While cryptocurrency hacks are not uncommon, instances where attackers take significant risks only to gain relatively modest sums are rare. Such a scenario unfolded recently when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway, connecting various blockchains, and minted 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, only to sell them for around $237,000 worth of ether.
This exploit highlights the growing list of vulnerabilities in bridge technologies in 2026, following a $270 million loss in the Drift Protocol on Solana and a social engineering attack that compromised infrastructure. The attack targeted the bridge contract rather than Polkadot's core network, leaving the native DOT token unaffected. The vulnerability lay in the validation process of incoming cross-chain messages by Hyperbridge's EthereumHost contract before they were passed to the TokenGateway.
Bridges, facilitating the movement of coins between blockchains, remain the weakest link due to their admin-level control over token contracts, making a single validation failure potentially catastrophic. The attack involved submitting a forged message that bypassed validation checks, granting the attacker admin rights over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through Odos Router V3 into a Uniswap V4 DOT-ETH pool, extracting approximately 108.2 ETH. However, the attacker's gains were limited by the weak liquidity in the bridged DOT pool on Ethereum, which was overwhelmed by the 1 billion tokens, resulting in the attacker receiving only a fraction of a cent per token.
This low liquidity worked against the attacker, capping their profit. The vulnerability was flagged by CertiK, confirming the attack vector and the attacker's profit of approximately $237,000.
Hyperbridge has not publicly addressed the exploit or disclosed whether other bridged token contracts are vulnerable to similar attacks.