While cryptocurrency hacks are commonplace, instances where attackers take substantial risks only to gain minimal rewards are rare. Such a scenario unfolded on Sunday when an attacker exploited a weakness in the Hyperbridge cross-chain gateway.

This gateway connects various blockchains, enabling the attacker to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network. However, the attacker only managed to sell these tokens for about $237,000 worth of ether. The exploit highlights the growing list of vulnerabilities in bridge protocols, which are crucial for transferring coins between different blockchains. The attack did not compromise Polkadot's core network or its native DOT token.

Instead, it targeted the bridge contract, specifically the EthereumHost contract's validation process for incoming cross-chain messages. The vulnerability allowed the attacker to submit a forged message, which was then processed as legitimate, granting them administrative control over the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them through Odos Router V3 into a Uniswap V4 DOT-ETH pool, resulting in approximately 108.2 ETH. The limited liquidity in the bridged DOT pool on Ethereum worked against the attacker, significantly reducing their potential profit.

If the same vulnerability were exploited on a deeper pool or a higher-value bridged asset, the losses would have been substantially greater. As of Monday morning, DOT was trading just below $1.20.

The exploit was flagged by CertiK, confirming the attack vector and the attacker's approximate profit of $237,000. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts using the same gateway are vulnerable to similar attacks.