BlocktoBlockto

Trending

Attacker Mints $1B Worth of Polkadot Tokens on Ethereum but Only Steals $237K
NEWS

Photo: Illustrative

Attacker Mints $1B Worth of Polkadot Tokens on Ethereum but Only Steals $237K

A security breach in Hyperbridge’s Ethereum gateway contract allowed an attacker to mint 1 billion bridged Polkadot (DOT) tokens on Ethereum, later converting them into roughly $237,000 worth of ether. The exploit did not impact the Polkadot main network or native DOT supply, but targeted the bridge’s flawed cross-chain validation logic.

Tristan R.
By Tristan R.

Senior Author · April 13, 2026

2 min
Key takeaways
A security breach in Hyperbridge’s Ethereum gateway contract allowed an attacker to mint 1 billion bridged Polkadot (DOT) tokens on Ethereum, later converting them into roughly $237,000 worth of ether.
The exploit did not impact the Polkadot main network or native DOT supply, but targeted the bridge’s flawed cross-chain validation logic.
DOT to ETH Chart Security analysis shows the attacker submitted a forged cross-chain message through the dispatchIncoming function , which was incorrectly accepted by the EthereumHost contract .

A security breach in Hyperbridge’s Ethereum gateway contract allowed an attacker to mint 1 billion bridged Polkadot (DOT) tokens on Ethereum, later converting them into roughly $237,000 worth of ether. The exploit did not impact the Polkadot main network or native DOT supply, but targeted the bridge’s flawed cross-chain validation logic.

DOT to ETH Chart

Security analysis shows the attacker submitted a forged cross-chain message through the dispatchIncoming function, which was incorrectly accepted by the EthereumHost contract. The request passed through to TokenGateway.onAccept, where a missing or bypassed state proof check allowed execution. The system processed an invalid request receipts validation, enabling unauthorized actions.

Admin Privileges Misused to Mint Unlimited Tokens

The malicious message triggered a changeAdmin function, granting the attacker full control of the bridged DOT contract on Ethereum. With admin access, they minted 1 billion tokens in a single transaction and routed funds through Odos Router V3, later swapping them on a Uniswap V4 DOT-ETH pool.

Blockchain security firm CertiK reported the exploit;

Liquidity Constraints Reduced Profit Impact

Despite the massive token mint, profits were limited due to low liquidity in the Ethereum DOT pool, which collapsed token value during dumping. The attacker extracted about 108.2 ETH across multiple trades, equal to roughly $237,000. Security firm analysis confirmed the exploit path and highlighted bridge vulnerabilities as a continued risk in cross-chain systems, where validation failures can enable unlimited token issuance.

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.

Attacker Mints $1B Worth of Polkadot Tokens on Ethereum but Only Steals $237K — Blockto — Blockto