Hyperbridge HandlerV1 Flaw Exploited, $242,000 Lost

BlockSec's Phalcon team reported on April 13 that the HandlerV1 contract operated by Hyperbridge on Ethereum was hit by an MMR proof replay vulnerability, leading to losses of about $242,000. Investigators said the issue came from proofs not being bound to specific requests, enabling attackers to replay previously valid proofs and fabricate requests that modified administrator permissions. The attacker then minted additional DOT and ARGN tokens for profit. Reported losses totaled roughly $237,400 from DOT minting and about $3,800 from ARGN minting. The vulnerability was identified and analyzed by PhalconSecurity.