While cryptocurrency hacks are not uncommon, instances where attackers take significant risks and end up with relatively small gains are rare. Such a scenario unfolded on Sunday, as an attacker exploited a vulnerability in a cross-chain gateway, creating 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, and then selling them for roughly $237,000 in ether. This incident highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million loss on Solana's Drift Protocol last month.
The attack targeted the bridge contract, rather than Polkadot's core network, and was made possible by a flaw in the validation process for incoming cross-chain messages. The weakness of bridges, which facilitate the transfer of coins between different blockchains, stems from their administrative control over token contracts on destination chains, making them a prime target for attackers.
In this case, the attacker submitted a forged message that bypassed validation checks, granting them administrative rights over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them on a Uniswap pool, but the limited liquidity of the market meant that the attacker's profits were capped at around $237,000. The incident was flagged by CertiK, which confirmed that the attacker profited by approximately $237,000 from the exploit.
Hyperbridge has yet to publicly comment on the incident or disclose whether other bridged token contracts are vulnerable to the same attack vector.