The next era of interoperability has begun.
You can now bridge & swap your USDC and USDT seamlessly across EVM networks, powered by Hyperbridge.
But it doesn’t end there, there’s always more…
Security is strongest when the community is involved.
Huge thanks to @HackenProof and the 20+ researchers who helped uncover and strengthen critical parts of Hyperbridge in less than a week.
Over $120,000 paid out so far through the bug bounty program.
$120,000+ paid out by @hyperbridge to 20+ security researchers in less than a week on HackenProof.
We’re grateful to @hyperbridge for being proactive and for their commitment.
A big thank you as well to our hacker community for their valuable contributions.
1 week. 927 reports. $120K in bounties paid. 0 SLA misses.
All handled flawlessly with HackenProof MCP.
If you're still manually triaging bug bounty reports and fighting through endless AI slop, it's time to upgrade and this is the standard you should be using.
Well done @hyperbridge team and congratz to all whitehats!
$120,000+ paid out by @hyperbridge to 20+ security researchers in less than a week on HackenProof.
We’re grateful to @hyperbridge for being proactive and for their commitment.
A big thank you as well to our hacker community for their valuable contributions.
Want to say a big thank you to all the security researchers on hackenproof reporting bugs.
If the issue you reported was fixed, rest assured you will be paid out.
Let the grind continue
All testing should happen on local forks only.
Live infrastructure attacks, social engineering, and third-party exploits are outside scope.
Submit your report here: https://t.co/WEgHNKV3Do
The Hyperbridge bug bounty program is now live on HackenProof.
Independent security researchers can review the Hyperbridge codebase and submit vulnerability reports through the security platform
🧵
This program is more about stress-testing the assumptions underneath the infrastructure itself, not just about finding bugs.
Reports submitted through HackenProof will be:
— reviewed
— classified
— acknowledged
— and rewarded within 3 days of approval
✅ [New bug bounty] Earn up to $50,000 with @hyperbridge
You will be rewarded based on these tiers:
Critical: $30,000 - $50,000
High: $5,000 - $15,000
Medium: $2,000 - $5,000
Low: $200 - $1,000
Start the #bugbounty hunt right now!
We’ve published the full post-mortem covering root cause analysis, exploit timeline, deployed fixes, audit findings, ecosystem disclosures and security architecture changes
Read the full report:
https://t.co/lIqFINB9HK
On April 13, 2026, an attacker exploited a vulnerability in Hyperbridge’s MMR verifier and drained the Token Gateway.
After a round of internal audits, we found the same class of bug in two widely used libraries across the Polkadot ecosystem, including pallet-beefy-mmr.
Here’s the full account 🧵
Hello @bcgame team,
Thank you for taking the proactive action of freezing these assets. This swift action has helped prevent the laundering of stolen funds and will greatly assist our ongoing investigation.
We are reaching out here because our previous attempts to contact you earlier this week - via email to [email protected] and direct messages on X - were unsuccessful. We would like to coordinate with you to facilitate the recovery of these tokens and further investigate this exploit.
Could you please arrange for the relevant DOT currently in your possession (along with any subsequent relevant deposits) to be returned to the Hyperbridge Sovereign Account: 13cKp88n27dzGussks75PWsnuKzQf4iMJSee31yvDBVvWDmU
(Address verification available here: https://t.co/PEcZ3y9gIl)
📢Official Statement: Abnormal Cross-Chain DOT Activity
We have closely monitored the recent exploit involving unauthorized cross-chain minting of bridged DOT tokens via the Hyperbridge protocol. This malicious activity poses a serious threat to the Polkadot ecosystem and broader crypto integrity.
To safeguard the industry, prevent potential money laundering risks, and protect our platform and users, https://t.co/WpNYAQujuV has taken the following decisive actions:
- All cross-chain generated DOT linked to the attack will be permanently locked.
- https://t.co/WpNYAQujuV does not support BSC-DOT; any deposits of such tokens will not be processed or credited.
Upholding the security and health of the crypto ecosystem remains a core principle at https://t.co/WpNYAQujuV.
For any inquiries, please contact: [email protected]