BitcoinPolkadot Price Dips 6% Following 1 Billion Token Minting...

Polkadot Price Dips 6% Following 1 Billion Token Minting Breach on Ethereum – Services Bitcoin News

-


Key Takeaways:

  • A hacker used a replay flaw to mint 1 billion fake Polkadot tokens via the Hyperbridge gateway.
  • The price of DOT dropped 6% to $1.16 before recovering, while the hacker netted $237,000 in ether.
  • Hyperbridge developers are now expected to deploy patches to secure administrative smart contract functions.

Liquidity Bottleneck Limits Losses

On April 13, blockchain security firm Certik alerted the cryptocurrency community to an exploit involving the Hyperbridge gateway, where a malicious actor minted 1 billion unauthorized Polkadot tokens on the Ethereum network. Following the incident, the price of DOT briefly plunged from $1.23 to $1.16, a decline of nearly 6%. However, at the time of writing, the token had erased some of those losses, recovering to $1.19.

According to onchain data and security reports, the attacker exploited a vulnerability within the Hyperbridge gateway smart contract. By using a fabricated message to gain administrative privileges over the bridged DOT contract on Ethereum, the perpetrator triggered a single transaction that generated the 1 billion tokens.

Despite the large number of tokens created, the attacker was unable to cash out at the market value because the bridged version of DOT on Ethereum had shallow liquidity.

Analysis from Lookonchain confirms the hacker liquidated the entire 1 billion-token haul in a single swap. The trade yielded approximately 108.2 ether, valued at roughly $237,000 at the time of the transaction. Had the bridged asset been more widely traded, the financial impact could have been substantially higher.

Security experts were quick to clarify that the breach was localized to the Hyperbridge gateway on Ethereum. Polkadot’s core relay chain and the authentic DOT tokens residing on the Polkadot network remain secure and were not impacted by the incident.

In its initial post mortem, Certik said the exploit stemmed from a replay vulnerability in Merkle Mountain Range’s calculateroot function. This flaw meant that proofs were not properly bound to requests, allowing attackers to reuse old state commitments. Downstream, the tokengateway.handlechangeadmin function failed to enforce strict checks, letting attackers arbitrarily input request data.

As a result, malicious code propagated unchecked through the system, ultimately enabling the attacker to change the admin of the Polkadot token. As Certik noted:

“The attacker submitted ‘proof’ value is copied from the ‘_stateCommitments’ in a previous txn… thus making the replay possible.”

Hyperbridge has yet to release a full post-mortem on the specific flaw in the gateway smart contract, but developers are expected to implement patches to prevent similar exploits in the future.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

At the HumanX conference, everyone was talking about Claude

At the HumanX AI conference in San Francisco this week, thousands of techies descended upon the city’s Moscone...

PDAX Integrates Personal InstaPay QR for Direct Fiat Deposits

Philippine-based cryptocurrency exchange PDAX has introduced a new feature allowing users to fund their accounts using personalized InstaPay...

Morocco rolls out Nexus AI Factory in bid to lead Africa’s AI sector

Nexus Core Systems has entered into...

Circle prepares for IPO with interest from BlackRock and ARK

Circle is preparing for its initial public offering, with BlackRock and ARK reportedly interested in acquiring shares. Source link...

Advertisement

RAVE Token Rockets Past $9, Weekly Gains Top 3,400% – Markets and Prices Bitcoin News

Key Takeaways: RAVE surged 245% on April 13, pushing its total monthly gains past 3,600% and market...

Must read

At the HumanX conference, everyone was talking about Claude

At the HumanX AI conference in San Francisco...

PDAX Integrates Personal InstaPay QR for Direct Fiat Deposits

Philippine-based cryptocurrency exchange PDAX has introduced a new...

You might also likeRELATED
Recommended to you