Cryptocurrency hacks are a common occurrence, but instances where attackers take significant risks only to reap minimal rewards are rare. Such a scenario unfolded on Sunday when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway.
The attacker successfully minted 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network and subsequently sold them for approximately $237,000 in ether. This incident highlights the growing list of vulnerabilities in bridge protocols, following a $270 million exploit on Solana's Drift Protocol last month. The recent attack targeted the bridge contract rather than Polkadot's core network, leaving the native DOT token unaffected. The weakness lay in the validation process of incoming cross-chain messages by Hyperbridge's EthereumHost contract, which, when compromised, can grant an attacker control over token contracts on destination chains.
Bridges remain a weak point in cross-chain architecture due to their admin-level control over token contracts, making a single validation failure potentially catastrophic. The attack began with the submission of a forged message that bypassed validation checks, allowing the attacker to gain admin rights over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through a Uniswap pool, extracting about 108.2 ETH.
However, the limited liquidity of the DOT-ETH pool worked against the attacker, significantly reducing the potential profit. The exploit was flagged by CertiK, which confirmed the attack vector and the attacker's profit of approximately $237,000.
Hyperbridge has yet to comment publicly on the exploit or its implications for other bridged token contracts using the same gateway.