TLDR
Several DeFi bridge and cross-chain protocols were hacked within hours, losing over $35 million and exposing recurring security weaknesses in key infrastructure.
- AFX Trade, Verus Bridge and B Network were exploited via compromised keys and flawed bridge logic, with combined losses around $35.5 million.
- The incidents highlight that DeFi risk still centers on governance, permissions and audits, not broken cryptography, with bridges and staking systems especially exposed.
- Crypto users should treat third-party bridges and bespoke staking contracts as high-risk, watching for compensation plans, code fixes and clearer security disclosures before trusting them.
Deep Dive
1. What Was Exploited
In roughly a 24 hour window, three protocols were hit: AFX Trade on Arbitrum, Veruss Ethereum bridge, and B Network staking, with total losses reported around $35.55 million. One detailed recap breaks down about $24.15 million stolen from an AFX-operated bridge, around $7.5 million from Verus, and roughly $3.86 million from B.
For AFX, attackers compromised validator signing keys for a custody bridge, meeting the quorum needed to authorize a withdrawal, then bridged stolen USDC to Ethereum and swapped it for about 12,467 ETH, as CoinDesk reports. Veruss Ethereum bridge was drained again via its import path, enabling payouts not backed by actual locked reserves, repeating a bug class from a May exploit described in follow up coverage. B Networks staking contract was hit after an attacker seized upgrade authority, allowing unauthorized changes and a direct drain of funds, according to a broader bridge-focused analysis.
2. Why These Hacks Matter
These exploits did not break Bitcoin or Ethereum cryptography; they abused how DeFi protocols manage keys, upgrades and bridge business logic. AFXs bridge code worked as intended, but the validator keys were in the wrong hands. Verus verified signatures and proofs, yet failed to ensure payouts matched assets actually locked, a logic gap explained in technical reporting on its second exploit.
Security firms note that most large 2026 losses still come from compromised keys and infrastructure rather than new contract bug types, even as AI tools make it easier to scan old code for weaknesses, as discussed in a wider review of AI and DeFi exploits published by Cointelegraph Magazine.
The main risk in many DeFi systems is how power is held and audited, not the base chains themselves; bridges and custom staking contracts are structurally fragile points.
3. What To Watch Next
For affected users, key questions are whether and how protocols will compensate losses and what concrete security changes they implement. B Network has pledged full compensation to impacted stakers, per CoinDesks bridge coverage, while AFX paused its bridge and is engaging security firms and partners. Verus now faces pressure to fully redesign its bridge lifecycle after repeating the same flaw class.
More broadly, users can reduce exposure by prioritizing: 1) native chain bridges over third-party custody bridges, 2) protocols with recent, high-quality audits that include bridge logic and upgrade paths, and 3) clear disclosure of key management and emergency controls. Monitoring on-chain security feeds for fresh alerts and watching how quickly teams patch and communicate after incidents can help distinguish serious operators from casual ones.
Conclusion
The $35 million in DeFi exploit losses came from a handful of bridge and staking systems, but they reinforce a wider pattern: the weakest links in crypto are often governance, keys and business logic around cross-chain movement, not the underlying chains. For crypto users, treating third-party bridges and complex staking contracts as high-risk and demanding stronger audits and transparency is increasingly important as attackers focus on these structural weak points.
