
Cross-chain security issues remain a major pain point for crypto markets, after investigators reported two separate bridge-related exploits occurring only hours apart. According to on-chain analytics firm Blockaid, the combined theft totaled more than $31.6 million, with funds taken from bridge infrastructure used by decentralized perpetual exchange AFX and the Verus Ethereum Bridge.
Blockaid said AFX’s bridge lost $24.15 million on Wednesday, before another attack targeting the Verus Ethereum Bridge resulted in roughly $7.5 million drained from bridge reserves. The back-to-back incidents underscore how bridge operators—and the protocols that integrate them—can be exposed even when exploits are not tied to a single chain-level weakness.
Key takeaways
- Blockaid reported losses of $24.15 million from an AFX-operated bridge on Arbitrum and about $7.5 million drained from the Verus Ethereum Bridge within hours.
- Offchain Labs co-founder Stephen Goldfeder said Arbitrum’s native bridge was not hacked, pointing to activity originating from a third-party protocol.
- Security researchers suggested the AFX incident may have involved compromised keys rather than a smart contract logic flaw.
- Blockaid said the Verus exploit appears to mirror a prior May incident, using a similar method while involving a different attacker wallet.
- Both cases highlight that bridges remain high-value targets because they custody large asset pools and move value across ecosystems.
AFX bridge exploit on Arbitrum: what was targeted
Blockaid said it detected an exploit at 9:30 pm UTC aimed at a bridge operated by AFX, a decentralized perpetual exchange running on Arbitrum. The investigation framed the event as a bridge compromise affecting a third-party integration rather than a breach of Arbitrum’s core bridging infrastructure.
According to Offchain Labs co-founder Stephen Goldfeder, a bridge hack report circulating online had impacted a transaction originating from a third-party protocol, and that the Arbitrum native bridge itself had not been exploited. Goldfeder stated that the transaction in question originated from another protocol and emphasized that Arbitrum’s native bridge “has not been hacked or exploited in any way.”
Additional analysis from SunSec, the founder of the DeFi security community DeFiHackLabs and a contributor to SEAL, suggested that the evidence pointed more toward compromised keys than toward a vulnerability in smart contract logic. While that distinction matters for incident response—key compromise typically demands urgent credential rotation and broader access review—it also signals that the weakest point may not always be the bridge contracts themselves.
Cointelegraph sought comment from AFX regarding the reported exploit, but the additional reporting available here centers on what Blockaid and affiliated investigators observed during the incident.
Verus Ethereum Bridge attack: a similar method to May
In a separate incident, Blockaid reported an exploit targeting the Verus Ethereum Bridge that drained approximately $7.5 million across multiple assets held in bridge reserves. The listed tokens included Ether (ETH), tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
Blockaid said the attack method appears similar to a previous Verus Ethereum Bridge incident reported in May, which resulted in the theft of $11.58 million. In that earlier case, Blockaid said the same overall approach was used, but by a different attacker wallet.
According to Blockaid, the attacker used the bridge “import path” to trigger “unbacked Ethereum-side payouts.” In practical terms, this points to a workflow-level weakness: attackers may be able to induce the bridge to release assets on one side of the system without corresponding backing on the other side, creating a direct path to reserve depletion.
For users and integrators, the repeated nature of the tactic raises a persistent risk: even when teams patch one vulnerability, the operational mechanics of how imports and payouts are handled can remain exploitable if the underlying assumptions aren’t fully addressed.
Why bridge failures keep recurring
Bridge exploits are difficult to eliminate entirely because cross-chain infrastructure often combines multiple components: custody of assets, message passing or import/export mechanisms, and permissioning for triggering settlement flows. When attackers find a seam between those elements—whether through compromised credentials, incorrect authorization, or weaknesses in how cross-chain states are validated—the result is frequently rapid draining of funds.
On-chain investigator TheCrypticWolf summarized the broader issue in a post on X, arguing that bridges remain a weak link until “security is upgraded.” While that statement reflects a general view rather than new incident-specific evidence, the two reported attacks within the same day give it concrete support: high-value bridge reserves make the system attractive, and high complexity makes comprehensive hardening challenging.
There is also an important asymmetry across the two incidents. Blockaid’s reporting on the AFX case was paired with Goldfeder’s clarification that Arbitrum’s native bridge was not compromised, suggesting the problem lay in third-party integration or bridge controls tied to a particular protocol. In contrast, Blockaid’s description of the Verus incident emphasizes how the bridge import mechanism can lead to Ethereum-side payouts that are not properly backed—an issue that may relate more directly to settlement logic and state assumptions.
What to watch next for affected ecosystems
Bridge-related incidents typically lead to emergency measures such as pause controls, increased monitoring, and changes to custody or authorization workflows. Readers should watch for follow-up disclosures from AFX and the Verus ecosystem, especially around what Blockaid and other investigators determine about root cause—whether it’s key compromise, an authorization failure, or a repeatable weakness in import/export settlement.
More broadly, these events reinforce that cross-chain exposure isn’t limited to the bridge operators alone: decentralized applications and traders relying on bridges for liquidity and settlement should treat bridge security as a continuously evolving risk, not a one-time checkbox.
https://www.cryptobreaking.com/hackers-drain-31-6m-after/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Hackers%20Drain%20$31.6M%20After%20Two%20Crypto%20Bridge%20Breaches%20in%207%20Hours%20
Comments
Post a Comment