While cryptocurrency hacks are commonplace, instances where attackers take substantial risks and end up with relatively meager gains are rare. Such a scenario unfolded on Sunday when an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway, which connects multiple blockchains, to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, and then sold them for approximately $237,000 in ether. This exploit highlights the growing list of vulnerabilities in bridge protocols, following a $270 million drain on Solana's Drift Protocol last month and a social engineering attack that compromised infrastructure.
The attack targeted the bridge contract, not Polkadot's core network, and the native DOT token remained unaffected. The vulnerability lay in the validation process of incoming cross-chain messages by Hyperbridge's EthereumHost contract before passing them to the TokenGateway. Bridges, designed to facilitate the transfer of coins between blockchains, are often the weakest link in cross-chain architecture due to their admin-level control over token contracts on destination chains, making them susceptible to attacks that can grant unlimited supply control with a single validation failure.
The attack began with the submission of a forged message via dispatchIncoming, which was then routed to TokenGateway.onAccept. However, the request receipts check failed to verify the message against a valid cross-chain state commitment from Polkadot, instead storing an all-zeros commitment value, indicating either a lack of or circumvention of proof validation for this specific call path.
The message was processed as legitimate, leading to the execution of changeAdmin on the bridged Polkadot token contract, thereby transferring admin rights to the attacker's address. With admin control, the attacker minted 1 billion tokens in a single transaction and routed them through Odos Router V3 into a Uniswap V4 DOT-ETH pool, ultimately extracting around 108.2 ETH across multiple swaps at slightly different prices.
The limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, capping their profit. Normally, weak liquidity is a significant issue for large traders, but in this case, it prevented the attacker from realizing the full potential of their exploit.
The bridged DOT pool's limited depth meant that the 1 billion tokens overwhelmed the available liquidity, resulting in the attacker receiving only a fraction of a cent per token. On a deeper pool or with a higher-value bridged asset, the same vulnerability could have led to substantially larger losses. As of Monday morning, DOT was trading just under $1.20. The exploit was flagged by CertiK, which confirmed the attack vector as the Hyperbridge gateway contract and estimated the attacker's profit from minting and selling the bridged tokens to be approximately $237,000.
Hyperbridge has not publicly commented on the exploit or disclosed whether other bridged token contracts using the same gateway are vulnerable to similar forged-message attacks.