While cryptocurrency hacks are common, instances where attackers take significant risks only to gain minimal rewards are rare. Such a scenario occurred on Sunday when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway.
The attacker successfully minted 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, but only managed to sell them for approximately $237,000 worth of ether. This exploit highlights the growing list of bridge vulnerabilities in 2026, including the recent $270 million Drift Protocol incident on Solana.
The attack targeted the bridge contract, not Polkadot's core network, and the native DOT token remained unaffected. The vulnerability was found in the Hyperbridge EthereumHost contract's validation process for incoming cross-chain messages.
Bridges, which facilitate the transfer of coins between blockchains, are often the weakest link in cross-chain architecture due to their admin-level control over token contracts. The attack unfolded when the attacker submitted a forged message, which was accepted as legitimate due to a validation failure.
The attacker then gained administrative rights to the bridged Polkadot token contract, minted 1 billion tokens, and sold them through Odos Router V3 and Uniswap V4, resulting in roughly 108.2 ETH. However, the limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, capping their profit. The incident was flagged by CertiK, which confirmed the attack vector and estimated the attacker's profit at approximately $237,000. Hyperbridge has yet to comment on the exploit or disclose whether other bridged token contracts are vulnerable to the same attack.