TLDR
Around 35 million dollars was drained from multiple cross chain bridges this week, highlighting persistent security weaknesses in DeFi infrastructure rather than in core L1 chains.
- Three recent attacks on AFX Trade, Verus Ethereum Bridge and B Network bridges together stole about 35.55 million dollars from protocol reserves.
- The incidents show both human key compromise and buggy bridge logic, underscoring that audits alone cannot fully protect cross chain systems.
- For users, bridge risk now rivals exchange risk, so where and how you move assets across chains matters as much as which tokens you hold.
Deep Dive
1. What Happened In The 35M Exploits
Crypto reporting notes that in one day three exploits on AFX Trade, Verus Ethereum Bridge and B Network produced combined losses of about 35.55 million dollars from protocol infrastructure, not core L1 bridges. This included roughly 24.15 million USDC drained from AFX Trades Arbitrum bridge, about 7.54 million from the Verus Ethereum bridge, and around 3.86 million from B Networks bridge reserves, according to a summary of recent DeFi hacks.
At AFX Trade, security researchers report that compromised validator keys were able to satisfy the bridges 5-of-7 threshold, allowing the attacker to extract around 24.15 million USDC from the bridge in a single transaction, as described in a technical alert on the AFX exploit.
Verus Ethereum bridge suffered a second exploit in 66 days, with roughly 7.3 to 7.5 million dollars drained by abusing its import logic to trigger unbacked Ethereum side payouts, a flaw detailed in a postmortem of the Verus bridge breach.
2. Why Cross Chain Bridges Are So Vulnerable
These attacks highlight two main weak spots. First is human and operational risk around key management: at AFX, the bridge was sound at the smart contract level but failed because validator signing keys were compromised. No amount of code auditing can fully eliminate the danger of leaked or phished keys.
Second is complex business logic. The Verus exploit abused a mismatch between cryptographic proofs and economic reality, where the bridge verified signatures and proofs but did not correctly enforce that payouts matched assets actually locked on the source chain, as explained in the Verus bridge analysis.
Bridge incidents are part of a wider trend, with earlier losses like the Kelp maker/">DAO incident where about 292 million dollars was drained via forged cross chain messages and a misconfigured LayerZero bridge, according to a review of recent cross chain exploits.
Even well known bridge stacks can fail if validator sets, message verification, or payout logic are misconfigured, so relying on brand alone is not a sufficient safety check.
3. Impact For Users And What To Watch
For everyday users, the direct losses hit protocols and liquidity pools first, but any assets routed through affected bridges can face delayed withdrawals, paused deposits on exchanges, or repricing of protocol tokens. Market overviews show hundreds of hacks in 2026 and nearly a billion dollars stolen, with 207 incidents and about 972 million dollars taken in the first half of the year alone, as noted in a broader security risk review.
The practical things to watch are: which bridges a protocol uses, whether there is a clear public security council or emergency pause process, and how quickly teams publish root cause reports and recovery plans after an incident. New designs that keep BTC or other assets on their native chain and avoid wrapped tokens are emerging as alternatives, precisely to reduce bridge exposure.
If you use protocols that depend heavily on custom cross chain bridges, monitoring their security disclosures and bridge architecture is as important as tracking price and TVL.
Conclusion
Bridge exploits wiping around 35 million dollars this week reinforce that cryptos real systemic risk has shifted from centralized exchanges to cross chain infrastructure. Losses stem from both human key compromise and subtle logic bugs, so resilience now depends on careful bridge design, strong operational controls, and user attention to where assets travel, not just what they are.
