Cryptocurrency hacks are not unusual, but instances where attackers take substantial risks only to gain minimal rewards are rare. Such an incident occurred on Sunday, when an attacker exploited a vulnerability in a cross-chain gateway, minting 1 billion Polkadot tokens on Ethereum and selling them for approximately $237,000 in ether.
This exploit highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million loss on Solana last month. The attack targeted the bridge contract, not Polkadot's core network, and was made possible by a flaw in how the Hyperbridge's EthereumHost contract verifies incoming cross-chain messages. As a result, the attacker was able to submit a forged message, gaining admin control over the bridged token contract and minting 1 billion tokens.
However, due to weak market liquidity, the attacker was only able to extract a fraction of the potential value, receiving roughly 108.2 ETH. The incident underscores the importance of robust security measures in cross-chain architecture, as bridges remain a vulnerable point due to their admin-level control over token contracts. The attack was flagged by CertiK, which confirmed the exploit and the attacker's profit of approximately $237,000.