Need help? Support
BITCOIN
Tether Dominance USDT.D

Cross-chain exploits steal $35M from DeFi

Published 565 words 3 min read

TLDR

At least three cross-chain DeFi bridges were hacked within hours, stealing over $35 million and exposing persistent security weaknesses in bridge infrastructure.

  1. AFX Trade, B Network and Verus bridges were exploited within roughly 6 hours, with losses around $24.2M, $3.9M and $7.5M respectively.
  2. The attacks mainly abused validator keys and flawed bridge logic, not the underlying cryptography of Bitcoin or Ethereum.
  3. DeFi users face ongoing bridge risk, so depth of audits, key management and incident response now matter as much as yields.

Deep Dive

1. What Was Exploited

Reporting from CoinDesk and others says at least three cross-chain protocols were drained for more than $35 million in one session, including AFX Trades Arbitrum bridge, the B Network staking system and the Verus Ethereum bridge. Bitcoin, Ethereum-linked protocols lose $35 million details the combined losses.

AFXs own custody bridge on Arbitrum was compromised for about $24.15 million in USDC, later bridged to Ethereum and swapped into roughly 12,467 ETH, with Arbitrums native bridge explicitly unaffected according to an AFX Trade bridge exploit report.

B Network lost about $3.86 million after an attacker seized upgrade authority over its staking contract, while Verus Ethereum bridge was hit again for about $7.5 million using a similar import-path bug to its May exploit, as covered in Verus Ethereum bridge hacked again for $7.54M. A CryptoPotato overview frames this run of attacks as three protocols were drained of $35M.

2. Why Bridges Are So Vulnerable

Across these incidents, the common thread is operational and design failure rather than broken cryptography. CoinDesk notes that each case involved either a logic flaw, where code behaved as written but still let unbacked funds out, or compromised keys granting attackers control they should never have had.

Verus is a clear example. Researchers at Backward Labs found that the bridge correctly verified signatures and proofs, but did not fully check that Ethereum-side payouts matched assets locked on the Verus side, enabling unbacked withdrawals; this persisted long enough for a second exploit, pushing total Verus bridge losses near $19 million as described in Verus bridge suffers second exploit in 66 days.

What this means

Cross-chain bridges remain one of DeFis weakest links because they mix complex contract logic, shared reserves and powerful keys, so small design or process errors can have outsized consequences.

3. Impact And What To Watch

For individual users, the main risk is that assets parked in or routed through a bridge can be drained even if the underlying chains are sound. AFX has paused its bridge and floated a white-hat bounty to recover funds, while B Network has suspended staking and pledged compensation, and Verus faces pressure to patch and re-audit its bridge before trust returns.

The broader market impact is heightened skepticism toward cross-chain systems and tighter scrutiny of validator key management and upgrade powers. When evaluating DeFi protocols, many users increasingly look at audit depth, bridge architecture, and whether funds rely on a single custom bridge or more battle-tested tooling.

Confidence: high because multiple independent security firms and news outlets report consistent timelines and loss figures.

Conclusion

These coordinated bridge exploits show that cross-chain infrastructure risk is now a core part of DeFi, not a corner case. The chains themselves held, but key custody and bridge logic did not. For crypto users, the practical takeaway is that yield or convenience from custom bridges should be weighed against how those systems are governed, audited and updated, since those operational details can determine whether tens of millions stay safe or disappear.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top