Cryptocurrency hacks have become increasingly common, but instances where attackers take substantial risks only to gain minimal rewards are rare. One such unusual incident occurred on Sunday, where an attacker exploited a vulnerability in a cross-chain gateway, creating 1 billion Polkadot tokens on Ethereum, valued at $1.19 billion, but only managed to sell them for approximately $237,000 in ether.
This incident highlights the ongoing issue of bridge vulnerabilities in 2026, following a $270 million drain on Solana's Drift Protocol last month. The exploit targeted the bridge contract, specifically the validation process for cross-chain messages, rather than Polkadot's core network, and the native DOT token remained unaffected.
The vulnerability in the Hyperbridge EthereumHost contract allowed the attacker to submit a forged message, which was then processed as legitimate, granting them administrative control over the bridged token contract. The attacker then minted 1 billion tokens and sold them on Uniswap, but due to limited liquidity, they only received a fraction of a cent per token. The lack of depth in the market worked against the attacker, capping their potential profit. If the same vulnerability were to be exploited on a deeper pool or a higher-value asset, the consequences could have been significantly more severe.
The incident was flagged by CertiK, which confirmed the attack vector and the attacker's profit of approximately $237,000. Hyperbridge has yet to publicly comment on the incident or disclose whether other token contracts using the same gateway are vulnerable to similar attacks.