A recent cryptocurrency hack has highlighted the risks associated with cross-chain bridges. On Sunday, an attacker exploited a vulnerability in Hyperbridge's gateway, which connects different blockchains, and minted 1 billion Polkadot tokens on Ethereum. However, due to weak liquidity, the attacker was only able to sell the tokens for approximately $237,000 worth of ether. This incident adds to the growing list of bridge vulnerabilities in 2026, including a $270 million Drift Protocol exploit on Solana.

The attack targeted the bridge contract, not Polkadot's core network, and was made possible by a flaw in how Hyperbridge's EthereumHost contract validates incoming cross-chain messages. The vulnerability allowed the attacker to submit a forged message, which was accepted as legitimate, granting them admin control over the bridged Polkadot token contract. With this control, the attacker was able to mint 1 billion tokens and sell them on a Uniswap V4 DOT-ETH pool.

However, the limited depth of the bridged DOT pool on Ethereum meant that the attacker was only able to extract a fraction of the potential value. The incident highlights the importance of robust security measures for cross-chain bridges, which can be vulnerable to exploits due to their admin-level control over token contracts on destination chains. CertiK has confirmed the attack vector and estimated the attacker's profit at approximately $237,000.