TLDR
Several recent hacks on cross-chain and bridge infrastructure have stolen around $35 million from DeFi protocols without compromising the underlying blockchains.
- Three linked incidents hit AFX Trade, Verus Bridge, and B Network, draining roughly $35.5 million from bridge and staking contracts.
- The attacks exploited bridge logic and key management, highlighting that business-rule flaws and compromised admins often matter more than pure cryptography.
- For users, the main risks are on third-party bridges and custody contracts, so how assets move between chains is now as important as where they are held.
Deep Dive
1. What Was Exploited And Where
Reporting from multiple outlets confirms three exploits within hours that together stole about $35.5 million from crypto protocols tied to Bitcoin and Ethereum ecosystems. AFX Trades USDC custody bridge on Arbitrum lost about $24.15 million, which the attacker bridged to Ethereum and swapped into 12,468 ETH in a single wallet, according to security firm coverage of the AFX exploit.
The VerusEthereum bridge suffered a repeat exploit, with attackers draining roughly $7.5 million by abusing its import mechanism to trigger unbacked payouts from reserves, as detailed in the Verus bridge report.
A separate B Network staking contract loss of about $3.86 million brings the combined total near $35.56 million in back-to-back hacks, as summarized in a broader multi-protocol incident recap.
Major chains like Ethereum and Arbitrum stayed intact, but attached bridges and staking contracts proved to be the weak links.
2. Why Cross-Chain Bridges Are So Vulnerable
In these cases, cryptographic proofs on the bridge contracts largely worked as designed; the failures came from business logic and operational security. The Verus bridge correctly verified signatures and Merkle proofs but failed to ensure payouts matched assets actually locked on the source chain, allowing unbacked withdrawals from reserves.
AFXs problem was concentrated key and custody risk: a self-operated bridge key was compromised, letting attackers drain USDC held off the main protocol. This pattern fits a wider trend where bridge design, admin-key custody, and oracle integration can be exploited even when the base chain is secure.
History shows this is not isolated: PeckShield tracked $328.6 million lost in eight major bridge incidents in May 2026 alone, underscoring that cross-chain infrastructure remains one of DeFis most fragile components.
3. Practical Impact And What To Watch Next
For everyday users, the direct impact depends on whether projects backstop losses. AFX and B have signaled attempts to compensate users or negotiate partial returns, while Verus now faces credibility and technical debt after a second similar exploit.
For the broader market, repeated bridge failures raise tail-risk for any protocol that depends on custom cross-chain messaging or custody solutions. Security firms and auditors are likely to focus more on economic backing checks, key management, and failure modes in bridge designs.
Key things to watch:
- Whether affected projects publish detailed postmortems and upgrade their bridges before resuming operations.
- New standards or audits specifically targeting cross-chain and custody bridges.
- Market reaction to protocols with heavy exposure to custom bridges versus battle-tested, widely used ones.
Confidence: high multiple independent reports agree on the incidents, amounts, and that core chains were not directly hacked.
Conclusion
Bridge and cross-chain exploits are again proving that the riskiest part of many DeFi stacks is not the base blockchain, but the glue that connects networks and custody systems.
For crypto users and builders, the takeaway is that cross-chain design, admin-key hygiene, and proof-of-reserves logic around bridges now belong alongside price, liquidity, and unlocks as core risk signals to monitor.
