While cryptocurrency hacks are not uncommon, instances where attackers take significant risks only to gain minimal rewards are rare. Such a scenario unfolded recently.

An attacker leveraged a vulnerability in a cross-chain gateway, minting 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network, and subsequently sold them for approximately $237,000 in ether. This exploit highlights the growing concern of bridge vulnerabilities in 2026, following a $270 million loss on Solana last month. The attack targeted the bridge contract, not Polkadot's core network, with the native DOT token remaining unaffected. The vulnerability was found in the validation process of incoming cross-chain messages.

Bridges, facilitating the movement of coins between blockchains, are often the weakest link due to their administrative control over token contracts. The attack began with the submission of a forged message, which, due to a validation failure, was processed as legitimate.

This granted the attacker administrative rights, allowing them to mint 1 billion tokens and sell them through a Uniswap pool, resulting in roughly 108.2 ETH. However, the attacker's gain was limited by the weak liquidity of the market, which could not absorb the large volume of tokens without significantly affecting the price. The attacker's profit was thus capped at a fraction of the potential value.

The exploit was flagged by CertiK, confirming the attack vector and the attacker's profit. The incident underscores the importance of robust security measures in cross-chain bridges to prevent such vulnerabilities.