Incident case

Hyperbridge Token Gateway 2026 MMR verifier exploit

An attacker submitted a forged Merkle Mountain Range proof containing an out-of-bounds leaf index that the verifier accepted. Downstream handlers treated the forged leaf as a valid Hyperbridge message and funds were extracted from Token Gateway. Hyperbridge paused bridging, patched and audited the stack, and later relaunched with a redesigned architecture.

reviewedcurrent

Incident facts

Incident title
Hyperbridge Token Gateway 2026 MMR verifier exploit
Bridge
Hyperbridge
Incident date
2026-04-13
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, Base, BNB Chain, Arbitrum, Unknown
Affected assets
Unknown
Attack category
Message Verification Failure
Reported loss
over $2 million
Amount confidence
High
Loss amount basis
Reported By Project
Recovery
Partial Recovery
Reimbursement
Unknown
Restart
Reopened
Current outcome
Migrated After Incident
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-09-03
Last verified
2026-09-03

Amount and valuation

Hyperbridge later reported realized loss of over $2 million, concentrated in DeFi Singularity incentive pools across Ethereum, Base, BNB Chain, and Arbitrum.

Use the later revised first-party assessment rather than the initial Ethereum-only estimate of roughly $237,000.

Why this remains unresolved

Timeline events

  • Hyperbridge Token Gateway MMR verifier exploited2026-04-13

    A forged proof with an out-of-bounds leaf index was accepted by the MMR verifier and downstream handlers treated it as a valid Hyperbridge message, enabling extraction from Token Gateway.

    Exploit OccurredHigh

    The later post-mortem supersedes the initial Ethereum-only scope.

  • Hyperbridge bridging operations paused2026-04-13

    Hyperbridge paused its messaging and bridging infrastructure within hours of detecting the Token Gateway exploit.

    Bridge PausedHigh
  • Hyperbridge bridging relaunched with redesigned architecture2026-06-15

    Hyperbridge announced that bridging had resumed after a redesign that replaced centralized proving and deprecated the shared TokenGateway in favor of issuer-owned Hyperfungible Token applications.

    Bridge ReopenedHigh

    This is a protocol relaunch; the shared TokenGateway itself is recorded as deprecated.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.