While cryptocurrency hacks are not uncommon, it is rare for attackers to take significant risks only to end up with relatively modest gains. Such a scenario unfolded on a recent Sunday. An attacker exploited a vulnerability in a cross-chain gateway, creating 1 billion Polkadot tokens on the Ethereum network, valued at $1.19 billion, but only managed to sell them for approximately $237,000 in ether. This incident highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million loss on Solana's Drift Protocol the previous month.

The exploit targeted a bridge contract rather than Polkadot's core network, and the native DOT token remained unaffected. The weakness lay in the validation process for cross-chain messages within the Hyperbridge EthereumHost contract. Bridges, which facilitate the transfer of coins between different blockchains, are often the most vulnerable part of cross-chain architecture due to their administrative control over token contracts on destination chains.

A single validation failure can potentially allow an attacker to mint an unlimited supply of tokens. The attack began with the submission of a forged cross-chain message, which was not properly validated against a legitimate cross-chain state commitment from Polkadot.

As a result, the message was processed as legitimate, granting the attacker administrative rights over the bridged Polkadot token contract. The attacker then minted 1 billion tokens and sold them through a Uniswap pool, but due to weak liquidity, the attacker only received a fraction of a cent per token.

If the same vulnerability were exploited on a more valuable asset or a deeper pool, the potential losses could have been significantly higher. The DOT token was trading just below $1.20 at the time of the incident. The security firm CertiK identified the exploit, confirming that the attacker profited around $237,000 from the sale of the minted tokens. Hyperbridge has yet to comment publicly on the incident or disclose whether other token contracts using the same gateway are vulnerable to similar attacks.