
Hyperbridge has launched a public bug bounty program on HackenProof, offering rewards of up to $50,000 for critical vulnerabilities. According to reports from HackenProof, the program invites independent security researchers to review the protocol codebase and submit reports through the security platform. The HackenProof page lists the Hyperbridge Protocol program as live and active, describing Hyperbridge as a system that lets blockchains communicate and transfer assets through consensus and state proofs, rather than older bridge models that rely on multisig committees.
The reward structure covers a comprehensive range of security issues, with rewards starting at $200 for low-severity reports and rising to $2,000–$5,000 for medium findings. As reported by HackenProof, high-severity bugs can earn $5,000–$15,000, while critical vulnerabilities can receive up to $50,000. The scope covers the full Hyperbridge protocol repository, with researchers able to report logic flaws, access-control issues, reentrancy, cross-chain message spoofing, state manipulation and any flaw that could affect message or fund integrity.
The bug bounty program follows an April exploit in which an attacker minted roughly 1 billion fake DOT-equivalent tokens on Ethereum through Hyperbridge's cross-chain gateway. According to reports from Crypto.news, the attacker gained admin control through a forged cross-chain message and extracted about $237,000 in ether. The fake supply affected the bridged DOT representation, while Polkadot's native network remained technically unaffected. The exploit highlighted common bridge risks where forged messages and weak verification checks remain attack paths.
The program includes specific testing restrictions, with Hyperbridge stating that testing must happen on local forks only. As reported by HackenProof, live infrastructure attacks, social engineering and third-party exploits are outside the program's scope. The HackenProof page requires proof-of-concept submissions and lists rules against service disruption, personal data access, spam, DDoS testing and reports that rely only on theory. Researchers must stay within scope and avoid public disclosure without approval.
Hyperbridge had previously appeared in crypto.news coverage before the exploit, with Enjin Blockchain using Hyperbridge on testnet in May 2025 to support cross-chain stablecoin transfers involving USDC and USDT from Ethereum and BNB Chain. According to earlier reports, that setup demonstrated why bridge security matters, as users lock tokens on one chain and receive matching versions on another network. When proof checks fail, the risk can move from one contract into a wider cross-chain system, making the new bounty program crucial for reducing repeat failures.