HubSec
ResearchSentinelForensicsAboutContact
ResearchSentinelForensicsAboutContact

Research

Post-mortems and vulnerability analysis for the Polkadot ecosystem.

April 13, 2026critical

Hyperbridge ISMP Gateway Exploit

Post-Mortem Analysis — April 13, 2026

An attacker exploited four compounding vulnerabilities in the Hyperbridge ISMP gateway to mint 1B bridged DOT and extract approximately $250,000-$787,000 across two transactions. Novel MMR proof boundary bypass, missing cryptographic binding, shallow governance auth, and dangerous ERC-6160 privilege model.

PolkadotEthereumBridgeProof ForgeryERC-6160Read analysis
HubSec

Independent security research for the Polkadot ecosystem.

PGP: 1027 0DFF 53E0 B61F 809F C079 E0E6 BF50 4785 0199 Verify

ResearchSentinelForensicsAboutContact

HubSec Forensics provides on-chain intelligence and evidence packaging. Attribution analysis produces probabilistic assessments, not definitive identification. Timezone estimates, behavioral profiles, and entity resolution are investigative leads, not proof of identity. HubSec does not access off-chain personal data, IP addresses, or exchange KYC records. For identity confirmation and legal action, engage qualified legal counsel and law enforcement with the evidence package HubSec provides.

© 2026 HubSec. All rights reserved.