While cryptocurrency hacks are not unusual, it is rare for attackers to take significant risks and end up with relatively modest gains. Such a scenario occurred on Sunday when an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway, which connects different blockchain networks, resulting in the minting of 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network.
The attacker then sold these tokens for approximately $237,000 worth of ether. This incident highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million exploit on Solana's Drift Protocol last month.
The vulnerability in this case was found in the Hyperbridge EthereumHost contract's validation process for incoming cross-chain messages. Bridges, which facilitate the transfer of coins between blockchain networks, are often the weakest link in cross-chain architecture due to their administrative control over token contracts on destination chains.
The attack did not affect Polkadot's core network or its native DOT token. The exploit involved the submission of a forged message via dispatchIncoming, which was processed as legitimate due to a validation failure. This allowed the attacker to gain administrative rights over the bridged Polkadot token contract, mint 1 billion tokens, and sell them on Uniswap, resulting in roughly 108.2 ETH.
However, the limited liquidity of the bridged DOT pool on Ethereum restricted the attacker's profit. The incident was flagged by CertiK, confirming the attack vector and the attacker's profit of approximately $237,000.
Hyperbridge has not publicly commented on the exploit or disclosed whether other bridged token contracts using the same gateway are vulnerable to similar attacks.