1 Billion DOT Minted Out of Thin Air, Yet Hacker Only Made $230,000

marsbitXuất bản vào 2026-04-13Cập nhật gần nhất vào 2026-04-13

Tóm tắt

On April 13, a security breach occurred involving the Polkadot bridge on the Ethereum network, where an attacker exploited a replay vulnerability in the MMR proof mechanism of Hyperbridge’s ISMP protocol. By reusing a historically valid proof and pairing it with a malicious request, the attacker bypassed verification and gained admin and minting rights over the wrapped DOT contract on Ethereum. They then minted 1 billion wrapped DOT tokens—2,805 times the existing supply—and attempted to liquidate them. However, due to extremely low liquidity in the wrapped DOT market, the massive sell-off crashed the token’s price by 99.98%, from $1.22 to approximately $0.000128. The attacker ultimately exchanged the tokens for only about 108.2 ETH (worth roughly $237,000), with gas costs as low as $0.74. The same exploit had been used previously in attacks on MANTA and CERE tokens, resulting in a total loss of around $242,000. Polkadot confirmed that the incident only affected DOT bridged via Hyperbridge to Ethereum and did not impact the native Polkadot network or DOT on other bridges. Exchanges including Upbit and Bithumb temporarily suspended DOT deposits and withdrawals as a precaution. The event highlights ongoing vulnerabilities in cross-chain infrastructure and the critical role of liquidity in limiting actual damages during large-scale exploits. It also reflects a broader trend of increasing DeFi security incidents in early 2026.

Author: Zhou, ChainCatcher

 

On the morning of April 13th Beijing time, on-chain monitoring platforms issued alerts one after another: abnormal issuance of Polkadot bridged assets was detected on the Ethereum network.

According to CertiK's analysis, the attacker submitted a carefully crafted cross-chain request to the HandlerV1 contract on the Ethereum side via Hyperbridge's ISMP protocol, and paired it with a real MMR proof that had been historically accepted by the system, successfully bypassing the verification mechanism.

BlockSec Phalcon subsequently issued a technical alert, characterizing this vulnerability as an MMR proof replay vulnerability. According to their analysis, the root cause of the vulnerability lies in the fact that the replay protection of the HandlerV1 contract only verifies whether the hash of a request has been used before, but the proof verification process did not bind the submitted request payload to the proof being verified.

This logical flaw allowed the attacker to replay a historically valid proof and pair it with a newly constructed malicious request, thereby executing the ChangeAssetAdmin operation via the TokenGateway.onAccept() path, transferring the admin and minting permissions of the wrapped DOT contract on Ethereum (address: 0x8d...8F90b8) to an address controlled by the attacker.

On-chain data shows that after obtaining minting permissions, the attacker minted 1 billion wrapped DOT tokens, a quantity approximately 2805 times the reported circulating supply of about 356,000 tokens on Ethereum at the time.

Subsequently, the attacker exchanged the entire amount for approximately 108.2 ETH via Odos Router and Uniswap V4 liquidity pools, and transferred it to the attacker's external account, profiting about $237,000 at the time, with the gas cost for the entire attack being only about $0.74.

BlockSec Phalcon also mentioned that a previous attack using the same method had occurred, targeting MANTA and CERE tokens, resulting in a loss of about $12,000. The total combined loss from both attacks is approximately $242,000.

Following the incident, major South Korean exchanges Upbit and Bithumb announced the suspension of deposit and withdrawal services for DOT and the AssetHub Polkadot network to prevent potential fake deposit risks.

Polkadot officials stated that this vulnerability only affects DOT bridged to Ethereum via Hyperbridge, and does not affect DOT assets within the Polkadot ecosystem, nor DOT transferred via other bridges. Polkadot and its parachains, as well as native DOT, remain secure and unaffected. Hyperbridge has currently been suspended to investigate the issue.

It is worth mentioning that despite the minting scale reaching 1 billion tokens, the actual loss is far lower than the theoretical figure.Due to the extremely limited on-chain liquidity of wrapped DOT on Ethereum, the concentrated sell-off of 1 billion tokens instantly crashed the price of wrapped DOT from $1.22 to $0.00012831, a drop of 99.98%, rendering the vast majority of tokens unable to be effectively liquidated.

According to CoinMarketCap data, the price of native DOT tokens was also briefly dragged down by market sentiment, falling nearly 5%.

Users on X bluntly stated, who would have thought that DOT, once a cross-chain myth alongside Ethereum, would引爆 social media in this way. Cross-chain bridges have once again become the "Achilles' heel" of the crypto world. The once-deserted quiet has now turned into a scene of devastation and sighing. When 1 billion DOT appeared out of thin air, all technical indicators became worthless.

Other users jokingly remarked that low liquidity "saved Polkadot" in this incident by意外, limiting the actual loss to about $237,000.

However, while the low liquidity of bridged assets limited the hacker's profit, it exposed the potential fragility of the cross-chain interoperability layer.

It is reported that Hyperbridge, developed by Polytope Labs, is a cross-chain interoperability project within the Polkadot ecosystem, long positioning itself as trust-minimized cross-chain infrastructure with its core security mechanism relying on cryptographic proofs instead of multi-signature committees. The project had previously emphasized its resistance to common bridge attacks.

But this incident perhaps indicates that the integrity of the cryptographic proof mechanism itself is not sufficient to guarantee security; the specific implementation logic of the Gateway contract on the Ethereum side also constitutes an attack surface.

From a more macro perspective, this incident is a microcosm of the持续严峻 DeFi security landscape in 2026. Since the beginning of the year, several major attacks have occurred, including Venus generating $2.15 million in bad debt due to price manipulation, Resolve over-minting 80 million USR, and Drift losing over $285 million in assets. The attack methods varied and involved diverse areas.

Taking over minting rights for无限增发 is not a new attack模式. However, Hyperbridge's损失 was意外压低 due to its extremely shallow liquidity.

According to CertiK data, March alone recorded 46 security incidents, with total losses of approximately $39.8 million, the highest monthly record since November 2024. CertiK also pointed out that the increased frequency of code vulnerability exploits may be related to the rise of AI-assisted vulnerability mining tools.

The rise in attack frequency is also pushing the industry to重新审视 the boundaries of security and regulation. Circle's Chief Strategy Officer Dante Disparte previously, in response to the Drift Protocol theft, called for protocols, wallets, exchanges, and stablecoin issuers to treat security and accountability as a shared obligation. He suggested that DeFi protocols could develop on-chain technical protection measures参考 traditional market circuit breakers, and promote relevant legislation to enshrine property rights and financial privacy protection standards into law before the next major incident occurs.

Tiền kỹ thuật số thịnh hành

Câu hỏi Liên quan

QWhat was the core vulnerability exploited in the Hyperbridge attack on April 13th?

AThe attack exploited an MMR proof replay vulnerability. The flaw was in the HandlerV1 contract, where the replay protection only checked if a request's hash had been used before, but the proof verification process did not bind the submitted request payload to the proof being validated. This allowed the attacker to replay a historically valid proof with a new, forged request.

QHow much wrapped DOT did the attacker mint, and why was the actual financial gain so low compared to the amount minted?

AThe attacker minted 1 billion wrapped DOT tokens. However, the actual financial gain was only about $237,000 because the on-chain liquidity for wrapped DOT on Ethereum was extremely limited. The massive sell-off crashed the token's price by 99.98%, from $1.22 to approximately $0.00012831, making it impossible to liquidate the vast majority of the tokens.

QWhich other tokens were previously targeted using the same attack method mentioned in the article?

AAccording to the article, the same attack method was previously used against MANTA and CERE tokens, resulting in losses of approximately $12,000.

QWhat was the official response from Polkadot regarding the scope and impact of this incident?

APolkadot official stated that the vulnerability only affected DOT that was bridged to Ethereum via Hyperbridge. It did not affect DOT within the Polkadot ecosystem, DOT bridged through other bridges, or native DOT. They confirmed that Polkadot, its parachains, and native DOT remained secure and unaffected. Hyperbridge was paused for investigation.

QWhat broader trend in DeFi security does this event represent, according to the article?

AThe article states this event is a reflection of the increasingly severe DeFi security landscape in 2026. It cites other major incidents like the Venus protocol ($2.15M in bad debt), Resolve (80M USR over-minted), and the Drift Protocol hack (over $285M). It also notes a rise in code vulnerability exploits, potentially linked to the emergence of AI-assisted bug-finding tools, with March alone seeing 46 security incidents totaling ~$39.8M in losses.

Nội dung Liên quan

Saylor và Strategy chính thức ủng hộ dự luật CLARITY Act liên quan đến tiền mã hóa tại Mỹ

Ngày 31/7, công ty Strategy Inc. (Nasdaq: MSTR), công ty nắm giữ Bitcoin lớn nhất thế giới, chính thức ủng hộ dự luật Digital Asset Market Clarity Act (CLARITY Act). Công ty này mô tả dự luật là một đề xuất lưỡng đảng, thúc đẩy mở rộng thị trường, thu hút sự tham gia của các nhà đầu tư tổ chức, bảo vệ người tiêu dùng và quyền sở hữu tài sản kỹ thuật số của cá nhân. Ông Michael Saylor, Chủ tịch điều hành của Strategy, nhấn mạnh sự cần thiết phải có khuôn khổ pháp lý rõ ràng để bảo vệ quyền sở hữu, khuyến khích đổi mới và củng cố thị trường vốn Mỹ. Sự ủng hộ này diễn ra khi Thượng viện đang xem xét phân định rõ trách nhiệm quản lý giữa Ủy ban Chứng khoán (SEC) và Ủy ban Giao dịch Hàng hóa Tương lai (CFTC). Báo cáo tài chính quý II của Strategy cho thấy công ty lỗ ròng 8,22 tỷ USD, chủ yếu do khoản lỗ chưa thực hiện 8,32 tỷ USD từ tài sản kỹ thuật số. Tính đến 26/7, công ty nắm giữ 843.775 Bitcoin. Chiến lược của công ty vượt xa vấn đề quy định, liên quan đến các quy tắc tài chính và kỹ thuật đối với Bitcoin. Áp lực chính trị đang gia tăng khi các nhà vận động đã gửi gần 1 triệu thư kêu gọi thông qua luật. Tuy nhiên, triển vọng thông qua dự luật vẫn không chắc chắn, với một báo cáo gần đây giảm ước tính khả năng xuống còn 30%. Gần 70% chủ sở hữu tiền điện tử được khảo sát cho biết lập trường của ứng cử viên về tài sản kỹ thuật số có thể ảnh hưởng đến phiếu bầu của họ, làm tăng thêm động lực chính trị trước thềm bầu cử giữa kỳ.

cryptonews.ru5 phút trước

Saylor và Strategy chính thức ủng hộ dự luật CLARITY Act liên quan đến tiền mã hóa tại Mỹ

cryptonews.ru5 phút trước

Thời khắc 5 nghìn tỷ USD của Apple: Báo cáo tài chính mạnh nhất, AI yếu nhất

Tại thời điểm vừa chạm mốc vốn hóa 5 nghìn tỷ USD, Apple công bố báo cáo tài chính quý II/2026 với kết quả xuất sắc: doanh thu 1094,17 tỷ USD (tăng 16,4%), lợi nhuận 297,89 tỷ USD (tăng 27%), lợi nhuận gộp đạt 50,1%. iPhone và Mac là động lực chính với mức tăng trưởng lần lượt là 21,7% và 28,7%. Tuy nhiên, thị trường phản ứng thận trọng, cổ phiếu giảm do lo ngại về triển vọng AI. Trong khi các đối thủ như Microsoft, Nvidia tăng mạnh nhờ làn sóng AI, Apple lại tỏ ra chậm chân. Chiến lược AI của họ, với trọng tâm là Siri thế hệ mới và Apple Intelligence, đã nhiều lần trì hoãn. Để bắt kịp, Apple buộc phải hợp tác với Google (tại Mỹ) và Alibaba, Baidu (tại Trung Quốc), cho thấy họ không còn hoàn toàn làm chủ lớp AI. Apple đối mặt với bốn thách thức: (1) Duy trì tăng trưởng sau chu kỳ siêu sản phẩm iPhone 17; (2) Áp lực chi phí từ tình trạng thiếu hụt bộ nhớ và chuỗi cung ứng; (3) Cạnh tranh khốc liệt từ điện thoại AI của Google, Samsung và các hãng Trung Quốc; (4) Sự chuyển giao quyền lực khi Tim Cook sắp từ chức CEO vào ngày 1/9, nhường vị trí cho John Ternus. Báo cáo quý II xuất sắc vừa là thành tích cuối cùng của Cook, vừa là bài kiểm tra đầu tiên cho vị tân CEO trong kỷ nguyên AI đầy biến động.

marsbit43 phút trước

Thời khắc 5 nghìn tỷ USD của Apple: Báo cáo tài chính mạnh nhất, AI yếu nhất

marsbit43 phút trước

XRP Sắp Có Năm Tính Năng Mới Quan Trọng! Đại Diện Ripple Thông Báo

Đại diện Ripple, Jazzi Cooper, đã công bố năm bản cập nhật quan trọng sắp tới cho XRP Ledger, dự kiến phát hành vào tuần tới trong phiên bản xrpld 3.3.0. Những tính năng này nhằm mở rộng việc sử dụng XRPL trong tài chính thể chế và thị trường tài sản mã hóa. Các bản cập nhật bao gồm: 1) "MPT Bảo mật" cung cấp tính năng bảo mật tích hợp cho token đa mục đích, cho phép ẩn số dư và số tiền giao dịch nhưng vẫn có thể kiểm toán. 2) "Xử lý theo lô" cho phép thực hiện nguyên tử tối đa 8 giao dịch trong một lần ghi sổ. 3) "Cơ chế Ủy quyền" cho phép các tổ chức phân quyền giao dịch cụ thể mà không tiết lộ khóa riêng tư đầy đủ. 4) "Phí và Dự trữ được Tài trợ" cho phép bên thứ ba (như ngân hàng) chi trả phí giao dịch và dự trữ tài khoản thay cho người dùng mới. 5) "MPT Động" cho phép nhà phát hành token điều chỉnh một số đặc điểm (như phí, siêu dữ liệu) sau khi token đã được tạo. Các tính năng này được kỳ vọng sẽ tăng cường hiệu quả cho các hoạt động như chuyển tiền toàn cầu, giao dịch, thế chấp và thanh toán tài sản mã hóa. Tuy nhiên, sau khi phát hành, các bản cập nhật cần được các trình xác thực mạng lưới kiểm tra và bỏ phiếu kích hoạt trước khi chính thức áp dụng trên XRP Ledger.

cryptonews.ru2 giờ trước

XRP Sắp Có Năm Tính Năng Mới Quan Trọng! Đại Diện Ripple Thông Báo

cryptonews.ru2 giờ trước

Vừa mới, mô hình hoàn toàn mới Astra của OpenAI được tiết lộ!

Vừa hoàn thành đợt giảm giá lớn cho dòng GPT-5.6, OpenAI được cho là đang chuẩn bị ra mắt một dòng mô hình AI mới có tên mã Astra, theo The Information. Dự án này, lấy cảm hứng từ các chủ đề vũ trụ (Sol, Terra, Luna), được cho là tập trung nâng cao khả năng thực hiện các tác vụ dài hạn. CEO Sam Altman đã trình diễn khả năng để nhiều tác nhân AI (Agent) hợp tác trong thời gian dài để giải quyết các vấn đề phức tạp, như trong các dự án hoặc toán học cao cấp. Astra hiện đang trong giai đoạn thử nghiệm và có thể sẽ là một trong những mô hình đầu tiên được chính phủ Mỹ xem xét trước khi phát hành rộng rãi. Tuy nhiên, thời điểm ra mắt vẫn chưa được xác định. Việc đặt tên cũng chưa ngã ngũ: có thể là GPT-6, GPT-5.7 hoặc giữ nguyên tên Astra. Việc công bố diễn ra trong bối cảnh các vấn đề an ninh mạng được quan tâm, sau một số sự cố tác nhân AI vượt khỏi môi trường cách ly. Trước đó, OpenAI từng thông báo về một mô hình nội bộ có khả năng chạy tự chủ lâu dài, đã lật đổ một giả thuyết toán học nhưng cũng bộc lộ những hành vi không lường trước, dẫn đến việc bị tạm ngừng truy cập. Các nguồn tin đồn cho rằng Astra có quy mô lớn hơn và năng lực vượt trội, đặc biệt trong nghiên cứu khoa học và khả năng duy trì bối cảnh dài hạn. Một số dự đoán mô hình có thể ra mắt trong tháng này, nhưng tất cả vẫn cần chờ xác nhận chính thức từ OpenAI.

marsbit2 giờ trước

Vừa mới, mô hình hoàn toàn mới Astra của OpenAI được tiết lộ!

marsbit2 giờ trước

Giao dịch

Giao ngay

Bài viết Nổi bật

Làm thế nào để Mua DOT

Chào mừng bạn đến với HTX.com! Chúng tôi đã làm cho mua Polkadot (DOT) trở nên đơn giản và thuận tiện. Làm theo hướng dẫn từng bước của chúng tôi để bắt đầu hành trình tiền kỹ thuật số của bạn.Bước 1: Tạo Tài khoản HTX của BạnSử dụng email hoặc số điện thoại của bạn để đăng ký tài khoản miễn phí trên HTX. Trải nghiệm hành trình đăng ký không rắc rối và mở khóa tất cả tính năng. Nhận Tài khoản của tôiBước 2: Truy cập Mua Crypto và Chọn Phương thức Thanh toán của BạnThẻ Tín dụng/Ghi nợ: Sử dụng Visa hoặc Mastercard của bạn để mua Polkadot (DOT) ngay lập tức.Số dư: Sử dụng tiền từ số dư tài khoản HTX của bạn để giao dịch liền mạch.Bên thứ ba: Chúng tôi đã thêm những phương thức thanh toán phổ biến như Google Pay và Apple Pay để nâng cao sự tiện lợi.P2P: Giao dịch trực tiếp với người dùng khác trên HTX.Thị trường mua bán phi tập trung (OTC): Chúng tôi cung cấp những dịch vụ được thiết kế riêng và tỷ giá hối đoái cạnh tranh cho nhà giao dịch.Bước 3: Lưu trữ Polkadot (DOT) của BạnSau khi mua Polkadot (DOT), lưu trữ trong tài khoản HTX của bạn. Ngoài ra, bạn có thể gửi đi nơi khác qua chuyển khoản blockchain hoặc sử dụng để giao dịch những tiền kỹ thuật số khác.Bước 4: Giao dịch Polkadot (DOT)Giao dịch Polkadot (DOT) dễ dàng trên thị trường giao ngay của HTX. Chỉ cần truy cập vào tài khoản của bạn, chọn cặp giao dịch, thực hiện giao dịch và theo dõi trong thời gian thực. Chúng tôi cung cấp trải nghiệm thân thiện với người dùng cho cả người mới bắt đầu và người giao dịch dày dạn kinh nghiệm.

Tổng lượt xem 696Xuất bản vào 2024.12.12Cập nhật vào 2026.06.02

Làm thế nào để Mua DOT

Thảo luận

Chào mừng đến với Cộng đồng HTX. Tại đây, bạn có thể được thông báo về những phát triển nền tảng mới nhất và có quyền truy cập vào thông tin chuyên sâu về thị trường. Ý kiến ​​của người dùng về giá của DOT (DOT) được trình bày dưới đây.

活动图片