Need help? Support
BITCOIN
Tether Dominance USDT.D

Bridge exploits drain $35M from DeFi

Published 520 words 3 min read

TLDR

Several DeFi bridges and cross-chain protocols were exploited within hours, with attackers stealing over $35 million in crypto.

  1. At least three bridge-related exploits hit AFX Trade, Verus Protocol and B Network, with combined losses reported around $35.55 million.
  2. The attacks mainly abused compromised keys and flawed upgrade or bridge logic, not the underlying cryptography, highlighting systemic design and governance weaknesses.
  3. For DeFi users, bridge risk is growing: protocols are pledging compensation or fixes, but repeated failures mean cross-chain exposure and key management deserve closer attention.

Confidence: high because multiple independent security firms and major outlets report consistent loss figures and exploit mechanics.

Deep Dive

1. What Was Actually Exploited

In a roughly six-hour window, at least three bridge or cross-chain systems were drained of more than $35 million, affecting infrastructure tied to Bitcoin, Ethereum and BNB Chain, according to a detailed CoinDesk recap of the attacks on Verus, B Network and AFX.

On Arbitrum, AFX Trades custody bridge lost about $24.15 million in USDC after an apparent key compromise, with funds bridged to Ethereum and swapped into roughly 12,468 ETH, as summarized in a Yahoo Finance report on the exploit.

The Verus Ethereum bridge suffered a repeat breach of its import path for around $7.37.5 million, while Bitcoin scaling project B Network lost an estimated $3.86 million after an attacker gained upgrade authority over its staking contract, allowing direct draining of funds.

2. Why Bridges Keep Failing

Investigations into the Verus incident show a classic design flaw: the bridge verified signatures and Merkle proofs but did not properly check that payout requests matched assets actually locked on the source chain, an authorization bypass and state-assumption bug described in a technical write-up on the Verus exploit.

AFXs incident appears rooted in compromised operational keys rather than a smart contract logic bug, and Bs exploit centered on excessive upgrade powers, illustrating that who controls the keys and permissions is often the real failure point.

Past data shows this is not isolated: Peckshield tracked roughly $328.6 million lost across eight major bridge exploits in May 2026, and Verus alone is now at about $19.1 million total drained across two similar attacks.

3. Impact On DeFi Users And What To Watch

These losses hit protocol treasuries and bridge reserves directly, cutting total value locked and putting pressure on affected tokens, but the core networks (Bitcoin, Ethereum, Arbitrum) were not themselves hacked.

Projects like B Network have pledged full user compensation, while AFX and Verus have paused or modified bridge operations, yet repeated exploits on the same contracts erode trust in cross-chain routes and can widen risk premia across DeFi.

What this means

If you use DeFi across multiple chains, the main risk is often the bridge and its key or upgrade governance, so monitoring audits, incident responses and how much value sits behind a single bridge is increasingly important.

Conclusion

The reported $35-million-plus drain shows that bridge and cross-chain infrastructure remains one of DeFis weakest links, with attackers exploiting governance and logic flaws rather than breaking cryptography.

For crypto users, the takeaway is less about abandoning DeFi and more about understanding where bridge risk sits in a stack, how protocols manage keys and upgrades, and which systems are repeatedly failing under stress.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top