On April 13, 2026, an attacker exploited a vulnerability in Hyperbridge’s MMR verifier and drained the Token Gateway.
After a round of internal audits, we found the same class of bug in two widely used libraries across the Polkadot ecosystem, including pallet-beefy-mmr.
Here’s the full account 🧵