A recent cryptocurrency hack has highlighted the risks associated with cross-chain bridges, with an attacker exploiting a vulnerability in Hyperbridge's gateway to mint 1 billion Polkadot tokens, valued at $1.19 billion, on the Ethereum network. However, due to weak liquidity, the attacker was only able to sell the tokens for approximately $237,000 worth of ether. The exploit, which occurred on Sunday, is the latest in a series of bridge vulnerabilities to be exposed in 2026, including a $270 million Drift Protocol drain on Solana last month. The attack did not affect Polkadot's core network or its native token, DOT.
Instead, it targeted the bridge contract, which holds admin-level control over token contracts on destination chains, making it a prime target for attackers. The vulnerability in Hyperbridge's EthereumHost contract allowed the attacker to submit a forged cross-chain message, which was accepted as legitimate by the TokenGateway. This granted the attacker admin rights over the bridged Polkadot token contract, enabling them to mint 1 billion tokens and sell them on the market.
The attack was flagged by CertiK, which confirmed that the attacker profited approximately $237,000 from the exploit. The limited depth of the bridged DOT pool on Ethereum meant that the attacker was unable to capitalize fully on the exploit, with the tokens selling for a fraction of a cent each. If the attack had occurred on a deeper pool or involved a higher-value bridged asset, the losses could have been significantly greater.
As it stands, the exploit highlights the ongoing risks associated with cross-chain bridges and the need for robust security measures to protect against such attacks.