While cryptocurrency hacks are not uncommon, instances where attackers take substantial risks only to gain minimal rewards are rare. Such a scenario occurred on Sunday when an attacker exploited a vulnerability in a cross-chain gateway, minting 1 billion Polkadot tokens on the Ethereum network, valued at $1.19 billion, but only managing to sell them for approximately $237,000 worth of ether. This incident highlights the ongoing issue of bridge vulnerabilities, following a $270 million exploit on Solana's Drift Protocol last month.

The attack targeted the bridge contract, specifically the validation process for incoming cross-chain messages, rather than Polkadot's core network, and the native DOT token remained unaffected. The exploit underscores the weaknesses in cross-chain architecture, particularly in bridges that hold administrative control over token contracts on destination chains, making them vulnerable to validation failures that can grant attackers unlimited minting capabilities. The attack unfolded when the perpetrator submitted a forged message that bypassed the validation check, allowing them to gain administrative rights over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through a Uniswap pool, but the limited liquidity in the market capped their profits.

The lack of depth in the bridged DOT pool on Ethereum meant that the attacker could only sell the tokens for a fraction of their value, resulting in significantly lower gains than would have been possible with a more liquid market or a higher-value asset. The incident was flagged by CertiK, which confirmed the attack vector and the attacker's profits. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts using the same gateway are vulnerable to similar attacks.