Cryptocurrency hacks have become relatively common, but instances where attackers take significant risks only to gain minimal rewards are rare. One such incident occurred recently.
An attacker discovered a vulnerability in a cross-chain gateway, enabling them to mint 1 billion Polkadot tokens on Ethereum and sell them for approximately $237,000 in ether. This exploit highlights the growing list of vulnerabilities in bridge protocols, following a $270 million incident on Solana last month.
The recent attack targeted the bridge contract and not Polkadot's core network, leaving the native DOT token unaffected. The vulnerability was found in the validation process of incoming cross-chain messages. Bridges, which facilitate the transfer of coins between blockchains, are often the weakest link due to their administrative control over token contracts.
A single validation failure can grant an attacker unlimited minting capabilities. The attack involved submitting a forged message, which was mistakenly processed as legitimate, allowing the attacker to gain administrative rights and mint 1 billion tokens.
These tokens were then sold through a Uniswap pool, resulting in roughly 108.2 ETH. However, due to weak liquidity, the attacker's profits were capped.
The bridged DOT pool had limited depth, causing the 1 billion tokens to overwhelm the available liquidity and resulting in a fraction of a cent per token. The same vulnerability could have led to significantly larger losses if the pool had more depth or the asset had a higher value. The incident was flagged by CertiK, confirming the attack vector and approximate profit of $237,000. Hyperbridge has not publicly commented on the exploit or disclosed whether other token contracts are vulnerable to the same attack.