Cryptocurrency hacks have become commonplace, but instances where attackers assume significant risk only to reap relatively minor rewards are rare. Such a scenario unfolded on a recent Sunday, when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway, successfully minting 1 billion Polkadot tokens on the Ethereum network, valued at $1.19 billion, and subsequently selling them for approximately $237,000 in ether. This incident highlights the ongoing issue of bridge vulnerabilities, following a $270 million exploit of the Drift Protocol on Solana last month, as well as a social engineering attack that compromised infrastructure. The Sunday attack targeted the bridge contract, bypassing state proof validation and granting the attacker administrative control over the bridged DOT token contract.
However, due to limited liquidity in the market, the attacker was unable to capitalize fully on the exploit, ultimately netting a significantly lower amount than the token's theoretical value. The vulnerability has been confirmed by CertiK, with Hyperbridge yet to comment publicly on the incident or disclose potential vulnerabilities in other bridged token contracts using the same gateway.