Cryptocurrency hacks have become increasingly common, but instances where attackers take significant risks only to reap modest rewards are rare. Such a scenario unfolded recently, as an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network. However, the attacker only managed to sell these tokens for approximately $237,000 worth of ether. This exploit highlights the growing list of bridge vulnerabilities in 2026, including a $270 million Drift Protocol incident on Solana last month.
The vulnerability in question was found in the Hyperbridge EthereumHost contract, specifically in its validation process for incoming cross-chain messages. Bridges, which facilitate the transfer of coins between different blockchains, are often the weakest link in cross-chain architecture due to their admin-level control over token contracts. This exploit targeted the bridge contract, not Polkadot's core network, and did not affect the native DOT token.
The attacker submitted a forged message, which was routed to TokenGateway.onAccept and processed as legitimate due to a missing or circumventable proof validation. This allowed the attacker to gain admin rights over the bridged Polkadot token contract, mint 1 billion tokens, and sell them on Uniswap V4. However, the limited liquidity in the DOT-ETH pool meant that the attacker only received a fraction of a cent per token, capping their profit. The exploit was flagged by CertiK, which confirmed the attack vector and estimated the attacker's profit at $237,000.
Hyperbridge has yet to comment on the incident or disclose whether other bridged token contracts are vulnerable to similar attacks.