May 22, 2025
Case Studies

Hypernative Detection: $1.3M Exploit of Bitcoin Mission on Arbitrum

The Hypernative platform flagged the malicious address used in the attack more than 22 hours before the first exploit

Hypernative

On April 17, 2025, Bitcoin Mission, a team using an incentive-based system to promote consensus propagation of Bitcoin, lost $1.3M in an exploit on Arbitrum. The Hypernative platform flagged the address involved in the attack as malicious 22 hours and 47 minutes before the execution.

The real story isn’t just that Hypernative flagged it early—it’s that this kind of exploit happens often, and shouldn’t still succeed. A standard Hypernative configuration would’ve prevented it, no drama, no headlines.

Dan Caspi
Co-founder & CTO
Hypernative

The exploit took advantage of a caller validation vulnerability in the OverPaper function of the protocol's Card Factory contract. This flaw allowed the hacker to withdraw a portion of the contract's balance each time it was exploited. The attack spanned 5 days and over 424 transactions.

Detection Timeline

The Hypernative platform accurately flagged the attacker's wallet as suspicious more than 22 hours before the first attack, when it was funded from Tornado Cash.

Prevention > Postmortems

Funding from suspect or sanctioned origins raises a flag, but it is important to distinguish would-be-attackers from privacy enthusiasts. And an early-warning system is only useful if it combines a high rate of detection with a low false-positive rate. Hypernative Platform's suite of detection engines includes a real-time machine-learning pipeline that can classify contracts based solely on their bytecode, without relying on noisy markers like funding sources. The system 

  • Monitors 60+ chains;
  • Covers security, technical, financial, governance and other risks;
  • Detected 99.5% of hacks over past two years with less than 0.001% false positive rate;
  • Saved more than $2B of funds to date with $100B of fund protected

Reach out for a demo of Hypernative’s solutions, tune into Hypernative’s blog and our social channels to keep up with the latest on cybersecurity in Web3.

Secure everything you build, run and own in Web3 with Hypernative.

Website | X (Twitter) | LinkedIn

Secure everything you build, run, and, own onchain

Book a demo