While cryptocurrency hacks are all too common, it's rare for an attacker to take a significant risk and end up with relatively modest gains. However, that's exactly what happened on Sunday when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway, which connects different blockchains. By doing so, they minted 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, but ultimately only managed to sell them for around $237,000 worth of ether.
This incident highlights the ongoing issue of bridge vulnerabilities, which have been a recurring problem in 2026, including a $270 million Drift Protocol exploit on Solana last month. The attack targeted the bridge contract, rather than Polkadot's core network, and was made possible by a flaw in how the Hyperbridge's EthereumHost contract validated incoming cross-chain messages. Bridges are particularly vulnerable because they hold administrative control over token contracts on destination chains, making them a prime target for attackers.
The exploit began when the attacker submitted a forged message that was routed to the TokenGateway, which failed to verify the message against a valid cross-chain state commitment from Polkadot. As a result, the attacker was able to gain administrative control over the bridged Polkadot token contract and mint 1 billion tokens, which they then sold through a Uniswap V4 DOT-ETH pool, extracting approximately 108.2 ETH. The limited liquidity in the bridged DOT pool worked against the attacker, capping their profits and preventing them from making off with a more substantial sum. If the same vulnerability were to be exploited on a deeper pool or a higher-value bridged asset, the potential losses could be significantly greater.
The incident was flagged by CertiK, which confirmed that the attack vector was the Hyperbridge gateway contract and that the attacker profited approximately $237,000 from the exploit. Hyperbridge has yet to publicly comment on the incident or disclose whether other bridged token contracts using the same gateway are vulnerable to the same attack vector.