Hyperbridge Token Gateway 2026 MMR verifier exploit
An attacker submitted a forged Merkle Mountain Range proof containing an out-of-bounds leaf index that the verifier accepted. Downstream handlers treated the forged leaf as a valid Hyperbridge message and funds were extracted from Token Gateway. Hyperbridge paused bridging, patched and audited the stack, and later relaunched with a redesigned architecture.
Incident facts
- Incident title
- Hyperbridge Token Gateway 2026 MMR verifier exploit
- Bridge
- Hyperbridge
- Incident date
- 2026-04-13
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, Base, BNB Chain, Arbitrum, Unknown
- Affected assets
- Unknown
- Attack category
- Message Verification Failure
- Reported loss
- over $2 million
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- Partial Recovery
- Reimbursement
- Unknown
- Restart
- Reopened
- Current outcome
- Migrated After Incident
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-09-03
- Last verified
- 2026-09-03
Amount and valuation
Hyperbridge later reported realized loss of over $2 million, concentrated in DeFi Singularity incentive pools across Ethereum, Base, BNB Chain, and Arbitrum.
Use the later revised first-party assessment rather than the initial Ethereum-only estimate of roughly $237,000.
realized lossover $2 million
Revised first-party scope after tracing across four EVM networks.
Why this remains unresolved
- Reviewed first-party updates establish partial voluntary returns but not full recovery.
- Final reimbursement or loss-allocation completion is not established.
Timeline events
Hyperbridge Token Gateway MMR verifier exploited2026-04-13
A forged proof with an out-of-bounds leaf index was accepted by the MMR verifier and downstream handlers treated it as a valid Hyperbridge message, enabling extraction from Token Gateway.
The later post-mortem supersedes the initial Ethereum-only scope.
Hyperbridge bridging operations paused2026-04-13
Hyperbridge paused its messaging and bridging infrastructure within hours of detecting the Token Gateway exploit.
Hyperbridge bridging relaunched with redesigned architecture2026-06-15
Hyperbridge announced that bridging had resumed after a redesign that replaced centralized proving and deprecated the shared TokenGateway in favor of issuer-owned Hyperfungible Token applications.
This is a protocol relaunch; the shared TokenGateway itself is recorded as deprecated.
Evidence records
- Post-Mortem: Hyperbridge MMR Verifier Exploit, April 13, 2026Hyperbridge · Tier 1 · High reliability · primary · 2026-05-14Claim scope: Incident Case
First-party technical post-mortem establishing the forged-proof verifier failure and Token Gateway boundary.
- Update on Recovery Efforts and Next StepsHyperbridge · Tier 1 · High reliability · primary · 2026-04-16Claim scope: Shutdown
First-party update confirming the bridging pause and revised multi-chain loss assessment/recovery work.
- Hyperbridge Relaunches as an Interoperability HyperstructureHyperbridge · Tier 1 · High reliability · primary · 2026-06-15Claim scope: Restart
First-party relaunch notice establishing resumed bridging and deprecation of the shared TokenGateway model.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final recovered amount and final net unrecovered loss are not established in the reviewed sources.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.