While cryptocurrency hacks are commonplace, instances where attackers take significant risks only to gain minimal rewards are rare. One such unusual case occurred on Sunday, when an attacker leveraged a vulnerability in the Hyperbridge cross-chain gateway to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, only to sell them for approximately $237,000 worth of ether. This exploit highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million drain on Solana's Drift Protocol last month.
The targeted bridge contract, rather than Polkadot's core network, was the weak point, with the native DOT token remaining unaffected. The vulnerability stemmed from the validation process of incoming cross-chain messages in Hyperbridge's EthereumHost contract, which, when bypassed, granted the attacker unlimited minting capabilities. Bridges, designed to facilitate the transfer of coins between blockchains, remain a critical vulnerability in cross-chain architecture due to their admin-level control over token contracts.
The attack unfolded when the attacker submitted a forged message that was incorrectly validated and processed as legitimate, resulting in the transfer of admin rights to the attacker's address. With this control, the attacker minted 1 billion tokens and sold them through Odos Router V3 and Uniswap V4, extracting roughly 108.2 ETH. However, the limited liquidity of the bridged DOT pool on Ethereum significantly capped the attacker's profits, as the overwhelming supply of 1 billion tokens led to a fraction of a cent per token.
This exploit was flagged by CertiK, confirming the attack vector and the attacker's profit of approximately $237,000. Hyperbridge has yet to comment publicly on the exploit or disclose whether other bridged token contracts are vulnerable to similar attacks.