Cryptocurrency hacks have become commonplace, but it's rare for attackers to take significant risks and walk away with relatively little to show for it. However, that's exactly what happened on Sunday when an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway, which connects different blockchains. The attacker was able to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network and then sell them for approximately $237,000 worth of ether.

This exploit highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million Drift Protocol drain on Solana last month. The attack targeted the bridge contract, rather than Polkadot's core network, and the native token DOT was not affected. The vulnerability lay in how Hyperbridge's EthereumHost contract validated incoming cross-chain messages before passing them to the TokenGateway.

Bridges, which facilitate the movement of coins between blockchains, remain a weak point in cross-chain architecture due to their admin-level control over token contracts on destination chains. A single validation failure can grant an attacker the ability to mint an unlimited supply of tokens. The attack unfolded when the attacker submitted a forged message via dispatchIncoming, which was routed to TokenGateway.onAccept.

The request receipts check, which should have verified the message against a valid cross-chain state commitment from Polkadot, stored an all-zeros commitment value, indicating that the proof validation was either absent or circumventable. As a result, the gateway processed the message as legitimate, allowing the attacker to execute changeAdmin on the bridged Polkadot token contract and transfer admin rights to their address. With admin control, the attacker was able to mint 1 billion tokens in a single transaction and sell them through Odos Router V3 into a Uniswap V4 DOT-ETH pool, extracting approximately 108.2 ETH.

However, the limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, capping their profit. The pool's limited depth meant that the 1 billion tokens overwhelmed the available liquidity, resulting in the attacker receiving only a fraction of a cent per token. If the vulnerability had been exploited on a deeper pool or a higher-value bridged asset, the losses would have been significantly larger.

As of Monday morning, DOT was trading at just under $1.20. CertiK flagged the exploit, confirming that the attack vector was the Hyperbridge gateway contract and that the attacker profited approximately $237,000 from minting and selling the bridged tokens.

Hyperbridge has not publicly commented on the exploit or disclosed whether other bridged token contracts using the same gateway are vulnerable to the same forged-message attack vector.