Cryptocurrency hacks have become increasingly common, but it's rare for attackers to take significant risks and end up with relatively modest gains. However, this is exactly what happened on Sunday when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway to mint 1 billion Polkadot tokens, worth approximately $1.19 billion, on the Ethereum blockchain, only to sell them for around $237,000 worth of ether.

This exploit highlights the ongoing issue of bridge vulnerabilities, which have been a major concern in 2026, with several high-profile incidents, including a $270 million Drift Protocol drain on Solana, occurring in recent months. The attack targeted the bridge contract, rather than Polkadot's core network, and was made possible by a weakness in the validation process for incoming cross-chain messages. As a result, the attacker was able to submit a forged message, which was accepted as legitimate, allowing them to gain admin control over the bridged Polkadot token contract and mint 1 billion tokens.

The tokens were then sold on the Uniswap V4 DOT-ETH pool, but the low liquidity of the pool limited the attacker's profits. The incident has been confirmed by CertiK, which flagged the exploit and estimated the attacker's profits at around $237,000.

Hyperbridge has yet to comment on the incident or disclose whether other bridged token contracts using the same gateway are vulnerable to similar attacks.