Cryptocurrency hacks have become all too familiar, but it's rare for attackers to take huge risks and end up with relatively little to show for it. This unusual scenario unfolded on Sunday when an attacker exploited a weakness in the Hyperbridge cross-chain gateway, which connects various blockchains, to mint 1 billion Polkadot tokens on Ethereum.
The attacker then sold these tokens for approximately $237,000 in ether. This incident is the latest in a string of bridge vulnerabilities that have been exposed in 2026, including a $270 million exploit on Solana's Drift Protocol last month. The breach did not affect Polkadot's core network or its native token, DOT, but rather targeted the bridge contract. The vulnerability lay in how the Hyperbridge EthereumHost contract validated incoming cross-chain messages before passing them to the TokenGateway.
Bridges, which facilitate the transfer of coins between different blockchains, are often the weakest link in cross-chain architecture because they hold administrative control over token contracts on destination chains. This means a single validation failure can grant an attacker unlimited supply. The attack began when the attacker submitted a forged message via dispatchIncoming, which was then routed to TokenGateway.onAccept.
However, the request receipts check failed to verify the message against a valid cross-chain state commitment from Polkadot, instead storing an all-zeros commitment value. This suggested that proof validation was either absent or could be circumvented for this specific call path, and the gateway processed the message as legitimate. The accepted message then executed changeAdmin on the bridged Polkadot token contract, transferring administrative rights to the attacker's address.
With administrative control, the attacker minted 1 billion tokens in a single transaction and sold them through Odos Router V3 into a Uniswap V4 DOT-ETH pool, extracting around 108.2 ETH across multiple swaps at slightly different prices. The limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, capping their profit.
The pool's weak depth meant that the 1 billion tokens overwhelmed the available liquidity, resulting in the attacker receiving only a fraction of a cent per token. If the vulnerability had been exploited on a deeper pool or a higher-value bridged asset, the losses could have been significantly larger.
As of Monday morning, DOT was trading just under $1.20. The security firm CertiK flagged the exploit and confirmed that the attack vector was the Hyperbridge gateway contract, with the attacker profiting approximately $237,000 from minting and selling the bridged tokens. Hyperbridge has not publicly commented on the exploit or disclosed whether other bridged token contracts using the same gateway are vulnerable to the same forged-message attack vector.