TLDR
In a few hours, three cross-chain protocols were exploited for over $35 million, highlighting bridges and governance as major weak points in crypto infrastructure.
- AFX, Verus and B Network were hacked within hours, losing about $24.15M, $7.54M and $3.86M in separate bridge and staking contract exploits.
- The incidents reused known bugs and abused upgrade powers and keys, showing failures in operations and design rather than broken blockchain cryptography.
- User risk depends on which bridges and contracts hold their assets, so audits, key management and compensation plans matter as much as headline chains.
Deep Dive
1. Timeline And Amounts
Security firms report that three attacks on cross-chain systems in the AFX, Verus and B Network ecosystems drained roughly $35.55 million in total within a single day. CoinDesk notes that at least three bridges and cross-chain protocols were hit in a six hour window, with combined losses above $35 million.
AFXs cross-chain bridge on Arbitrum lost about $24.15 million in USDC, which the attacker moved to Ethereum and converted into 12,467.5 ETH, according to AFX bridge loses $24.15 million USDC.
The Verus Ethereum Bridge suffered a new exploit of roughly $7.54 million, using the same bridge contract and import path as a May hack, while Bitcoin scaling protocol B Network lost about $3.86 million when an attacker seized upgrade authority over its staking contract, as detailed in Bitcoin, Ethereum-linked protocols lose $35 million.
2. Why Bridges Are Fragile
In all three cases, the core chains such as Ethereum or Arbitrum were not broken. The failures sat in the bridge and protocol layers that control pooled assets and cross-chain messages.
For Verus, the latest exploit reused the same contract path and apparent bug class as the May incident, draining redeposited assets from the same bridge contract, according to Verus Ethereum Bridge hacked again for $7.54M. That shows how incomplete remediation can leave users exposed even after an apparent recovery.
For B Network, the attacker gained upgrade authority over a staking contract, then changed behavior to drain funds. This emphasizes how privileged keys, admin roles and upgrade logic are now as important to secure as the code itself.
The biggest structural risk in cross-chain systems is usually operational security and governance, not the underlying cryptography that secures Bitcoin or Ethereum.
3. User Impact And Safeguards
For everyday users, the key question is where assets are parked. Funds sitting in vulnerable bridges or staking contracts can be drained even when the base chain looks healthy. In the AFX case, Offchain Labs stressed that Arbitrums native bridge was unaffected and the loss came from a third party bridge operated by AFX.
These exploits also show how repeated issues can occur when compromised contracts are reused and when audits do not translate into strong security culture. Investigators note that the Verus bridge had already suffered an earlier exploit, and the July attack hit the same contract entry path.
Practical safeguards include favoring well established bridges with transparent audits, clear key management and emergency procedures, and paying attention to whether protocols publish detailed post mortems and firm compensation commitments after incidents. When those signals are weak, cross-chain exposure carries higher tail risk.
Conclusion
The loss of more than $35 million across AFX, Verus and B Network illustrates that cross-chain protocols concentrate risk in a few contracts and keys. When those controls fail, large pools of assets can vanish quickly even though the underlying blockchains remain sound. For crypto users, understanding which bridges and governance structures stand behind their deposits is now as important as choosing the right chain or token.
