While cryptocurrency hacks are becoming increasingly common, instances where attackers take substantial risks only to gain minimal rewards are rare. Such an unusual case occurred on a recent Sunday, where an attacker managed to exploit a weakness in the cross-chain gateway operated by Hyperbridge, which interconnects various blockchain networks. The attacker successfully minted 1 billion Polkadot tokens, valued at approximately $1.19 billion, and then sold them on the Ethereum network for roughly $237,000 worth of ether. This exploit highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million loss on the Drift Protocol in Solana last month.

The attack targeted the bridge contract specifically and did not affect Polkadot's core network or its native DOT token. The vulnerability was found in the way Hyperbridge's EthereumHost contract validates cross-chain messages before they are processed by the TokenGateway.

Bridges, which facilitate the transfer of coins between different blockchain networks, are often the weakest link due to their administrative control over token contracts, making them susceptible to significant exploits if validation fails. The attack began with the submission of a forged message that bypassed validation checks, allowing the attacker to gain administrative rights over the bridged Polkadot token contract. With these rights, the attacker minted 1 billion tokens and sold them through a Uniswap pool, but due to low liquidity, the attacker only managed to extract about 108.2 ETH. The limited market depth worked against the attacker, capping their potential profit.

The exploit was flagged by CertiK, confirming that the attack vector was through the Hyperbridge gateway contract, resulting in the attacker profiting around $237,000. Hyperbridge has yet to comment on the exploit or whether other token contracts using the same gateway are vulnerable to similar attacks.