While cryptocurrency hacks are not uncommon, instances where attackers take substantial risks only to gain minimal profits are rare. Such a scenario occurred on Sunday when an attacker exploited a weakness in the Hyperbridge cross-chain gateway, resulting in the minting of 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network. However, the attacker only managed to sell these tokens for approximately $237,000 worth of ether. This incident highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million exploit on Solana's Drift Protocol last month.
The attack targeted the bridge contract, specifically the EthereumHost contract's validation process for incoming cross-chain messages, rather than Polkadot's core network, leaving the native DOT token unaffected. The vulnerability allowed the attacker to submit a forged message, which was accepted as legitimate, granting them admin rights over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through a Uniswap pool, but due to weak liquidity, the sale yielded significantly less than expected.
The exploit was flagged by CertiK, confirming the attack vector and the attacker's profit of approximately $237,000. Hyperbridge has yet to comment on the incident or disclose whether other token contracts using the same gateway are vulnerable to similar attacks.