TLDR
Several cross-chain DeFi bridges and protocols were hacked within hours, with attackers stealing around $35M, exposing recurring weaknesses in bridge security and off-chain key management.
- AFX Trade, B Network, and Verus bridges were exploited in quick succession, with individual losses of roughly $24M, $3.9M, and $7.5M respectively.
- None of the attacks broke Bitcoin or Ethereum themselves; they abused compromised validator keys, upgrade powers, and a repeated bridge logic flaw.
- The incidents reinforce that cross-chain bridges remain high-risk infrastructure, so users should watch protocol security practices, admin key usage, and TVL concentration carefully.
Deep Dive
1. Three Attacks, ~$35M Lost
Reports describe a cluster of exploits where three cross-chain protocols were drained for over $35M in less than a day, with most of the damage landing in a roughly six hour window. AFX Trade, BSquaredNetwork, and Verus collectively lost over $35M.
AFX Trades Arbitrum bridge saw about $24.15M in USDC stolen, bridged to Ethereum and swapped for around 12,467 ETH, according to security firm Blockaid and Arbitrums Offchain Labs, who stressed that the native Arbitrum bridge was not affected by this third party exploit (Cointelegraph).
BSquared Network lost roughly $3.86M when its B2 tokens on BNB Chain were drained and converted through bridges into ETH and stablecoins, while the Verus Ethereum bridge was hit for about $7.37.5M in ETH, tokenized BTC and stablecoins in a second exploit following a May incident (Coindesk, Crypto.news).
2. Off-Chain Trust, Not Base Chains
Analyses emphasize that these attacks did not break Bitcoin or Ethereums cryptography. Instead, they targeted weaker trust assumptions around bridges and governance. AFXs loss is attributed to compromised bridge keys controlling withdrawals, while B Networks exploit stemmed from an attacker seizing upgrade authority over a staking contract and draining funds (Cryptobriefing).
Verus reused the same bridge import path and bug class as its May hack; detailed postmortems show the bridge verified signatures and proofs but failed to ensure that Ethereum payouts were backed by real reserves on the Verus side, an authorization bypass that remained exploitable for 66 days (Bitcoin.com).
Auditing smart contract code alone is not enough; who holds keys, what upgrade powers exist, and how bridge state is validated are critical risk factors.
3. User Impact And What To Watch
For ordinary users, the immediate impact is protocol-specific. AFX, B Network, and Verus face liquidity shocks, potential make-good plans, and reputational damage, but Bitcoin (BTC) and Ethereum (ETH) as base assets were not directly compromised.
More broadly, bridge exploits remain one of DeFis largest systemic risks, with hundreds of millions already lost to similar incidents this year (Bitcoin.com). Users and builders should pay attention to whether bridges are custodied or trust minimized, how many signers control withdrawals, whether upgrade keys are diversified or time locked, and whether recent security audits cover both logic and operational controls.
Confidence: high because multiple independent security firms, media outlets, and on-chain trackers converge on the amounts, timeline, and root causes.
Conclusion
The $35M drained across AFX, B Network, and Verus is another reminder that cross-chain DeFi risk often lives in governance and key management rather than in core blockchain cryptography.
If you interact with bridges or cross-chain protocols, treating admin keys, validator sets, and audit quality as first class signals can materially change your risk profile, especially during periods when large amounts of liquidity sit in a single bridge contract.
