Cryptocurrency hacks have become all too common, but it's rare for attackers to take huge risks and end up with relatively modest gains. However, that's exactly what happened on Sunday when an attacker exploited a vulnerability in the Hyperbridge cross-chain gateway.
The attacker was able to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network and then sell them for approximately $237,000 worth of ether. This exploit is the latest in a series of bridge vulnerabilities that have been exposed in 2026, including a $270 million exploit of the Drift Protocol on Solana last month.
The attack on Sunday targeted the bridge contract, rather than Polkadot's core network, and the native DOT token was not affected. The vulnerability in the Hyperbridge EthereumHost contract allowed the attacker to submit a forged cross-chain message, which was then processed as legitimate by the TokenGateway. This granted the attacker admin-level control over the bridged Polkadot token contract, enabling them to mint 1 billion tokens in a single transaction.
The attacker then used the Odos Router V3 to transfer the tokens to a Uniswap V4 DOT-ETH pool, where they were sold for roughly 108.2 ETH. However, due to the limited liquidity in the bridged DOT pool on Ethereum, the attacker was only able to extract a fraction of a cent per token, capping their profit at around $237,000. If the same vulnerability had been exploited on a deeper pool or a higher-value bridged asset, the losses could have been significantly larger.
The exploit was flagged by CertiK, which confirmed that the attack vector was the Hyperbridge gateway contract and that the attacker profited approximately $237,000 from minting and selling the bridged tokens. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts using the same gateway are vulnerable to the same attack vector.