TLDR
Several Bitcoin and Ethereum-linked DeFi protocols were hacked in close succession, losing roughly 35 million dollars in bridge and infrastructure exploits.
- Three main incidents hit AFX Trade, Verus Bridge, and B Network, draining around 35.5 million dollars via cross-chain and infrastructure flaws.
- The losses highlight persistent security weaknesses in bridges and protocol logic, including a repeated bug on the Verus-Ethereum bridge.
- Users should watch for compensation plans, contract upgrades, and stronger audits, and treat cross-chain and smaller protocols as higher-risk venues.
Deep Dive
1. What Was Hacked And How Much
Recent reporting describes a cluster of attacks on Bitcoin and Ethereum-linked protocols that together cost users about 35.5 million dollars.
- Arbitrum-based AFX Trade lost around 24.15 million dollars in USDC after its bridge keys were compromised, prompting the team to offer the attacker a 30 percent bounty for returning most funds.
- The Verus-Ethereum Bridge was exploited for about 3,816 ETH, valued near 7.5 million dollars, using a bug similar to one seen in a prior May 2026 incident, bringing its cumulative bridge losses to roughly 19.1 million dollars.
- B Network suffered an exploit of about 3.86 million dollars but publicly pledged to fully compensate affected users, softening direct customer impact.
These incidents are summarized in reports from outlets such as U.today and Bitcoin.com, and referenced in wider DeFi exploit coverage on crypto news sites.
2. Why This Matters For BTC/ETH Ecosystems
These hacks did not compromise the core Bitcoin (BTC) or Ethereum (ETH) chains themselves. Instead, they targeted protocols that connect to or build on those networks, especially bridges moving assets between chains.
In the Verus-Ethereum case, researchers describe an authorization bypass and flawed state checks that allowed unbacked payouts from Ethereum bridge reserves even when cryptographic proofs looked valid. That kind of logic error shows how complex bridge designs can fail even when signatures and Merkle proofs verify correctly.
AFX Trade and B Network fit a broader pattern in 2026 where bridge keys, configuration, or protocol logic become single points of failure for large pools of user funds.
Risk often sits in the surrounding DeFi infrastructure, not the base BTC or ETH chains, so bridge and protocol quality matter as much as which asset you hold.
3. What Users Should Watch Next
For directly affected users, the key questions are whether teams honor compensation pledges and whether any negotiated white-hat deals with attackers succeed. B Network has said it will make users whole, while AFX Trade is attempting to recover funds via a bounty offer.
More broadly, it is worth monitoring whether these projects publish full postmortems and upgrade contracts to fix state-validation logic, and whether they add external audits or monitoring. Security firms already highlight that repeated bugs, as with the Verus bridge, are a major red flag.
For everyday users, practical risk management includes limiting exposure to newer or lightly audited bridges, diversifying venues, and keeping larger balances on more established protocols and exchanges that show stronger security and disclosure standards.
Conclusion
The 35 million dollar loss from Bitcoin and Ethereum-linked protocols is another reminder that cross-chain bridges and DeFi infrastructure remain prime targets, even when base chains are secure. The main consequences will depend on recovery, compensation, and how quickly affected projects harden their designs. For crypto users, treating bridges and smaller protocols as high-risk layers and watching for transparent postmortems and upgrades is key to navigating this environment.
