyperbridge Breaks Down April 13 Exploit

Key Highlights

  • Hyperbridge’s April 13 exploit stemmed from a vulnerability in its MMR verifier logic.
  • Attackers used forged proofs with out-of-bounds leaf indexes to drain token gateway funds.
  • Hyperbridge launched a public bug bounty program with rewards up to $50,000 following the incident.

Hyperbridge, a decentralized and permissionless protocol, today published a detailed post-mortem on the security incident that occurred on April 13, 2026, in which an attacker exploited a vulnerability in the protocol’s Merkle Mountain Range (MMR) verifier to drain funds from the Token Gateway contract.

According to the report, the attacker submitted a forged proof containing a leaf with an out-of-bounds index. The MMR verifier incorrectly accepted the proof because it failed to check for leftover leaves after processing peaks in the Merkle structure. This resulted in downstream components treating the forged message as legitimate, allowing the extraction of funds from the Token Gateway settlement layer.

Hyperbridge also:

— removed additional attack surface

— tightened settlement validation

— improved escrow accounting

— strengthened proof verification rules

— launched a public bug bounty program ($200–$50,000) on HackenProofhttps://t.co/WEgHNKV3Do

— Hyperbridge (@hyperbridge) May 14, 2026

Internal review and security audits 

Following the incident, Polytope Labs conducted an internal review and an independent security audit from Security Research Labs (SR Labs). Altogether, the audits recognized 14 vulnerabilities across the verification and settlement stack: 1 critical, 3 high, 5 medium, 4 low, and 1 informational. 

Parallelly, Polytope Labs conducted an internal audit of the entire Hyperbridge protocol, and the audits revealed the same class of flaw in two broadly used open-source libraries across the Polkadot ecosystem. Both were revealed privately to their maintainers and have since been patched and include the following: 

  • paritytech/merkle-mountain-range (used in Polkadot’s pallet-beefy-mmr): Fixed by Parity.
  • antouhou/rs-merkle: Hyperbridge is currently running on a patched fork while upstream review continues.

Other issues unveiled comprised duplicate leaf index attacks, empty leaf proofs that returned success, and problems with fee-on-transfer tokens and escrow accounting in the IntentGatewayV2. 

Response and bug bounty program 

In response, Hyperbridge tightened proof verification rules, reduced the attack surface through code refactoring, and improved settlement logic. The team also launched a public bug bounty program on Hacken Proof with rewards ranging from $200 to $50,000. 

Researchers can submit vulnerability reports, including the complete Hyperbridge protocol repository, to earn rewards. All vulnerability classes that could compromise the integrity of messages or funds crossing through Hyperbridge are in scope. The platform will acknowledge, classify, and reward the researchers within three days of approval.

In the X thread, Hyperbridge highlighted transparency and proactive ecosystem responsibility. The exploit was isolated to the Token Gateway and did not compromise the broader cross-chain messaging infrastructure. No further losses have been reported since the pause.

Difficulties in cross-chain solution

The security loophole exploited on April 13 in the MMR Verifier system of Hyperbridge made it possible to extract funds from the Token Gateway through the Merkle proof validation flaw.

Although there was money lost during the hack, the team acted swiftly to stop the system, fix the problems, and conduct security audits that led to addressing many other issues. By making the information about what happened publicly available and sharing it with the wider Polkadot network, the company acted responsibly in terms of security. 

The incident highlights the difficulties that persist in developing a safe cross-chain solution. With the protocol restarting its work based on audited code, increased testing, and bug bounties, time will tell how effective it is going to be.

Also Read: Sen. Warren Drops Epstein Bombshell During CLARITY Act Showdown

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

SOL Goes Live on XRP Ledger as Axelar Brings Solana to XRPL
SOL Goes Live on XRP Ledger as Axelar Brings Solana to XRPL
Cboe Files With SEC to List 3x Bitcoin and Ether ETFs
Cboe Files With SEC to List 3x Bitcoin and Ether ETFs
Lido Calls for Deeper Review Before EIP-8363 Advances
Lido Calls for Deeper Review Before EIP-8363 Advances
Nigel Farage Wins UK By-Election Amid Crypto Donation Probe
Nigel Farage Wins UK By-Election Amid Crypto Donation Probe
SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall

Find Us on Socials

You may also like

Galaxy, Compass and Montera Agree to Texas Data Center Rules

Galaxy, Compass and Montera Agree to Texas Data Center Rules

Grayscale: ETH and SOL Could Get Scarcer if Proposals Implemented

Grayscale: ETH and SOL Could Get Scarcer if Proposals Implemented

Upbit Operator Dunamu’s Q2 Profit Falls 85% as Trading Slows

Upbit Operator Dunamu’s Q2 Profit Falls 85% as Trading Slows

Coinbase Halts cbETH on Arbitrum, Optimism, Polygon After Aug 17

Coinbase Halts cbETH on Arbitrum, Optimism, Polygon After Aug 17

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information