Hyperbridge has revised the losses related to the hack on April 13, now estimating them at around $2.5 million. This amount is approximately ten times higher than the initial estimate of $237,000.
The team communicated this new estimate in a post-incident update on April 16. The revision includes losses from associated incentive pools, as well as the results of forensic analyses conducted on four EVM chains.
What the new estimate includes
According to initial reports, an attacker generated 1 billion bridged DOT tokens and liquidated the entire amount in a single transaction, thus harvesting 108.2 ETH (approximately 237,000 dollars).
However, the team clarified that this amount did not reflect the total extent of the situation.
“After comparing the attacker's activities across each of the four chains, considering the two-phase nature of the attack and the losses from the associated incentive pools, the total loss incurred, revised, amounts to approximately 2.5 million dollars, denominated in ETH and DOT at the time of the hack,” can be read in the blog.
Follow us on X for real-time news updates
The analysis also clarified the timeline of events that led to the breach. What seemed to be a single hack actually consisted of two related events, spaced about an hour apart.
The attacker initially extracted about 245 ETH from the Token Gateway smart contract. Nearly an hour later, they proceeded with the unauthorized creation of nearly 1 billion bridged DOT tokens.
These were then sold on the liquidity available on decentralized exchanges.
“On April 13, 2026, an attacker exploited a vulnerability in the verification logic of the Merkle Mountain Range (MMR), allowing the culprit to create new assets and drain the escrowed assets on the Token Gateway. This affected the pools of DOT tokens on the connected EVM networks: Ethereum, Base, BNB Chain, and Arbitrum,” the team specified.
The team emphasizes that the hack remains contained within the Token Gateway and the affected bridged token contracts on EVM networks.
Hyperbridge: recovery and compensation strategy
The blog reveals that a significant portion of the stolen funds has been traced back to Binance. Hyperbridge explains collaborating with the exchange's compliance team and law enforcement to attempt to obtain a freeze on the assets. The team warns that this substantial recovery could take several months to a year.
If the recovery proves insufficient, affected users will be compensated in BRIDGE tokens, the native asset of the Hyperbridge network. The compensation mechanism and distribution schedule will be communicated on April 13, 2027, exactly one year after the hack.
“Prioritizing recovery before any token-based compensation serves the affected users. Delivering premature compensation in tokens, without allowing the necessary time for on-chain traceability, compliance procedures on exchanges, and coordination with authorities, would dilute the actual value attributed to the affected users, thereby reducing the compensation they ultimately receive,” stated Hyperbridge.
The team adds that the Token Gateway remains halted and will resume operations only once the vulnerability is fully corrected, the update audited by an independent third party with the publication of the report, and additional safeguards deployed and operational. The coming months will be crucial to determine whether Hyperbridge will manage to recover a significant portion of the stolen funds.
