TLDR
Several cross-chain bridges, including AFX, BSquared Network and Verus, were exploited within hours, losing about $3536 million and underscoring that bridges remain a core security weak spot in crypto.
- Three main incidents hit AFX Trade, BSquared Network and the Verus Ethereum bridge, with losses clustered around $24.15M, $3.86M and $7.5M respectively.
- The attacks relied on compromised keys, upgrade powers and a repeated bridge logic flaw rather than breaking Bitcoin or Ethereum themselves.
- The events raise scrutiny on bridge design, audits and governance, and users should watch for postmortems, compensation plans and concrete security upgrades before trusting these routes.
Deep Dive
1. What Was Exploited
In a roughly 6 hour window, at least three cross-chain protocols were drained for a combined total of about $35.55 million across multiple chains and assets. AFX Trades Arbitrum-based bridge lost roughly $24.15 million in USDC that was bridged to Ethereum and converted into 12,467 ETH, according to on-chain analyses and reporting on the AFX bridge loss.
BSquared Network, a Bitcoin scaling protocol, saw around $3.86 million drained after attackers took control of its staking contracts upgrade authority, then swapped stolen B2 tokens into BNB and ETH before routing via NEAR and HOT Protocol, as summarized in Hackers Day coverage.
The Verus Ethereum bridge was exploited for about $7.54 million, draining ETH, tokenized BTC and stablecoins via its bridge import path, in a second attack that reused the same contract path and bug class as a May exploit, per Verus bridge hack analysis.
2. Why Bridges Stay Vulnerable
Reports from CoinDesk and security firms stress that none of these attacks broke underlying cryptography on Bitcoin or Ethereum; instead they exploited governance and logic gaps in cross-chain systems, including compromised keys and flawed validation rules in bridge contracts.
In AFXs case, investigators point to key or backend compromise around a 7-validator signing set, while BSquareds loss came from misused upgrade permissions on a staking contract, and Veruss repeat exploit reflects an unfixed validation flaw in its import path that allowed unbacked payouts on the Ethereum side. As one recap of Bitcoin and Ethereum-linked protocol losses notes, these are logic flaws and compromised keys rather than math failures.
bridge security depends as much on keys, upgrade controls and thorough audits as on smart contract code, and repeated flaws or weak processes can be just as damaging as a bug.
3. Impact And What To Watch
So far, the direct impact is concentrated in the exploited protocols and their users, but the pattern reinforces a broader narrative that cross-chain bridges are still cryptos weakest link. Some teams, like BSquared, have publicly committed to compensating affected users, while AFX and Verus are under pressure to publish clear postmortems and remediation plans.
For crypto users, the practical signals to watch are: whether these bridges reduce TVL and volumes, whether independent audits confirm fixes, and whether protocols tighten key management and upgrade governance. Market reaction has been cautious but not panic-level, with Bitcoin and Ethereum themselves remaining structurally intact despite the protocols around them suffering losses.
Conclusion
Cross-chain exploits totaling around $35M highlight that the main systemic risk lies in how bridges and staking contracts are designed, upgraded and operated, not in the base blockchains. Until bridge logic, key security and audits improve meaningfully, routing assets through smaller cross-chain protocols will carry elevated, protocol-specific risk that users and builders need to factor into their decisions.
