Hyperbridge has released an update regarding the attack incident; the vulnerability stemmed from a flaw in the Merkle proof verification logic.

robot
Abstract generation in progress

ME News Report, April 13 (UTC+8), the blockchain interoperability protocol Hyperbridge disclosed details of a previous DOT attack incident, resulting in a loss of approximately $237k. The vulnerability stemmed from the HandlerV1 contract’s VerifyProof() function lacking input validation, failing to check that leaf_index < leafCount, which allowed the attacker to forge Merkle proofs. The attacker used this to gain administrator privileges on the bridged DOT token contract on Ethereum, subsequently minting 1 billion bridged DOT tokens (about 2800 times the legitimate circulating supply of approximately 356k tokens), and cashing out on a decentralized exchange. Hyperbridge stated that they are currently working with security partners to trace the funds, and cross-chain functionality will remain suspended until the investigation is complete. (Source: Foresight News)

DOT2.74%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin