Hyperbridge has released an update regarding the attack incident; the vulnerability stemmed from a flaw in the Merkle proof verification logic.

robot
Abstract generation in progress

ME News Report, April 13 (UTC+8), the blockchain interoperability protocol Hyperbridge disclosed details of the previous DOT attack incident, with losses of approximately $237k. The vulnerability stemmed from the HandlerV1 contract’s VerifyProof() function lacking input validation, failing to verify that leaf_index < leafCount, which allowed attackers to forge Merkle proofs. The attacker used this to gain administrator privileges on the bridged DOT token contract on Ethereum, then minted 1 billion bridged DOT tokens (about 2800 times the legitimate circulating supply of approximately 356k tokens), and cashed out on a decentralized exchange. Hyperbridge stated that they are currently working with security partners to trace the funds, and cross-chain functionality will remain suspended until the investigation is complete. (Source: Foresight News)

DOT1.12%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin