While cryptocurrency hacks are commonplace, it's unusual for attackers to take significant risks and walk away with relatively modest gains. However, that's exactly what happened on Sunday when an attacker exploited a vulnerability in Hyperbridge's cross-chain gateway, minting 1 billion Polkadot tokens on Ethereum and selling them for approximately $237,000 worth of ether.

This exploit highlights the ongoing issue of bridge vulnerabilities, which have been a recurring problem in 2026, including a $270 million Drift Protocol exploit on Solana last month. The attack targeted Hyperbridge's EthereumHost contract, specifically the validation process for incoming cross-chain messages. Bridges, which facilitate the transfer of coins between blockchains, are often the weakest link in cross-chain architecture due to their admin-level control over token contracts on destination chains.

The vulnerability allowed the attacker to submit a forged message, which was accepted as legitimate, granting them admin rights to the bridged Polkadot token contract. With this control, the attacker minted 1 billion tokens and sold them on Uniswap, but limited liquidity restricted their profit. The exploit was flagged by CertiK, which confirmed the attack vector and estimated the attacker's profit at approximately $237,000. Hyperbridge has yet to publicly comment on the exploit or disclose whether other bridged token contracts using the same gateway are vulnerable to similar attacks.