Hackers Steal More Than $31.6M in Two Crypto Bridge Exploits Within Hours
Key Takeaways
- •Blockaid said AFX lost $24.15 million after one of its cross-chain bridges on Arbitrum was exploited on Wednesday.
- •Offchain Labs co-founder Stephen Goldfeder said the affected transaction came from a third-party protocol and that Arbitrum’s native bridge was not compromised.
- •Blockaid’s CEO said the AFX exploit appeared to involve authentic validator signatures and likely stemmed from compromised offchain signing infrastructure.
- •The Verus Ethereum Bridge was separately drained of about $7.5 million in assets including Ether, tBTC, USDC, USDt, EURC, MKR and scrvUSD.
- •Blockaid said the Verus exploit used the same method as a May incident that drained $11.58 million, though a different attacker wallet was involved.

Hackers stole more than $31.6 million in two unrelated crypto bridge exploits that occurred just hours apart, targeting bridges operated by decentralized perpetual exchange AFX and Verus Protocol.
According to Blockaid, AFX, a decentralized perpetual exchange operating on Arbitrum, reportedly lost $24.15 million on Wednesday after one of its cross-chain bridges was targeted. Hours later, Blockaid said it detected a separate exploit against the Verus Ethereum Bridge, resulting in the theft of about $7.5 million in crypto assets.
The back-to-back incidents underscored the security risks that continue to affect cross-chain bridges, which are used to move assets between separate blockchains and often hold large reserves of funds. Cross-chain bridges have been among the most frequently targeted components in the crypto sector, with major bridge exploits dating back to 2022 — including the Ronin Network and Wormhole incidents — collectively responsible for losses exceeding $1 billion and prompting repeated calls from security researchers for upgraded key-management and validation practices.
“Another bridge, another exploit. Bridges will always be a weak link, until security is upgraded,” onchain investigator TheCrypticWolf said in a post on X: https://x.com/TheCrypticWolf1/status/2080145550100337039?s=20
AFX protocol bridge targeted
Blockaid said it detected an exploit at 9:30 pm UTC on Wednesday targeting a bridge operated by AFX. Offchain Labs co-founder Stephen Goldfeder confirmed that a bridge hack had affected a third-party protocol, while saying the Arbitrum native bridge had not been compromised.
“We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” Goldfeder said in a post on X: https://x.com/sgoldfed/status/2080071210847674709?s=20
SunSec, founder of the Web3 security community DeFiHackLabs and a contributor to SEAL, said the available evidence pointed to compromised keys rather than a smart contract logic flaw as the cause of the exploit: https://x.com/1nf0s3cpt/status/2080082521778467217?s=20
Ido Ben-Natan, co-founder and CEO of Blockaid, told Cointelegraph that the company’s assessment was consistent with reports that five hot validator keys had been compromised.
“This appears to have been an operational security incident rather than a smart contract vulnerability,” Ben-Natan said. “The unauthorized withdrawal carried genuine validator signatures, meaning the bridge’s onchain verification behaved exactly as designed rather than being bypassed.”
Ben-Natan added that the required validator quorum had been satisfied using authentic signatures, indicating that the compromise likely occurred in the bridge’s offchain signing infrastructure rather than in the bridge contract itself. Key compromises involving validator or signer infrastructure have been a recurring failure mode in bridge exploits, distinct from smart-contract logic bugs, because they allow attackers to produce valid signatures that onchain code has no mechanism to reject.
Cointelegraph said it reached out to AFX for comment.
Verus Ethereum Bridge hit in separate exploit
In a separate incident, Blockaid detected an exploit targeting the Verus Ethereum Bridge. The attack drained $7.5 million from bridge reserves in Ether, tBTC, USDC, USDt, EURC, MKR and scrvUSD. tBTC is a Bitcoin-backed ERC-20 token.
Blockaid said the attack appeared similar to a previous Verus Ethereum Bridge incident in May, when $11.58 million was drained. According to Blockaid, the same attack method was used, but the attacker wallet was different. The recurrence of the same exploit path against the same bridge months apart highlights the challenge of fully remediating bridge vulnerabilities once an import or verification flow is found to be exploitable.
“An attacker used the bridge import path to trigger unbacked Ethereum-side payouts,” Blockaid said.