While cryptocurrency hacks are common, instances where attackers take considerable risks only to gain minimal returns are rare. Such a scenario occurred on Sunday, when an attacker exploited a vulnerability in a cross-chain gateway, minting 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, and selling them for roughly $237,000 in ether. This incident adds to the growing list of bridge vulnerabilities in 2026, including a $270 million exploit on Solana's Drift Protocol last month.

The attack targeted the bridge contract and not Polkadot's core network, with the native DOT token remaining unaffected. The vulnerability was found in the validation process of incoming cross-chain messages in the EthereumHost contract. Bridges, which facilitate the transfer of coins between blockchains, are often the weakest link due to their admin-level control over token contracts.

The attack involved submitting a forged message that bypassed validation checks, granting the attacker admin rights and enabling them to mint 1 billion tokens. However, due to weak liquidity, the attacker was only able to extract around 108.2 ETH. The limited depth of the bridged DOT pool on Ethereum meant that the attacker received a fraction of a cent per token, significantly capping their profit.

If the same vulnerability were exploited on a deeper pool or higher-value asset, the losses would have been substantially greater. The exploit was flagged by CertiK, confirming the attack vector and the attacker's profit of approximately $237,000.