**[Updated Pre-Proposal Discussion] DOT Recovery Loan to Hyperbridge Exploit Victims**

Posting in a more formal capacity than usual, on behalf of W3F -

The Web3.0 Technologies Foundation (“W3F”) has been following this thread, and the related discussion across the forum, since the Hyperbridge Token Gateway incident on 13 April. We recognise that real losses have been borne by real users.

We want to be clear about W3F’s position, because we think candour serves this conversation better than silence.

The exploit concerned Hyperbridge’s Token Gateway contracts on Ethereum and other EVM chains. Those contracts were not deployed, operated, or controlled by the W3F. Hyperbridge is an independent team, and the recovery process — including asset tracing, exchange coordination, law enforcement engagement, and the BRIDGE-token compensation mechanism Hyperbridge has committed to — is being run by them as described by them publicly. Affected users looking for updates on recovery, timelines, or compensation should engage with Hyperbridge’s published official channels directly, where the substantive information sits.

We’ve seen calls for W3F to coordinate with Hyperbridge on a solution. W3F is in regular contact with teams across the ecosystem, as you would expect, but it would not be appropriate for W3F to position itself as a co-author of a recovery process that isn’t ours to run. The remediation process is being led by Hyperbridge.

We appreciate the seriousness with which forum members are engaging with this question.

Hello Bill, SAXEMBERG,

Thank you Bill and Saxemberg for posting in a formal capacity. Candour is genuinely appreciated, and so is the explicit acknowledgment that real losses have been borne by real users. Me and several other severely affected users want to engage with the substance directly, because I believe there is more common ground here than the framing of the post suggests.

First, on what is not being asked. No one in the affected LP community has claimed that W3F deployed, operated, or controlled the Token Gateway contracts. No one is asking W3F to co-author Hyperbridge’s recovery process. No one is asking W3F to lead asset tracing, exchange coordination, or law enforcement engagement. The framing of the post addresses positions that have not been put forward. What is being asked is structurally different and narrower.

Per W3F’s own September 2024 press release (Chainwire, coinpaper.com/5356/…):
• Hyperbridge was “Web3 Foundation’s inaugural funding initiative”
• W3F led the seed round of Hyperbridge in active partnership with Scytale Digital
• W3F’s then-CEO publicly described Hyperbridge as “embodying the highest standards of security”
• The press release explicitly states about Hyperbridge security: “audits conducted by the same team responsible for Polkadot”
• W3F-attributed marketing claimed Hyperbridge would offer “the highest level of economic security for any bridge available today”
• The crowd loan raised $2.7M from the Polkadot community on the basis of these endorsements

In addition, the DAO allocated 795,000 DOT to the DeFi Singularity campaign that actively recruited external LPs into Hyperbridge pools. Hyperbridge is documented as official Polkadot infrastructure on the W3F-copyrighted Polkadot Wiki.

Liquidity providers entered these pools based on these specific public endorsements. They provided private capital for the development of the ecosystem, incurring impermanent loss and token depreciation - as part of participating in DeFi. They did not consent to taking on 100% of all losses from a hack on infrastructure approved at the ecosystem level.

One question from several affected individuals: Why are such facts being ignored?

Secondly. Yes, a full post-mortem report with all loss compensation measures is not yet available, but even now, based on the latest Hyperbridge post: Update on Recovery Efforts and Next Steps , there are critical questions to be answered asap:

• In the initial version of the report, there was a statement that a separate compensation proposal would be made for liquidity providers. About a day later, the statement was changed by Hyperbridge, and now the report only mentions DOT holders as affected - even though liquidity providers have suffered double losses. This needs to be revised!

• The compensation measures do not include either future bridge fees or undistributed DOT from the DeFi Singularity program. From the official address of that program, 13w5qyCGFJaf3mdcWfCK2RV6UhGafwD23j71DBa8Yk3K1k4r, on 15-02-26, 198,500 DOT were sent as a reward for liquidity providers. On 16-02-26, they arrived at the Bifrost address. On the same day, 198,500 vDOT were minted. At the time of the hack, 173,363 vDOT remained undistributed at the Bifrost address. This is exactly what Saxemberg was talking about (initiating a referendum on the Hyperbridge network), except that vDOT is not stored in Hyperbridge’s account.

• The allocation of the BRIDGE token to cover leftover losses. As of now, the token is not traded anywhere!

• The Hyperbridge team does not reply to emails, does not publish a timeline for releasing the report. There is also no register of affected parties with loss amounts, nor any specifics. They have taken a position of silence. Yet, according to a message in Telegram, the bridge itself is expected to launch within the next two weeks.

All of this requires the following in our opinion:

  • The structural basis for fair loss compensation, if necessary, requires some form of assistance from Hyperbridge’s main investor, namely W3F.
  • W3F mentions that it is in regular contact with teams across the ecosystem. That is precisely the channel through which this discussion should take place. We are not asking for public involvement in the Hyperbridge recovery process. We are asking for W3F to engage with Hyperbridge in resolving the issues mentioned above and make sure that all collected DOT, all vDOT and all frozen funds and future bridging fees and other financial income is used solely to repay victims. We lost 2.5 Million, some of us lost 6 digit amounts as a private person, some lost all assets they had. And again: based on all the involvement and marketing around Hyperbridge, users should not be the ones who take all the risk at the end, while the big players just move on without engagement.

@saxemberg @bill_w3f @ThomasR

It is nearly one month since the April 13 exploit.

Hyperbridge remains silent. No substantive post-mortem. No timeline. No updates. No reaction to the most obvious recovery step: distributing the undistributed Singularity vDOT, which was always intended for LPs in the first place.

We the affected LPs need direct support and engagement from Major Voters and especially W3F. W3F please reach out to Hyperbridge as your investment and as the protocol you funded, audited, and publicly endorsed. Push them to communicate, to inform, to be professional, and to distribute what is already available.

We have lost enormous amounts. The continued silence on the back of users who responded to a DAO-funded campaign on infrastructure documented as official Polkadot is not acceptable from any mature ecosystem.

A direct conversation between W3F, Major Polkadot Players and Voters and Hyperbridge is overdue. We are not asking for miracles. We are asking for basic professional communication and the disbursement of funds that are sitting idle while LPs absorb the full loss.

Please engage.

Bill already responded to this above.

Hello, Dear Gr33nHatt3R,

There is no answer here. This is a wave-off from the affected users, completely ignoring their arguments and evidence. The problem will not solve itself anyway. So far, apart from vague information from the hyperbridge and complete ignorance of the facts of responsibility on the part of W3F, there is nothing. No explanations, no prospects, no deadlines. If W3F acknowledges that real users have suffered real losses, this needs to be addressed somehow. W3F has all the tools and leverage to provide assistance on this matter. We are not asking for the impossible — we are asking for an HONEST constructive dialogue in seeking a solution to the problem of the affected LPs.

At this stage, all that can happen is to wait until the bridge gets back online as this is the only way any repayments can be done. According to a Hyperbridge team member “the issue of users who held (and are still holding DOT) before the exploit will be sorted after the bridge re-opens”.

Agreed on most accounts as communications from many sides have been abysmal. In any case, several DMs have been sent to some self-identified victim accounts but none has been answered so far.

Once the bridge is reopened which is something that should happen in the next few weeks (it won’t take many months as one of the commenters on TG argued) other options could be weighed in. Hopefully the plan for LPs is brought forward soon.

Hi Saxemberg, I have contacted several victims to check their DMs. You contacted them via Discord or X or TG?

The most crucial item for now is that major voters, w3f and the polkadot treasury are in a DIRECT line with Hyperbridge to distribute the vDOT which naturally would have been paid out to LPs anyway, would the bridge not have been hacked.

@bill_w3f

Thank you for the formal statement on May 14. I want to engage with the substance directly while addressing several structural concerns that require Web3 Foundation’s attention.

Context: Professional Investor Obligations

I am writing in my capacity as CEO of a corporate LP depositor and investor with obligations to shareholders. These obligations require us to pursue structured recovery frameworks for our losses from the April 13 exploit across pools that were part of the DeFi Singularity campaign.

Three Structural Concerns Requiring Clarification

1. Undistributed DeFi Singularity vDOT Allocation

Per the official 6-month report, only 336,593 vDOT of the 795,000 DOT Referenda 1439 allocation was distributed. Approximately 458,000 DOT (~$600-800K) remained undistributed when the pools were compromised.

The complete silence from Hyperbridge on the disposition of these funds - despite the question being raised repeatedly across Telegram, Discord, and the Forum for over one month - creates the impression that they are considering options other than disbursing them to the affected LPs for whom they were allocated.

These funds represent the single most obvious and immediate recovery source. Yearn Finance precedent: within 2 days of the Sonne Finance exploit, they disbursed OP rewards to affected users, recovering 30-50% of losses immediately. The vDOT represents a similar proportion for Hyperbridge victims.

We need direct confirmation from Hyperbridge that these funds will be disbursed to affected LPs in DOT/vDOT, not retained, redirected, or substituted with BRIDGE tokens.

2. Total Loss Figure Discrepancy

The $2.5M figure cited by Hyperbridge does not align with external LP exposure as we understand it. External LP losses appear to be in the range of $1.5M, not $2.5M. This distinction is material. If Hyperbridge is including internal protocol liabilities or ecosystem partner losses in the denominator to minimize the vDOT payout ratio to external LPs, that needs to be clarified immediately. The vDOT were allocated exclusively for liquidity providers under Referenda 1439, not for covering other categories of loss.

We need transparency on the composition of the $2.5M figure and confirmation that the vDOT allocation will be calculated against actual external LP losses.

3. Web3 Foundation’s Role in Securing Direct Engagement

Your May 14 post states that affected users should “engage with Hyperbridge’s published official channels directly.” That is precisely what we have been attempting for over one month. The response has been silence on the most fundamental questions.

The relationship between W3F and Hyperbridge - as documented in W3F’s own September 2024 press release - goes beyond passive infrastructure provision:

  • W3F’s “inaugural funding initiative”
  • W3F led the seed round with Scytale Digital
  • W3F CEO publicly stated Hyperbridge “embodies the highest standards of security”
  • Press release claimed “audits conducted by the same team responsible for Polkadot”
  • Hyperbridge documented as official Polkadot infrastructure on W3F-copyrighted Wiki

The post-mortem now confirms that the exploit resulted from a missing bounds check in code written over two years ago, plus 14 additional vulnerabilities identified post-incident - including a second critical bug that could have allowed permanent bridge compromise.

W3F mentions being “in regular contact with teams across the ecosystem.” That contact provides W3F with leverage that external LPs simply do not have.

We are not asking W3F to co-author Hyperbridge’s recovery process. We are asking W3F to use its relationship with Hyperbridge to secure:

  1. Direct, substantive engagement from Hyperbridge on the vDOT allocation question
  2. Transparent disclosure of the loss composition ($2.5M breakdown)
  3. A realistic timeline for a full recovery and disbursement framework

Why This Matters for the Broader Ecosystem

The Hyperbridge Recovery is also an ecosystem positioning cases. Mature ecosystems recognize that protecting users of actively promoted infrastructure is essential for long-term trust and capital formation.

W3F’s relationship to Hyperbridge is structurally stronger than most industry precedents. The question is whether the Polkadot ecosystem will adopt the emerging 2026 standard we have seen from other hacks - coordinated recovery frameworks for infrastructure failures in DAO-endorsed campaigns. Or default to a model where victims absorbed 100% of losses.

Requested Action

I respectfully request that W3F facilitate direct engagement between Hyperbridge and affected LPs on the three questions above, using the regular contact channels W3F has with Hyperbridge.

Thank you for your consideration.

What is truly shocking to me is that we are seemingly watching yet another last-minute, security-compromising change to an OpenGov proposal (just in the Summary not in the description) unfold.
According to this pre-discussion, it appears this action is already effectively pre-approved by the Web3 Foundation and Parity. When structural decisions regarding ecosystem risk and treasury allocations are rubber-stamped behind closed doors—bypassing rigorous, decentralized oversight—it sets an incredibly dangerous precedent.
Operating like this undermines the entire permissionless framework we are supposed to be building. It makes the next attack or systemic failure feel less like an isolated possibility and more like just a matter of time.

@ThomasR - a factual clarification on the undistributed DeFi Singularity vDOT, so that everyone following this thread, including potential voters, works from accurate information.

To avoid conflating separate things, there appear to be two distinct categories:

  1. The undistributed CAMPAIGN vDOT - approximately 458,000 of the 795,000 DOT from Referendum 1439, earmarked as LP incentives via Merkl and never distributed because the pools were compromised in the exploit.

  2. Any vDOT that Bifrost itself holds, whether as an LP participant or carried over from its own positions.

My question concerns only category 1 - the undistributed campaign rewards.

Two specific questions:

  1. The undistributed campaign vDOT appear to sit on the Bifrost parachain under a multisig. Which party holds operational control over their distribution? My understanding is that control rests with the Hyperbridge team, and that Bifrost cannot move these funds unilaterally absent some specific arrangement. Could you confirm or correct this?

  2. Does Bifrost have any unilateral ability to distribute, move, or redirect these campaign vDOT, or does that authority rest with Hyperbridge (or require a governance action)?

This matters because clarity on who controls these specific funds determines which party the affected LPs should address regarding disbursal. Earlier in this thread Bifrost was described as “just a user of Hyperbridge’s services.” Confirming that Bifrost does not control these campaign vDOT would be consistent with that and would help everyone understand where responsibility for these funds lies.

Thank you for the clarification.

We share the text of the proposed Wish For Change referendum on Polkadot that seeks to Disburse the Undistributed DeFi Singularity vDOT (Referendum 1439) to Hyperbridge LPs Affected by the April 13 Exploit.

We invite affected parties like @BCG @Hackvictim @Polka to engage constructively with the parties who hold a lot of the weight in the vote like the W3F and their representatives like @bill_w3f @Pala_Labs The Polakdot Community Foundation and many others to show the facts around this referendum. We also invite Polytope Labs to engage with this referendum and participants.

It doesn’t work the way you say. Anyone in possession of funds allocated for an OpenGov approved purpose which went unused, must immediately return them to Polkadot treasury.

Putting this to OpenGov as a Wish For Change is the wrong route. A Wish For Change moves no funds, but that is the problem: the signal alone would make Polkadot governance the body that adjudicates exploit refunds, and that is the precedent to avoid. The exploit came from a flaw in Hyperbridge’s own code, as the post mortem confirms, so the responsibility is the protocol’s, not Polkadot’s.

Governance has only one proper role here. Not authoring the compensation, but managing its own treasury: whether to lend new capital, and whether to reclaim unspent budget from a campaign that is now closed.

The fix belongs to the two teams that ran the campaign. The undistributed Singularity rewards are vDOT, a Bifrost asset, so what providers genuinely earned can be released on the Bifrost side with no Polkadot vote. The unspent remainder is budget for a campaign that no longer exists and should return to the treasury.

Hyperbridge should cover the principal losses. It raised over five million dollars across its seed and public sale, and its CEO said in November the team runs a low burn with close to four years of runway. For a team this size, losses near 1.5 million are within reach. The question is will, not ability.

On leverage, candidly: we hold a real one over Bifrost, which is asking the treasury right now to renew its 1M DOT loan, and little direct hold over Hyperbridge. So make that renewal conditional. Bifrost engages Hyperbridge, they come back with a concrete joint plan that pays providers and returns the unused budget, and only then does the loan proceed. Without it, vote it down.

Unfortunately @thewhiterabbitM has been wrong on most points.

It was forcefully suspended after the exploit and it is not depleted hence not over. Not completed either. Funds remain there and belonged to the LPs in its intention. Returning all funds back to the treasury seems to be the maximum pain option for all as it solves nothing and only creates more uncertainty and punishes the LPs and the protocols the hardest. That’s the reason why a vote is needed to make these new terms official which in our view would align in its original intention without just executing them arbitrarily. The second best option is to just keep the funds there untouched awaiting for future interactions.

The funds were awarded through Polkadot and a Wish for Change in that intent coming from Polkadot about the funds granted by Polkadot is a direct line of intention for funds that are there available under the control of Hyperbridge/Bifrost. So Polkadot OpenGov is not irrelevant in this conversation as you try to frame it. If you can ask for a return to the Polkadot treasury then that also means that Polkadot is also in a direct line of influence, interaction, etc. You can’t have it both ways. You can’t say Polkadot doesn’t have a role in this conversation but it also should 100% act on its own behalf to claim back the funds. It’s an attempt for a free lunch.

So it’s better to frame it in the way that other teams have already done:

Yearn, disbursing planned rewards.

Sonne, disbursing planned rewards.

Kyberswap, settling the debt with future profit.

Bitfinex, monetizing the debt with future profits.

So in this case, it would take a similar precedent to other protocols did by their own only in this time action would be taken by the approval of the DAO that granted the funds in the first place. It also wouldn’t require a bailout as these funds are already there. And any other funds claimed back from CEXes would still be there for future compensation as we all know Singularity funds don’t cover more than 35% of the debt.

With that being said, it’d be more welcome if most people involved as a victim would come forward to weigh in in this situation.

Fully supporting this proposal as one of the affected parties. I want to lay out why this is the only fair path forward and address the objections that have been raised.

Why this is fair and correct:

These vDOT were never a discretionary bonus. They were allocated under Referendum 1439 as rewards against the liquidity LPs actually provided. Per the official 6-month report, only 336,593 of the 795,000 DOT were distributed, leaving roughly 458,000 DOT undistributed. Had the bridge not been exploited, these rewards would have reached LPs through the normal Merkl distribution schedule. The exploit, caused by a missing bounds check in Hyperbridge’s MMR verifier per their own post-mortem, interrupted that. LPs did nothing wrong. Asking the victims of an engineering failure to also forfeit the rewards they were already earning is not defensible.

This costs the Treasury nothing. This is the point that dissolves most objections. No new funds are requested. This is the disbursal of funds already granted under 1439, to the exact recipients they were intended for. There is no precedent concern, no budget impact, no bailout.

The precedent is established and recent. Following the Sonne Finance exploit, Yearn redirected undistributed OP rewards to affected users within two days. Two days. Here we are at more than two months of silence. Bitfinex, Kyberswap and others returned funds while investigations were still active. The claim that disbursal must wait for law enforcement to conclude is simply not how comparable cases have been handled.

On the objection that this should wait for the full recovery process:

This conflates two separate things. The stolen funds under investigation and the undistributed campaign rewards are not the same pot. The vDOT were never stolen. They were simply never distributed because the pools were compromised. There is no investigative reason to keep allocated LP rewards frozen while LPs sit in limbo. If anything, the risk runs the other way: if the bridge relaunches and the campaign resumes, these undistributed rewards could be captured by fresh capital instead of the LPs they were owed to. This proposal correctly prevents that by establishing that LP debt takes seniority over any future campaign rewards.

On the delay itself:

Every week of silence destroys value. DOT has depreciated significantly over this period. The affected LPs are not only carrying their principal loss, they are watching the one clearly available recovery source lose value while no party will even confirm its disposition. This is avoidable harm caused purely by inaction.

A direct call to Bifrost and Hyperbridge:

Bifrost was co-proponent of Referendum 1439, not merely a user. Hyperbridge controls the undistributed vDOT. Both have been asked repeatedly, across the forum, Telegram and Discord, for a simple confirmation: will these undistributed vDOT be disbursed to affected LPs, yes or no? The continued absence of a straight answer is itself telling. I invite both teams to engage here, on record, before more value is needlessly destroyed.

This proposal asks for nothing unreasonable. It asks that funds already allocated to LPs reach those LPs. I support it fully and urge delegates and affected parties to do the same.

Thank you, thank you @SAXEMBERG!

As one of the victims (my loss was around $30k at the time of hack), I’ve been screaming at the wall in their discord, just to be met with pretty much automated responses and nothing from the founders. I was starting to accept the fact that I’ll never see anything back and that this is another one of those incidents that are successfully swept under the rug.

I’m willing to cooperate however possible. I’m not expecting to get all my money back — I took a risk and there were consequences. I’m just looking for a transparent, fair and just process to wrap up this chapter for all of us. Releasing the funds that were meant for the LP’s to the LP’s to cover their losses would be a great first step.

Thanks for the clarification, that closed the loop for me, and apologies for my earlier misreadings. Stepping back though, this looks like a solution in search of a problem. And the problem, such as it is, belongs to Hyperbridge and Bifrost, the two proponents of the DeFi Singularity campaign.

I am sorry for everyone who lost funds. That is real, and I don’t say it lightly. It is also, with respect, not the Polkadot community’s bill to pay.

The 1439 proposal already answers what happens to the leftover, in its own words: “All unused funds will be returned to the treasury.” That was approved. No vote is needed to follow a rule we already set, only to break one.

And the rewards were never an entitlement. They were an APY for providing liquidity, a minimum deposit held for a minimum time. The pools are gone, so the remainder was earned by no one. That is not a debt, it is pay for work that can no longer be done. The funds also already sit with the responsible side: under 1439 the curators controlling distribution are Hyperbridge and Bifrost themselves. Polkadot does not move anything here. They do.

As for trust, Hyperbridge spent its own. Twelve days before the exploit, on April 1, the team joked about a fake breach and called the protocol “effectively unhackable”. On April 13 an attacker minted a billion fake DOT through it. That is on them. And trust does not come back by having Polkadot and its community gift money to cover a loss that two funded teams caused and are responsible for. A little accountability would not hurt. It is overdue in web3.

Which is the part I still don’t follow. You are not an affected LP, yet a lot of effort is going into making this Polkadot’s decision rather than Hyperbridge’s responsibility. The simplest path is the one the rules already describe.

So: unused funds go back, as written. Hyperbridge covers the loss it caused, as it already promised to do in BRIDGE, and since its relaunch it can. The two proponents bring one plan. Bifrost is asking the treasury for a fresh 1M DOT loan right now, which is exactly where to ask for it.

No probs, hopefully we get to see proper interactions this time. Make sure to be ready to interact with the voters once the decision vote goes live. Stay in the loop and make sure to follow up this thread and referendum. Make sure to comment there too.

It’s not unused and quite allocated and that’s the point as there are some entities that are directly connected to them as potential senior grantees, it’s quite easy to tell and there is no point in rereading that point over and over so an example for proper understanding is coming next on why this clawback attempt is inconsistent and how properly abandoned funds have no one to claim rights over those funds. No need for snark either so try to keep it civil will ya?

If you want to clawback the funds you are more welcome to kickstart a competing proposal to do that and you are free to vote against this one, that’s the whole point as Polkadot should have a say on those funds if needed. While you’re at it make sure to clawback all the unused funds from other referenda many of which are there abandoned for years like Mythos unused marketing costs. Mythos funds are properly unused and abandoned on a multisig just to put a concrete example. That was more valuable than this referenda for some time and taking it back wouldn’t have damaged real people, not even whatever Marketing agency or KOL Mythos wanted to fund and didn’t make use of as of now has been completely abandoned. But you never raised any concern about it and many other similar referenda with unused funds so it’s quite curious what got you so fixated on this referendum with real people who believed in the ecosystem are on the line and on the loses side and heavy impact on people’s lives when there are other older referenda with more funds open for returns which would have affected no one. Just a completely straightforward example as to why this clawback approach to 1439 funds is not consistent with anything you or anyone has done in the past and how these referenda differ in its potential grantees. Abandoned basically means there is no one to give it to or no concrete use of it was made or no delivery was done while funds remain stranded. If clawbacks are so important then start doing a proper clawback of other referenda such as the Mythos one first, you’ll get more value and the human impact will be far less than for this one.

With that been said, these two referenda are not be equivalent in any way shape or form as the Mythos multisig should 100% be responsible for the return of these obviously abandoned funds whereas the funds granted by 1439 definitely has entities entitled to these funds and are very much in use and entities are surrounding them which is the main point of the idea. Showcasing them side by side had to be done to make crystal clear the inconsistency in clawback intentions if there ever was any and the direct idea on what constitutes as abandoned.

(Thanks to the kind anon that noticed this)

The Bifrost loan is not meant for payments to affected LPs, it’s never been intended for such use and the returns are offered to the treasury, So it’s a completely inaccurate approach.

One correction first. You suggest I kickstart a competing proposal to claw these funds back. But there is nothing to claw back, and no new referendum is needed. 1439 already states that unused funds return to the treasury. That is the approved rule. The burden of a referendum falls on whoever wants to depart from it, not on someone asking that it simply be followed. Redirecting those funds is the new proposal here. Returning them is just the original terms.

To be clear, this is only my personal opinion, offered as one community member.

Mythos, with respect, is beside the point. Whatever should happen to other referenda is a separate conversation I am glad to have elsewhere. It does not change what 1439 itself says.

What strikes me is how much effort is going into solving what is, for Polkadot, a non-problem. The flaw was in Hyperbridge’s code, not in Polkadot. Polkadot’s consensus, its parachains and native DOT were never touched. So there is no reason to pull in an entity whose only role was to fund a campaign that later went wrong because of an exploit it did not cause. The DAO put up money for a growth campaign. That campaign failed for reasons that sit entirely with the protocol that was hacked.

And it is worth remembering what that campaign also was. It was, in part, marketing for Polkadot and its infrastructure. The exploit did not only hurt the LPs, it reflected badly on Polkadot too, a collateral hit to a network that did nothing wrong. That damage gets worse, not better, if the unused funds are kept rather than returned, and if Hyperbridge and Bifrost do not make their users whole. Returning the grant and repairing the harm is how the reputational damage is contained. Repurposing DAO funds to paper over a protocol’s failure is how it deepens.

On entitlement, the same logic settles it. The APY was earned by providing liquidity, monthly, against a minimum deposit. What was earned before April 13 is genuinely owed and should be paid. What was never provided, in pools that no longer exist, was never earned by anyone, and by the proposal’s own terms it goes back.

So the community does not need to do anything heavy here. Honor 1439 as written, and let Hyperbridge cover the loss it caused, which it has already committed to do in BRIDGE.

And if the two proponents choose not to honor that commitment, the community is not obliged to keep extending them goodwill. It would be reasonable, and healthy, for voters to hold any further requests from these teams until the 1439 commitment is met. Not as punishment, simply as the natural consequence of a promise to the DAO being left unkept. That kind of accountability is overdue in web3, and it costs the community nothing.