Cryptocurrency hacks have become commonplace, but instances where attackers take significant risks only to gain minimal rewards are rare. Such a scenario unfolded recently. An attacker exploited a weakness in Hyperbridge's cross-chain bridge, minting 1 billion Polkadot tokens on the Ethereum network, valued at $1.19 billion, and selling them for approximately $237,000 in ether. This incident adds to the growing list of vulnerabilities in bridge protocols, following a $270 million exploit on Solana's Drift Protocol last month.

The attack targeted the bridge contract, specifically the EthereumHost contract's validation process for incoming cross-chain messages. The vulnerability enabled the attacker to submit a forged message, which was then processed as legitimate, granting them admin control over the bridged DOT token contract. The attacker then minted 1 billion tokens and sold them on Uniswap, but due to weak liquidity, they only managed to extract around 108.2 ETH.

The limited depth of the DOT-ETH pool on Ethereum meant the attacker received a fraction of a cent per token, capping their profit. The security firm CertiK identified the exploit and confirmed the attacker's profit was approximately $237,000. Hyperbridge has yet to comment on the incident or disclose whether other token contracts using the same gateway are vulnerable to similar attacks.