Start now →

Polkadot-Ethereum Bridge Hack Losses Were 10x Worse Than Reported, Team Admits

By Logan Hitchcock · Published April 16, 2026 · 3 min read · Source: Decrypt
EthereumRegulationAltcoinsSecurity
Polkadot-Ethereum Bridge Hack Losses Were 10x Worse Than Reported, Team Admits
NewsLaw and Order

Polkadot-Ethereum Bridge Hack Losses Were 10x Worse Than Reported, Team Admits

Polkadot bridge protocol Hyperbridge said losses from this week's hack were 10x worse than originally reported, tallying about $2.5 million.

Logan HitchcockBy Logan HitchcockEdited by Andrew HaywardApr 16, 2026Apr 16, 20263 min read
Image: Shutterstock/Decrypt
Image: Shutterstock/Decrypt
Create an account to save your articles.Add on GoogleAdd Decrypt as your preferred source to see more of our stories on Google.

In brief

An exploit that led to the minting of 1 billion wrapped Polkadot (DOT) tokens earlier this week is even worse than originally reported, according to the team behind Hyperbridge

What was originally thought to amount to $237,000 worth of token losses linked to the Polkadot-Ethereum bridge is actually closer to $2.5 million—a more than 10x increase from the initial report. 

“An attacker exploited a vulnerability in the Merkle Mountain Range (MMR) proof verification logic, allowing the culprit to mint assets and drain escrowed assets on Token Gateway,” the team posted in a Thursday postmortem

The attacker extracted roughly 245 ETH from a related TokenGateway contract.

About an hour later, a forged cross-chain message bypassed MMR proof verification, allowing the attacker to mint 1 billion bridged DOT and dump them into thin liquidity.

— Hyperbridge (@hyperbridge) April 16, 2026

“Our initial public estimate of the realized loss was approximately $237,000, based on the immediately observable sell-off of bridged DOT on Ethereum,” they added. “That figure did not capture the full picture, we later learned.”

In addition to the $237,000 in observable losses, a smart contract was exploited for 245 ETH or around $561,000 hours before the malicious DOT token mintings. Plus, three connected blockchains—Base, Arbitrum, and BNB Chain—were also impacted, contradicting the team’s original report that only wrapped DOT on Ethereum was affected. 

“Following reconciliation of attacker activity across each of the four chains, the two-phase nature of the attack, and losses from the associated incentive pools, the revised total realized loss is approximately $2.5 million, denominated in ETH and DOT at the time of the exploit,” it wrote.

The stolen funds have been traced to a deposit address on Binance, and the firm has engaged the centralized exchange’s compliance team and relevant law enforcement in an attempt to freeze and recover the stolen assets—but it doesn’t expect a resolution soon. 

“We are pursuing every available channel, but the realistic timeline for meaningful recovery in a case of this type is measured in months, and can extend up to a year,” it added. 

While its goal is to make all affected users whole, repaying funds that have been compromised, the protocol indicated that it is “committed to a structured BRIDGE token allocation to cover the residual loss,” should it be unable to do so. 

But BRIDGE, its native protocol token, maintains extremely low volumes, last trading $1,800 over 24 hours when it changed hands for around $0.006 on March 29, according to data from CoinGecko. At that price point, the token had a market cap of around $858,000, about one-third of the total losses from its exploit. 

Bridging functionality on the four affected blockchains remains paused, and will only resume after a patch is deployed and audited. 

“This does not change our conviction that cross-chain interoperability is only secure through cryptographic proofs,” the protocol team wrote. 

“What this exploit has made clear, expensively, is that verification logic needs more frequent audits and adversarial testing at every layer of the stack,” it added. “That is the standard Token Gateway will operate under going forward.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.
This article was originally published on Decrypt and is republished here under RSS syndication for informational purposes. All rights and intellectual property remain with the original author. If you are the author and wish to have this article removed, please contact us at [email protected].

NexaPay — Accept Card Payments, Receive Crypto

No KYC · Instant Settlement · Visa, Mastercard, Apple Pay, Google Pay

Get Started →