defirisk.co
rubric v1.7.0

Hypr Network: Bridge Contract Reinitialization (OP Stack Unpatched Dev Branch)

Hypr Network's bridge was drained for $220K just two days after launch because the team deployed from a non-production OP Stack dev branch that contained a critical reinitialization bug — a patch existed but hadn't been applied before go-live.

Occurred 2023-09-12 Loss $220K Status closed

Summary #

Hypr Network suffered a L2 Bridge (Gaming-focused L2) on 2023-09-12, resulting in a loss of approximately $220K.

What happened #

Hypr Network's bridge was drained for $220K just two days after launch because the team deployed from a non-production OP Stack dev branch that contained a critical reinitialization bug — a patch existed but hadn't been applied before go-live.

Linked factors #

  • RD-F-006 — causal : Audit-deploy gap — alternate field name [via dashboard_risk_factors/Code newly deployed/upgraded?: Yes — newly launched L2 bridge, 2 days old]
  • RD-F-007 — related : Bug bounty absent — baseline integrity gap [via dashboard_risk_factors/Bug bounty: N/A]
  • RD-F-076 — related : Protocol age (Cat 5 — < 6 months age signal) [via dashboard_risk_factors/Protocol age: 2 days (launched 2 days before exploit)]
  • RD-F-126 — causal : Is-a-fork-of (Cat 8 anchor) [via dashboard_risk_factors/Forked?: Yes — OP Stack fork (Optimism)]