While cryptocurrency hacks are not uncommon, instances where attackers take significant risks only to reap minimal rewards are rare. Such a scenario unfolded recently when an attacker exploited a weakness in a cross-chain gateway, minting 1 billion Polkadot tokens on the Ethereum network, valued at $1.19 billion, and selling them for approximately $237,000 in ether.
This incident highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million exploit on Solana's Drift Protocol last month. The attack targeted the bridge contract, specifically the validation process for incoming cross-chain messages, rather than Polkadot's core network, and the native DOT token remained unaffected. The vulnerability in the Hyperbridge EthereumHost contract allowed the attacker to submit a forged message, which was then processed as legitimate, granting them admin control over the bridged Polkadot token contract.
The attacker subsequently minted 1 billion tokens and sold them on Uniswap, but limited liquidity restricted their profit. The incident was flagged by CertiK, confirming the attack vector and estimated profit of $237,000. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts are vulnerable to similar attacks.