Cryptocurrency hacks have become all too familiar, but instances where attackers take substantial risks only to reap minimal rewards are rare. Such an unusual scenario unfolded on Sunday when an attacker exploited a weakness in Hyperbridge's cross-chain gateway, which connects various blockchains, and minted 1 billion Polkadot tokens valued at $1.19 billion on the Ethereum network, only to sell them for approximately $237,000 in ether. This incident highlights the growing list of vulnerabilities in bridge protocols, following a $270 million exploit on Solana's Drift Protocol last month. The attack targeted Hyperbridge's EthereumHost contract, specifically the validation process for incoming cross-chain messages, rather than Polkadot's core network, leaving the native DOT token unaffected.

The flaw allowed the attacker to submit a forged message, which, after being processed as legitimate, granted them administrative control over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through Odos Router V3 on Uniswap V4, but the limited liquidity in the DOT-ETH pool capped their profit. The attack's success was contingent on the weakness in the bridge's validation process, which typically verifies messages against a valid cross-chain state commitment.

In this case, the commitment value was either absent or circumventable, allowing the forged message to be accepted. The incident underscores the vulnerability of bridges, which, due to their role in moving coins between blockchains and holding administrative control over token contracts, can grant an attacker unlimited minting capabilities with a single validation failure. The specifics of the attack involved the attacker executing a changeAdmin function on the bridged Polkadot token contract, transferring administrative rights to their address, and then minting and selling the tokens.

The market's limited ability to absorb the large volume of tokens at stable prices worked against the attacker, significantly reducing their potential profit. This exploit was flagged by CertiK, confirming the attack vector and the attacker's profit. Hyperbridge has yet to comment publicly on the exploit or disclose whether other token contracts using the same gateway are vulnerable to similar attacks.