A recent cryptocurrency hack has highlighted the risks associated with cross-chain bridges, where an attacker exploited a vulnerability in the Hyperbridge gateway to mint 1 billion Polkadot tokens on Ethereum. Despite the massive token creation, the attacker only managed to steal approximately $237,000 worth of ether due to low liquidity in the market. This incident is the latest in a series of bridge-related vulnerabilities, including a $270 million Drift Protocol exploit on Solana last month. The attack targeted the bridge contract, rather than Polkadot's core network, and was made possible by a flaw in the validation process for cross-chain messages.
The vulnerability allowed the attacker to submit a forged message, which granted them admin control over the bridged DOT token and enabled them to mint the tokens. The attacker then sold the tokens on Uniswap, but the limited liquidity in the market meant they received a fraction of their potential value.
The incident has highlighted the importance of robust security measures for cross-chain bridges, which are often the weakest link in cryptocurrency architecture. CertiK has confirmed the attack vector and estimated the attacker's profit at around $237,000. Hyperbridge has yet to comment on the exploit or disclose whether other bridged token contracts are vulnerable to similar attacks.