Cryptocurrency hacks are a common occurrence, but it's rare for attackers to take significant risks and end up with minimal gains. However, this unusual scenario played out recently. An attacker exploited a weakness in Hyperbridge's cross-chain gateway, which connects different blockchains, and minted 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network.

The attacker then sold these tokens for approximately $237,000 worth of ether. This incident highlights the growing list of vulnerabilities in bridge protocols, including a recent $270 million exploit on Solana.

The attack targeted the bridge contract, not the core Polkadot network, and the native DOT token remained unaffected. The vulnerability was found in the EthereumHost contract's validation process for incoming cross-chain messages. Bridges are often the weakest link in cross-chain architecture, as they hold admin-level control over token contracts on destination chains.

A single validation failure can grant an attacker unlimited control. The attack unfolded when the hacker submitted a forged message, which was routed to TokenGateway.onAccept.

The request receipts check failed to verify the message against a valid cross-chain state commitment from Polkadot, allowing the gateway to process the message as legitimate. The accepted message transferred admin rights to the attacker's address, enabling them to mint 1 billion tokens and sell them through a Uniswap V4 DOT-ETH pool, extracting around 108.2 ETH.

The limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, capping their profit. If the same vulnerability were exploited on a deeper pool or a higher-value bridged asset, the losses would have been significantly larger.

The incident was flagged by CertiK, which confirmed the attack vector and the attacker's profit of approximately $237,000. Hyperbridge has not publicly commented on the exploit or disclosed whether other bridged token contracts using the same gateway are vulnerable to the same attack vector.