TLDR
Multiple cross-chain DeFi protocols were hacked within hours, losing around $35 million to exploits targeting bridges and contract permissions rather than core blockchains.
- At least three systems, including AFX Trade, Verus Ethereum bridge and B Network, were drained for roughly $3536 million in a short window.
- The attacks abused compromised bridge keys and flawed cross-chain logic, highlighting bridges and admin controls as DeFis main structural weak points.
- Users should watch for remediation plans, compensation offers and tighter security controls before trusting newer bridges with large balances.
Deep Dive
1. What Was Exploited And How Big Was It?
Reporting from CoinDesk and on-chain trackers shows that in about six hours, three cross-chain and bridge protocols lost more than $35 million in total value.
- Arbitrum-based perp venue AFX Trade lost about $24.15 million in USDC after an attacker compromised keys to its custodial bridge, then moved funds to Ethereum and swapped into ETH. This is detailed in coverage of the AFX Trade bridge hack.
- The Verus Ethereum bridge was hit again, draining roughly $7.5 million in ETH, tokenized BTC and stablecoins from reserves using the same bridge contract and import path as a May exploit, according to the Verus bridge incident report.
- B Network, a Bitcoin-linked scaling protocol, lost around $3.86 million when an attacker seized upgrade authority over its staking contract and pushed unauthorized changes that let them drain funds, as summarized in the broader cross-chain attack overview.
These are not isolated bugs in small tokens but failures in infrastructure that many DeFi users rely on to move or stake assets across chains.
2. Why Bridges And Cross-Chain Logic Keep Breaking
None of the attacks required breaking blockchain cryptography. Instead, they exploited how bridges and cross-chain contracts are designed, governed and administered.
- AFX Trade appears to have fallen to compromised operational keys on its bridge, a reminder that custody-style bridges can be single points of failure when key security is weak.
- Verus repeated exploit came from a logic gap: the bridge verified proofs but did not fully enforce that payouts matched assets properly locked on the source chain, allowing unbacked withdrawals, as technical analysis of the Verus bridge flaw explains.
- B Networks loss was driven by overpowered upgrade permissions, showing that poorly scoped admin roles can let attackers rewrite contract behavior even when the code itself is secure.
For DeFi users, the real risk often sits in bridges, key management and governance powers, not in Bitcoin or Ethereum themselves.
3. What DeFi Users Should Watch Now
Security firms and teams are still investigating, and user outcomes depend on how each protocol responds.
- Some projects, like B Network, have publicly pledged full compensation to affected users; others may pursue partial recovery or bounty deals where hackers keep a slice if they return funds.
- For future safety, look for bridges with rigorous audits, clear limits on admin authority, public incident postmortems and diversified validator sets rather than single custodial keys.
- If you use cross-chain DeFi, avoid parking large balances on newer or lightly audited bridges, and monitor project channels for any suspension, upgrade or incident notices.
Treat cross-chain infrastructure as higher risk than core chains, size exposure accordingly, and give more weight to teams that upgrade security after incidents rather than redeploying funds into unchanged systems.
Conclusion
These exploits underline a structural reality in DeFi: the weakest links are often bridges and admin controls, not the underlying blockchains. Around $35 million was drained by abusing keys and logic gaps, and similar failures have recurred across the sector. Watching how protocols patch these issues, compensate users and redesign their cross-chain architectures will be key to judging which DeFi platforms remain trustworthy over time.
