Cryptocurrency hacks have become commonplace, but instances where attackers take significant risks only to gain minimal rewards are rare. One such incident occurred on Sunday, where an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway, connecting various blockchains, to mint 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, and subsequently sold them for approximately $237,000 in ether.

This exploit highlights the growing list of vulnerabilities in bridge protocols, following a $270 million Drift Protocol incident on Solana last month. The targeted bridge contract, rather than Polkadot's core network, contained the vulnerability, which lay in the validation process of incoming cross-chain messages.

Bridges, facilitating coin transfers between blockchains, remain a weak point in cross-chain architecture due to their administrative control over token contracts on destination chains. A single validation failure can grant an attacker unlimited token minting capabilities. The attack unfolded with the submission of a forged message, which bypassed validation checks and granted the attacker admin rights to the bridged Polkadot token contract. The attacker then minted 1 billion tokens and sold them through a Uniswap V4 pool, but low liquidity limited the profit to roughly 108.2 ETH.

The limited depth of the bridged DOT pool on Ethereum meant the attacker received only a fraction of a cent per token. CertiK identified the exploit, confirming the attack vector and approximate profit of $237,000. Hyperbridge has yet to comment on the incident or disclose potential vulnerabilities in other bridged token contracts using the same gateway.