10 亿枚 DOT 凭空铸造,黑客却只赚了 23 万美元

marsbitPublished on 2026-04-13Last updated on 2026-04-13

Abstract

北京时间4月13日上午,以太坊网络上的Polkadot桥接资产出现异常增发。攻击者利用Hyperbridge的ISMP协议漏洞,通过重放历史有效的MMR证明,成功绕过验证机制,将以太坊上wrapped DOT合约的管理和铸币权转移至自己控制的地址,并凭空铸造了10亿枚桥接DOT,数量相当于当时流通量的2805倍。 随后,攻击者通过去中心化交易所将大量代币兑换为约108.2枚ETH,获利约23.7万美元。由于该代币流动性极低,巨额抛售导致其价格暴跌99.98%,因此实际损失远低于理论值。此次事件还影响了市场情绪,原生DOT价格一度下跌近5%。 Polkadot官方表示,漏洞仅影响通过Hyperbridge跨链的DOT,原生DOT及其他桥接资产未受影响。Hyperbridge目前已暂停运行并进行调查。此次事件是2026年DeFi安全形势严峻的又一案例,也再次暴露跨链桥在实现层面的潜在风险。

作者:Zhou, ChainCatcher

 

北京时间 4 月 13 日上午,链上监控平台相继发出警报:以太坊网络上的 Polkadot 桥接资产出现异常增发。

据 CertiK 分析,攻击者通过 Hyperbridge 的 ISMP 协议向以太坊侧的 HandlerV1 合约提交了一份经过精心构造的跨链请求,并配合一份历史上曾被系统接受过的真实 MMR 证明,成功绕过验证机制。

BlockSec Phalcon 随后发布技术警报,将此次漏洞定性为 MMR 证明重放漏洞。据其分析,漏洞的根源在于 HandlerV1 合约的重放保护仅验证某个请求的哈希值是否曾被使用过,但证明验证过程并未将提交的请求载荷与被验证的证明进行绑定。

这一逻辑断层使得攻击者得以重放一份历史有效证明,并将其与新构造的恶意请求配对,进而通过 TokenGateway.onAccept() 路径执行 ChangeAssetAdmin 操作,将以太坊上 wrapped DOT 合约(地址:0x8d...8F90b8)的管理员和铸币权限转移至攻击者控制的地址。

据链上数据显示,取得铸币权限后,攻击者铸造了 10 亿枚桥接版 DOT,这一数量约为当时以太坊上该代币报告流通量约 356000 枚的 2805 倍。

随后攻击者通过 Odos Router 和 Uniswap V4 流动性池将全部筹码兑换为约 108.2 个 ETH,并转入攻击者的外部账户,按当时价格计算获利约 23.7 万美元,整个攻击消耗的 gas 费用仅约 0.74 美元。

BlockSec Phalcon 还提到,此前已有一次采用相同手法的攻击发生,针对的是 MANTA 和 CERE 代币,损失约 1.2 万美元。两次攻击合计总损失约 24.2 万美元。

事发后,韩国头部交易所 Upbit 和 Bithumb 相继宣布暂停 DOT 及 AssetHub Polkadot 网络的充提服务,以防范潜在的假存款风险。

Polkadot 官方表示,该漏洞仅影响通过 Hyperbridge 跨链到以太坊上的 DOT,不影响 DOT 在 Polkadot 生态中的资产,也不影响通过其他跨链桥转移的 DOT。Polkadot 及其平行链,以及原生 DOT 均保持安全,未受到影响。目前 Hyperbridge 已暂停运行,以便对该问题进行调查。

值得一提的是,尽管铸造规模达到 10 亿枚之多,实际损失却远低于理论数字。由于以太坊上 wrapped DOT 的链上流动性极为有限,10 亿枚代币的集中抛售瞬间将 wrapped DOT 价格从 1.22 美元砸至 0.00012831 美元,跌幅 99.98%,绝大部分代币无法有效变现。

据 CoinMarketCap 数据,原生 DOT 代币价格也受市场情绪短暂拖累一度跌近 5%。

X 上用户直言,谁能想到,曾经与以太坊并肩的跨链神话 DOT,会以这种方式引爆社交媒体。跨链桥再次成为加密世界的“阿喀琉斯之踵”,曾经无人问津的冷清,如今变成了满目疮痍的唏嘘。当 10 亿枚 DOT 凭空出现,所有的技术指标都成了废纸。

用户戏称,低流动性在这次意外“救了 Polkadot 一命”,将实际损失控制在约 23.7 万美元。

不过,桥接资产的低流动性虽限制了黑客获利,却暴露了跨链互操作层的潜在脆弱性。

据悉,Hyperbridge 由 Polytope Labs 开发,是 Polkadot 生态的跨链互操作项目,长期以密码学证明替代多重签名委员会为核心安全机制,定位为信任最小化的跨链基础设施。该项目此前一直强调其对常见桥接攻击的抵御能力。

此次事件或许表明,密码学证明机制本身完好并不足以保证安全,以太坊侧 Gateway 合约的具体实现逻辑同样构成攻击面。

从更宏观的视角来看,此次事件是 2026 年以来 DeFi 安全形势持续严峻的一个缩影。今年以来已相继发生多起重大攻击事件,包括 Venus 因价格操纵产生 215 万美元坏账、Resolve 超额铸造 8,000 万枚 USR,以及 Drift 被盗超 2.85 亿美元资产,攻击手法各异,涉及领域广泛。

通过接管铸币权进行无限增发,不是什么新的攻击模式。只不过,Hyperbridge 因为流动性极浅,损失反倒被意外压低。

据 CertiK 数据,仅 3 月单月就记录了 46 起安全事件,总损失约 3,980 万美元,为 2024 年 11 月以来的单月最高纪录。CertiK 还指出,代码漏洞利用频率上升,可能与人工智能辅助漏洞挖掘工具的兴起有关。

攻击频率的上升,也在推动行业重新审视安全与监管的边界。Circle 首席战略官 Dante Disparte 此前在回应 Drift Protocol 被盗事件时呼吁,协议、钱包、交易所及稳定币发行方应将安全与问责视为共同义务,DeFi 协议可参考传统市场的熔断机制开发链上技术保护手段,并推动相关立法在下一次重大事件发生前将财产权与金融隐私保护标准写入法律。

Related Questions

Q这次攻击事件的核心漏洞是什么?

A此次攻击的核心是MMR证明重放漏洞。攻击者通过Hyperbridge的ISMP协议,向以太坊侧的HandlerV1合约提交了一份精心构造的跨链请求,并配合一份历史上曾被系统接受过的真实MMR证明,成功绕过了验证机制。漏洞的根源在于HandlerV1合约的重放保护仅验证某个请求的哈希值是否曾被使用过,但证明验证过程并未将提交的请求载荷与被验证的证明进行绑定,导致攻击者得以重放历史有效证明来执行恶意操作。

Q攻击者最终获利多少,为什么实际损失远低于理论上的10亿枚DOT价值?

A攻击者最终获利约23.7万美元。实际损失远低于理论价值的主要原因是:以太坊上wrapped DOT的链上流动性极为有限。攻击者铸造的10亿枚代币数量是当时流通量的2805倍,如此巨量的集中抛售瞬间将wrapped DOT的价格从1.22美元砸至0.00012831美元,跌幅高达99.98%,导致绝大部分代币无法有效变现,从而将实际损失控制在了较低水平。

Q此次事件对Polkadot原生代币和生态有何影响?

APolkadot官方表示,该漏洞仅影响通过Hyperbridge跨链到以太坊上的wrapped DOT,不影响DOT在Polkadot生态中的原生资产,也不影响通过其他跨链桥转移的DOT。Polkadot及其平行链,以及原生DOT均保持安全,未受到影响。不过,据市场数据显示,原生DOT代币价格受市场情绪拖累一度下跌近5%。此外,韩国头部交易所Upbit和Bithumb为防范风险,暂停了DOT及AssetHub Polkadot网络的充提服务。

Q除了本次事件,攻击者还利用相同手法攻击了哪些项目?

A据BlockSec Phalcon分析,此前已有一次采用相同手法的攻击发生,攻击目标分别是MANTA和CERE代币,造成了约1.2万美元的损失。两次攻击合计总损失约为24.2万美元。

Q这次事件反映了当前DeFi安全领域的哪些趋势和挑战?

A此次事件是2026年以来DeFi安全形势持续严峻的一个缩影。今年以来已发生多起重大攻击事件,涉及价格操纵、超额铸造等多种手法。据CertiK数据,仅3月单月就记录了46起安全事件,总损失约3980万美元,为2024年11月以来的单月最高纪录。攻击频率的上升可能与人工智能辅助漏洞挖掘工具的兴起有关。这推动行业重新审视安全与监管的边界,有声音呼吁协议、交易所等应将安全视为共同义务,并推动将财产权与金融隐私保护标准写入法律。

Related Reads

With Daily Active Users Reaching 3-4 Times That of the Industry's Second Place, Which Crack in the Office Agent Market Has Tencent's WorkBuddy Torn Open?

Tencent's AI office assistant, WorkBuddy, has achieved daily active users (DAU) 3-4 times that of the industry's second-place product, primarily driven by non-technical users like HR, operations, and administrative staff. Its rapid growth, starting with a public beta in March 2026, highlights a key strategic divergence from competitors like OpenAI's Codex and Anthropic's Claude Code. Unlike those tools, which originated as developer-focused assistants (in command lines or IDEs) and are now expanding towards office scenarios, WorkBuddy was built from the ground up for non-technical office workers. Its development was user-driven, initiated after腾讯云's team observed non-technical employees using their CodeBuddy coding tool for general tasks. WorkBuddy's design is defined by three core decisions aimed at lowering barriers: 1) Using natural language instead of technical concepts, so users describe their goal without needing to understand prompts or agents. 2) Providing pre-packaged "Skill" templates for common office tasks like data processing, content creation, and research. 3) Natively integrating into existing腾讯 ecosystems like腾讯 Docs and WeChat, making the agent a seamless part of the user's workflow rather than a separate tool. This "scenario encapsulation" approach, prioritizing the shortest path for users to get work done, contrasts with the "underlying capability" focus of Codex and Claude, which offer more flexibility but require more technical setup. Analysts confirm WorkBuddy's leading market position in China by mid-2026, with massive user and request growth following its launch. Recognizing the same trend of surging non-technical adoption, OpenAI and Anthropic are now pivoting their products with features like role-based plugins (Codex) and a simplified desktop interface (Claude Cowork). However, adapting tools built for developers requires significant changes to interaction models and integrations. WorkBuddy currently holds an estimated six-month lead in delivering a complete solution for non-technical office users. Its recently launched enterprise version aims to solidify this advantage. The competition underscores two valid paths: embedding agent capabilities directly into familiar work environments versus building powerful, general-purpose agents that users must learn to access. WorkBuddy's early success demonstrates the effectiveness of the former strategy for mainstream office adoption.

marsbit5m ago

With Daily Active Users Reaching 3-4 Times That of the Industry's Second Place, Which Crack in the Office Agent Market Has Tencent's WorkBuddy Torn Open?

marsbit5m ago

Dalio's Latest Warning: Don't Get Carried Away by AI, Real Returns on US Stocks in the Next 5-10 Years Could Be -5% to -10%

Ray Dalio, founder of Bridgewater Associates, warns investors against excessive concentration in AI stocks. He argues the current market, dominated by a few AI giants, mirrors historical patterns where revolutionary new technologies lead to high risk, volatility, and uncertainty. While acknowledging AI's transformative potential, Dalio emphasizes that most investors fail at this stage of the cycle by over-concentrating in a handful of leading companies. He cites inherent risks: companies cannot accurately forecast investment needs or external shocks (e.g., monetary policy, geopolitics, taxes), face potential disruption from future technologies and international competition (notably from China), and experience significant price swings. Dalio's core advice is diversification, calling it his "Holy Grail of Investing." He presents a mathematical case that a well-diversified portfolio of 15-20 uncorrelated, good bets offers a superior risk-adjusted return compared to a concentrated position. Dalio also offers a cautious outlook, suggesting U.S. stocks may deliver real returns of -5% to -10% over the next 5-10 years based on valuation and bubble indicators. He concludes that in the face of high uncertainty, the prudent strategy is not to avoid betting entirely, but to avoid large, concentrated bets where one lacks sufficient informational edge. Instead, investors should build a strategically balanced, diversified portfolio.

marsbit1h ago

Dalio's Latest Warning: Don't Get Carried Away by AI, Real Returns on US Stocks in the Next 5-10 Years Could Be -5% to -10%

marsbit1h ago

Rain Valuation Approaches $20 Billion: The Battle for U-Cards Extends to Rewards Systems

Rain, a stablecoin payments infrastructure company, is shifting the competitive focus for U Cards from simple issuance to user retention and repeated usage. On June 15, Rain launched "Rain Rewards," an embedded loyalty program capability within its card-issuing infrastructure. This allows partner businesses—like fintech platforms and neobanks—to configure branded loyalty points, earning rules, redemptions, and merchant promotions directly within their card products. The system, built from the 2025 acquisition of Uptop, ensures points are only issued upon final transaction settlement, preventing liabilities from refunds. Trials, such as with Avalanche Card, reportedly boosted spending by 25% among enrolled users. Founded by Farooq Malik and Charles Yoo-Naut, Rain evolved from a tool for managing Web3 company expenses into a full-stack enterprise platform. It is a Principal Member of Visa and Mastercard, enabling partners to issue stablecoin-backed cards and wallets while leveraging traditional payment networks. Notably, the popular U Card Plasma One is issued by Rain under Visa's authority. Rain also integrates with Visa's stablecoin settlement pilot, using USDC for network settlement. Rain's rapid funding reflects growing institutional interest in stablecoin payment infrastructure. It raised a $245 million Series A in March 2025, a $58 million Series B in August 2025, and a $250 million Series C in January of this year, reaching a $19.5 billion valuation. Annualized transaction volume exceeds $3 billion, serving over 200 partners including Western Union and Nuvei. Beyond cards, Rain is expanding into programmable payments. Its June 2026 "Agent Control Layer" allows businesses to set spending rules—like merchant categories, amounts, and frequency—for AI agents before transactions occur. This positions Rain not as a single product but as an operating system for stablecoin payments, handling everything from card issuance and wallet management to rewards, on/off-ramps, and automated compliance. The goal is to enable seamless, often invisible, real-world spending of on-chain assets.

Foresight News1h ago

Rain Valuation Approaches $20 Billion: The Battle for U-Cards Extends to Rewards Systems

Foresight News1h ago

Trading

Spot
Futures

Hot Articles

How to Buy DOT

Welcome to HTX.com! We've made purchasing Polkadot (DOT) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Polkadot (DOT) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Polkadot (DOT)After purchasing your Polkadot (DOT), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Polkadot (DOT)Easily trade Polkadot (DOT) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

5.4k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy DOT

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of DOT (DOT) are presented below.

活动图片