Cryptocurrency hacks are becoming increasingly common, but instances where attackers take significant risks only to gain minimal rewards are rare. Such an incident occurred on Sunday, where an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway to mint 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, and then sold them for approximately $237,000 worth of ether. This exploit highlights the growing number of bridge vulnerabilities in 2026, including a recent $270 million Drift Protocol incident on Solana. The attack targeted Hyperbridge's EthereumHost contract, which is responsible for validating incoming cross-chain messages before passing them to the TokenGateway.

However, the vulnerability allowed the attacker to submit a forged message, which was accepted as legitimate, granting them admin control over the bridged Polkadot token contract. The attacker then minted 1 billion tokens and sold them on Uniswap, but the low liquidity of the DOT-ETH pool limited their profits. The incident underscores the weaknesses in cross-chain architecture, particularly in bridges, which can provide attackers with admin-level control over token contracts. In this case, the attacker's gains were capped due to the limited depth of the bridged DOT pool on Ethereum, resulting in a significantly lower profit than expected.

As of Monday, DOT was trading at just under $1.20, and CertiK has confirmed the attack vector and the attacker's approximate profit of $237,000.