Two Days Into Its Life, Hypr Network's Bridge Loses $220K to a Forked Optimism Bug
Gaming-oriented layer-2 network Hypr lost roughly $220,000 — 2.57 million HYPR tokens — to a bridge exploit on Wednesday, December 13, 2023, barely 48 hours after its mainnet beta launch.
A community member (@ManaMoonNFT) flagged the suspicious activity before the team itself confirmed anything had gone wrong. The Hypr account initially posted a vague caution rather than acknowledging an attack outright:

📢 ATTENTION: Do not use the Hypr Network Bridge. The team wants to perform some more tests and do some further audits on the bridge.
A subsequent update clarified that the broader HYPR holder base was unaffected — the loss was confined to two wallets, which happened to be the only addresses that had bridged tokens up to that point.
Even so, HYPR's price fell nearly 40% once the attacker converted the haul into 97 ETH (around $220,000 at the time). The token has since clawed back losses alongside the broader market recovery.
01Not a keys problem this time
Recent months have brought a string of bridge losses tied to compromised private keys — Heco/HTX, Multichain, and Poly Network among them. Hypr's incident is different: it's the first bridge hack rooted in an actual code vulnerability since the BNB Bridge incident last fall — setting aside the Shibarium bridge's brief self-inflicted freeze in August.
Credit for the technical breakdown goes to BlockSec and to Hypr Network's own post-mortem.
02How the bug got there
Hypr runs on the OP Stack, the framework that lets teams spin up their own Optimism-derived rollups by forking Optimism's codebase.
According to Hypr's post-mortem thread, the team had built on the most current commit of the OP monorepo's develop branch at deployment time — not realizing that branch wasn't meant for production use and still carried an unpatched critical flaw. The full post-mortem has since been published.
BlockSec's technical breakdown described the mechanism:
The root cause was that the attacker managed to circumvent the 'finalizeERC20Withdrawal' function check by reinitializing the contract, due to the existence of the 'clearLegacySlot' modifier.
In effect, a contract-reinitialization path let the attacker bypass the withdrawal safeguard entirely.
03The addresses involved
Two wallets carried out the exploit:
- Exploiter address 1: 0x5b8d598b354f5760b2a65f492154e7a3df46d1be
- Exploiter address 2: 0x3ea6ba6d3415e4dfd380516c799aafa94e420519
The attack transaction is recorded at 0x51ce3d9cfc85c1f6a532b908bb2debb16c7569eb8b76effe614016aac6635f65.
Initial funding for the attacker came from FixedFloat, a service frequently used by exploiters to source starting capital, via this transaction. As of publication, the stolen ETH had not moved from the 0x5b8d address.
04Accountability across the stack
The episode illustrates a recurring tension in DeFi: reusing and building on open-source code accelerates innovation, but it also means a single flaw can ripple across many independent projects, as seen previously with Curve's Vyper bug and its knock-on effects elsewhere in the sector.

BlockSec noted that the underlying vulnerability had already been patched by the OP team, but only after Hypr's contract was already live:
This incident underscores the importance of the community working collaboratively to refine the process for releasing security patches, which will undoubtedly benefit us all.
Hypr's post-mortem noted that after discussions with OP Labs, the latter acknowledged room for improvement in their release and communications process.
The Optimism Foundation, having reassured the community that no other OP Stack deployments were impacted, added:
We encourage developers building projects in production to use releases approved by Optimism governance, which meet the security bar established by the Collective. We're also improving our release comms processes to help ensure it's clearer to projects leveraging the OP Stack.
05The cost of moving fast
Being early to a fresh ecosystem often comes with real upside for the first users who show up. With market sentiment reawakening after a long stretch of indifference, FOMO is once again pulling people toward untested platforms — a dynamic that makes incidents like Hypr's a useful reminder of the trade-off between speed and caution when adopting brand-new infrastructure.
Get new scam files the moment we publish them — usually 2–3 emails a week.