Skip to main content

Hackers Drain $31.6M After Two Crypto Bridge Breaches in 7 Hours



Cross-chain security issues remain a major pain point for crypto markets, after investigators reported two separate bridge-related exploits occurring only hours apart. According to on-chain analytics firm Blockaid, the combined theft totaled more than $31.6 million, with funds taken from bridge infrastructure used by decentralized perpetual exchange AFX and the Verus Ethereum Bridge.



Blockaid said AFX’s bridge lost $24.15 million on Wednesday, before another attack targeting the Verus Ethereum Bridge resulted in roughly $7.5 million drained from bridge reserves. The back-to-back incidents underscore how bridge operators—and the protocols that integrate them—can be exposed even when exploits are not tied to a single chain-level weakness.



Key takeaways



  • Blockaid reported losses of $24.15 million from an AFX-operated bridge on Arbitrum and about $7.5 million drained from the Verus Ethereum Bridge within hours.

  • Offchain Labs co-founder Stephen Goldfeder said Arbitrum’s native bridge was not hacked, pointing to activity originating from a third-party protocol.

  • Security researchers suggested the AFX incident may have involved compromised keys rather than a smart contract logic flaw.

  • Blockaid said the Verus exploit appears to mirror a prior May incident, using a similar method while involving a different attacker wallet.

  • Both cases highlight that bridges remain high-value targets because they custody large asset pools and move value across ecosystems.



AFX bridge exploit on Arbitrum: what was targeted


Blockaid said it detected an exploit at 9:30 pm UTC aimed at a bridge operated by AFX, a decentralized perpetual exchange running on Arbitrum. The investigation framed the event as a bridge compromise affecting a third-party integration rather than a breach of Arbitrum’s core bridging infrastructure.



According to Offchain Labs co-founder Stephen Goldfeder, a bridge hack report circulating online had impacted a transaction originating from a third-party protocol, and that the Arbitrum native bridge itself had not been exploited. Goldfeder stated that the transaction in question originated from another protocol and emphasized that Arbitrum’s native bridge “has not been hacked or exploited in any way.”



Additional analysis from SunSec, the founder of the DeFi security community DeFiHackLabs and a contributor to SEAL, suggested that the evidence pointed more toward compromised keys than toward a vulnerability in smart contract logic. While that distinction matters for incident response—key compromise typically demands urgent credential rotation and broader access review—it also signals that the weakest point may not always be the bridge contracts themselves.



Cointelegraph sought comment from AFX regarding the reported exploit, but the additional reporting available here centers on what Blockaid and affiliated investigators observed during the incident.



Verus Ethereum Bridge attack: a similar method to May


In a separate incident, Blockaid reported an exploit targeting the Verus Ethereum Bridge that drained approximately $7.5 million across multiple assets held in bridge reserves. The listed tokens included Ether (ETH), tBTC, USDC, USDt, EURC, MKR, and scrvUSD.



Blockaid said the attack method appears similar to a previous Verus Ethereum Bridge incident reported in May, which resulted in the theft of $11.58 million. In that earlier case, Blockaid said the same overall approach was used, but by a different attacker wallet.



According to Blockaid, the attacker used the bridge “import path” to trigger “unbacked Ethereum-side payouts.” In practical terms, this points to a workflow-level weakness: attackers may be able to induce the bridge to release assets on one side of the system without corresponding backing on the other side, creating a direct path to reserve depletion.



For users and integrators, the repeated nature of the tactic raises a persistent risk: even when teams patch one vulnerability, the operational mechanics of how imports and payouts are handled can remain exploitable if the underlying assumptions aren’t fully addressed.



Why bridge failures keep recurring


Bridge exploits are difficult to eliminate entirely because cross-chain infrastructure often combines multiple components: custody of assets, message passing or import/export mechanisms, and permissioning for triggering settlement flows. When attackers find a seam between those elements—whether through compromised credentials, incorrect authorization, or weaknesses in how cross-chain states are validated—the result is frequently rapid draining of funds.



On-chain investigator TheCrypticWolf summarized the broader issue in a post on X, arguing that bridges remain a weak link until “security is upgraded.” While that statement reflects a general view rather than new incident-specific evidence, the two reported attacks within the same day give it concrete support: high-value bridge reserves make the system attractive, and high complexity makes comprehensive hardening challenging.



There is also an important asymmetry across the two incidents. Blockaid’s reporting on the AFX case was paired with Goldfeder’s clarification that Arbitrum’s native bridge was not compromised, suggesting the problem lay in third-party integration or bridge controls tied to a particular protocol. In contrast, Blockaid’s description of the Verus incident emphasizes how the bridge import mechanism can lead to Ethereum-side payouts that are not properly backed—an issue that may relate more directly to settlement logic and state assumptions.



What to watch next for affected ecosystems


Bridge-related incidents typically lead to emergency measures such as pause controls, increased monitoring, and changes to custody or authorization workflows. Readers should watch for follow-up disclosures from AFX and the Verus ecosystem, especially around what Blockaid and other investigators determine about root cause—whether it’s key compromise, an authorization failure, or a repeatable weakness in import/export settlement.



More broadly, these events reinforce that cross-chain exposure isn’t limited to the bridge operators alone: decentralized applications and traders relying on bridges for liquidity and settlement should treat bridge security as a continuously evolving risk, not a one-time checkbox.



https://www.cryptobreaking.com/hackers-drain-31-6m-after/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Hackers%20Drain%20$31.6M%20After%20Two%20Crypto%20Bridge%20Breaches%20in%207%20Hours%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Solana Policy Institute Calls on SEC to Safeguard DeFi Developers from Overly Strict Regulations

US Crypto Policy Innovation: Advocates Push for Clear Regulations and Developer Protections The Solana Policy Institute has urged the U.S. Securities and Exchange Commission (SEC) to differentiate between centralized crypto exchanges and non-custodial decentralized finance (DeFi) software. The nonprofit emphasizes that developers creating and publishing non-custodial code should not be classified as intermediaries, advocating for balanced regulation that fosters innovation without compromising security or legality. Key Takeaways Advocates call for regulatory clarity distinguishing between non-custodial DeFi protocols and centralized exchanges. The Institute argues that applying traditional securities laws to DeFi code risks stifling innovation and pushing activity offshore. Authorities are encouraged to adopt a custody-and-control-based framework to clarify legal liabilities. Legislation proposals aim to shield developers from legal liabilities associated with blockchain code and activ...