Security audit finds critical flaws in Hyperliquid Bridge, up to $1.2B at risk
A security audit of the Hyperliquid Bridge, conducted between October 12 and 26, 2026, identified four critical and six medium-severity vulnerabilities in the protocol's smart contracts. The bridge, which holds approximately $7.5 billion in total value locked across Ethereum mainnet and multiple L2 networks, received an overall risk score of 7 out of 10. Two critical reentrancy flaws were found in the lockTokens and releaseTokens functions, potentially allowing attackers to double-mint or double-release assets via malicious token callbacks. Two additional critical access-control weaknesses were identified, including a single-owner validator set with no multi-signature protection and an upgradeable proxy lacking a timelock mechanism. Auditors warned that these vulnerabilities could be combined with other attack vectors to compromise up to $1.2 billion in assets, and urged immediate remediation before the protocol reaches its next TVL milestone.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in