While cryptocurrency hacks are commonplace, instances where attackers take significant risks only to gain minimal rewards are rare. Such a scenario unfolded recently. An attacker discovered a vulnerability in Hyperbridge's cross-chain gateway, which connects multiple blockchains, and used it to mint 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, and then sold them for around $237,000 in ether. This exploit highlights the growing list of vulnerabilities in bridge protocols, including the recent $270 million Drift Protocol incident on Solana.

The attack targeted Hyperbridge's EthereumHost contract, specifically the validation process for incoming cross-chain messages. Since bridges hold administrative control over token contracts on destination chains, a single validation failure can grant an attacker unlimited token minting capabilities. The attack began when the attacker submitted a forged message that bypassed validation checks, allowing them to gain administrative control over the bridged Polkadot token contract. With this control, they minted 1 billion tokens and sold them through a Uniswap pool, resulting in approximately 108.2 ETH.

However, due to the limited liquidity in the bridged DOT pool on Ethereum, the attacker's profits were significantly capped. If the same vulnerability had been exploited on a more liquid pool or a higher-value asset, the losses would have been substantially greater. The incident was flagged by CertiK, which confirmed the attack vector and estimated the attacker's profit at around $237,000. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts using the same gateway are vulnerable to similar attacks.