While cryptocurrency hacks are common, instances where attackers take significant risks only to gain minimal rewards are rare. Such a scenario unfolded on Sunday, as an attacker exploited a vulnerability in a cross-chain gateway, creating 1 billion Polkadot tokens on Ethereum and selling them for around $237,000 in ether.

This incident highlights the growing list of bridge vulnerabilities in 2026, including a $270 million drain on Solana's Drift Protocol last month. The exploit targeted the bridge contract and not Polkadot's core network, leaving the native DOT token unaffected. The weakness was found in the validation process of incoming cross-chain messages by Hyperbridge's EthereumHost contract. Bridges, which facilitate the transfer of coins between blockchains, remain a weak point in cross-chain architecture due to their administrative control over token contracts.

The attack involved submitting a forged message that bypassed validation checks, granting the attacker administrative rights to mint unlimited tokens. The attacker then minted 1 billion tokens and sold them through a Uniswap pool, but limited liquidity restricted their profits to approximately $237,000. The incident was flagged by CertiK, which confirmed the attack vector and the attacker's profits. Hyperbridge has yet to comment on the exploit or disclose whether other bridged token contracts are vulnerable to similar attacks.