In a surprising turn of events, a recent crypto hack resulted in a relatively small payout for the attacker. On Sunday, an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway, successfully minting 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network.

However, the attacker only managed to sell these tokens for approximately $237,000 worth of ether. This incident highlights the growing concern of bridge vulnerabilities in 2026, following a $270 million Drift Protocol exploit on Solana last month. The attack on Hyperbridge's cross-chain gateway did not affect Polkadot's core network or its native token, DOT. The exploit took advantage of a weakness in the EthereumHost contract's validation process for incoming cross-chain messages, which are used to facilitate the transfer of tokens between different blockchain networks.

The vulnerability allowed the attacker to submit a forged message, which was then processed as legitimate by the TokenGateway, granting the attacker admin control over the bridged Polkadot token contract. Once in control, the attacker minted 1 billion tokens and sold them on Uniswap, but the limited liquidity in the market meant that the attacker received a significantly lower price per token than expected.

This lack of liquidity ultimately limited the attacker's profit to $237,000. The incident was flagged by CertiK, which confirmed that the attack vector was indeed the Hyperbridge gateway contract. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts using the same gateway are vulnerable to similar attacks. The attack has raised concerns about the security of cross-chain architecture, particularly the bridges that facilitate the transfer of tokens between different blockchain networks.

These bridges often hold admin-level control over token contracts on destination chains, making them a prime target for attackers.