Cryptocurrency hacks have become commonplace, but instances where attackers take significant risks only to walk away with relatively small sums are rare. Such a scenario unfolded on Sunday when an attacker exploited a weakness in a cross-chain gateway, minting 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, only to sell them for approximately $237,000 worth of ether.

This incident highlights the ongoing issue of bridge vulnerabilities, following a $270 million exploit on Solana's Drift Protocol last month. The attack targeted the bridge contract, specifically the validation process for incoming cross-chain messages, rather than Polkadot's core network, leaving the native DOT token unaffected. Bridges, which facilitate the transfer of coins between blockchains, remain a weak point due to their admin-level control over token contracts, making them susceptible to validation failures that can grant attackers unlimited minting capabilities.

The exploit was made possible by a forged message that bypassed state proof validation, allowing the attacker to gain admin rights and mint a large number of tokens. However, the limited liquidity in the market restricted the attacker's ability to profit, as the sale of 1 billion tokens overwhelmed the available liquidity, resulting in a significantly lower price per token. The attack was flagged by CertiK, which confirmed the exploit vector and the attacker's profit of approximately $237,000. The incident underscores the importance of robust security measures for cross-chain bridges to prevent such vulnerabilities.