While cryptocurrency hacks are common, instances where attackers take significant risks only to gain minimal rewards are rare. Such a scenario unfolded on Sunday when an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway, connecting various blockchains, and minted 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, only to sell them for approximately $237,000 worth of ether.

This exploit highlights the growing list of bridge vulnerabilities in 2026, including a $270 million Drift Protocol drain on Solana last month. The attack targeted Hyperbridge's EthereumHost contract, specifically the validation process for incoming cross-chain messages.

Bridges, facilitating coin movement between blockchains, remain the weakest link due to their admin-level control over token contracts, making a single validation failure potentially catastrophic. The attack began with a forged message submitted via dispatchIncoming and routed to TokenGateway.onAccept, bypassing proof validation and granting the attacker admin rights to the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through Odos Router V3 and Uniswap V4, extracting around 108.2 ETH.

However, the limited liquidity of the bridged DOT pool on Ethereum worked against the attacker, significantly reducing their potential profit. The vulnerability was flagged by CertiK, confirming the attack vector and approximate profit of $237,000. Hyperbridge has not publicly addressed the exploit or its potential impact on other bridged token contracts using the same gateway.