While crypto hacks are becoming increasingly common, instances where attackers take significant risks only to walk away with minimal gains are rare. One such incident occurred on Sunday, where an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway, resulting in the minting of 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network.
The attacker then sold these tokens for approximately $237,000 worth of ether. This exploit highlights the growing list of vulnerabilities in bridge protocols, following a $270 million drain on Solana's Drift Protocol last month. The Sunday attack targeted the bridge contract, rather than Polkadot's core network, and was made possible by a flaw in the validation process of incoming cross-chain messages.
Bridges, which facilitate the transfer of coins between different blockchains, are often the weakest link in cross-chain architecture due to their admin-level control over token contracts on destination chains. The attack unfolded when the attacker submitted a forged message, which was not properly validated, granting them admin rights to the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through a Uniswap V4 DOT-ETH pool, extracting around 108.2 ETH. However, the limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, capping their profit.
If the same vulnerability were to be exploited on a deeper pool or a higher-value bridged asset, the losses would have been significantly greater. The exploit was flagged by CertiK, confirming the attack vector and the attacker's profit of approximately $237,000. Hyperbridge has yet to publicly comment on the incident or disclose whether other bridged token contracts using the same gateway are vulnerable to the same attack vector.