NewsCryptoTwo Crypto Bridge Exploits Drain Over $31.6 Million Within Seven Hours

Two Crypto Bridge Exploits Drain Over $31.6 Million Within Seven Hours

Author: CryptoBreaking·

Key Takeaways

  • Two bridge-related exploits occurring within hours of each other on Wednesday resulted in combined losses exceeding $31.6 million, according to on-chain analytics firm Blockaid.
  • The AFX bridge on Arbitrum lost $24.15 million, with investigators suggesting the root cause was compromised private keys rather than a smart contract logic flaw.
  • Arbitrum's native bridge was not compromised in the AFX incident, as the attack originated from a third-party protocol integration, according to Offchain Labs co-founder Stephen Goldfeder.
  • The Verus Ethereum Bridge lost approximately $7.5 million using an attack method similar to a May incident that previously stole $11.58 million, indicating the same structural vulnerability remained exploitable.
  • Bridge protocols have historically accounted for the largest share of value stolen in DeFi attacks, with major incidents including Ronin Network ($625 million), Wormhole ($320 million), and Nomad Bridge ($190 million).
Two Crypto Bridge Exploits Drain Over $31.6 Million Within Seven Hours

Cross-chain security vulnerabilities remain a persistent challenge for cryptocurrency markets, as investigators reported two separate bridge-related exploits occurring within hours of each other. According to on-chain analytics firm Blockaid, the combined theft exceeded $31.6 million, with losses stemming from bridge infrastructure associated with decentralized perpetual exchange AFX and the Verus Ethereum Bridge.

Bridge protocols have historically accounted for the largest share of value stolen in DeFi attacks, with incidents such as the Ronin Network hack ($625 million, March 2022), the Wormhole exploit ($320 million, February 2022), and the Nomad Bridge drain ($190 million, August 2022) underscoring a recurring pattern that long predates Wednesday's incidents.

Blockaid reported that AFX's bridge lost $24.15 million on Wednesday, followed by an attack on the Verus Ethereum Bridge that drained approximately $7.5 million from bridge reserves. The back-to-back incidents highlight how bridge operators—and the protocols integrating with them—can remain exposed even when exploits are not tied to a single chain-level weakness.

AFX Bridge Exploit on Arbitrum

Blockaid said it detected an exploit at 9:30 PM UTC targeting a bridge operated by AFX, a decentralized perpetual exchange built on Arbitrum. The investigation characterized the event as a compromise of a third-party integration rather than a breach of Arbitrum's core bridging infrastructure.

Offchain Labs co-founder Stephen Goldfeder clarified that a bridge hack report circulating online had involved a transaction originating from a third-party protocol, and that Arbitrum's native bridge itself was not compromised. Goldfeder emphasized that Arbitrum's native bridge "has not been hacked or exploited in any way."

Additional analysis from SunSec—founder of the DeFi security community DeFiHackLabs and a contributor to SEAL—suggested that the evidence pointed more toward compromised private keys than a smart contract logic vulnerability. This distinction carries significant implications for incident response, as key compromise typically requires urgent credential rotation and a broader review of access controls, and signals that the weakest point may not always reside in the bridge contracts themselves. Private key compromises were also the root cause of the Ronin and Wormhole breaches, making operational security at bridge operators a recurring point of failure distinct from code-level bugs.

Cointelegraph reached out to AFX for comment regarding the reported exploit. The available reporting centers on observations made by Blockaid and affiliated investigators during the incident.

Verus Ethereum Bridge Attack Mirrors Prior May Incident

In a separate incident, Blockaid reported an exploit targeting the Verus Ethereum Bridge that drained approximately $7.5 million across multiple assets held in bridge reserves. Affected tokens included Ether (ETH), tBTC, USDC, USDt, EURC, MKR, and scrvUSD.

Blockaid noted that the attack method appears similar to a previous Verus Ethereum Bridge incident reported in May, which resulted in the theft of $11.58 million. In that earlier case, the same general approach was used but executed by a different attacker wallet. The recurrence suggests that even after a first exploitation, the same structural pathway remained accessible—a pattern that stands in contrast to single-incident bridge breaches where patches closed the specific vector.

According to Blockaid, the attacker leveraged the bridge's "import path" to trigger "unbacked Ethereum-side payouts." In practical terms, this indicates a workflow-level weakness: attackers may be able to induce the bridge to release assets on one side of the system without corresponding backing on the other side, creating a direct mechanism for reserve depletion.

The repeated nature of this tactic raises persistent concerns for users and integrators. Even when development teams patch a specific vulnerability, the operational mechanics governing imports and payouts can remain exploitable if underlying assumptions are not fully addressed.

Why Bridge Failures Continue

Bridge exploits remain difficult to eliminate entirely because cross-chain infrastructure typically combines multiple components: asset custody, message passing or import/export mechanisms, and permissioning systems for triggering settlement flows. When attackers discover a seam between these elements—whether through compromised credentials, incorrect authorization, or weaknesses in how cross-chain states are validated—the result is frequently a rapid draining of funds.

On-chain investigator TheCrypticWolf summarized the broader issue in a post on X, arguing that bridges remain a weak link until "security is upgraded." While that statement reflects a general perspective rather than incident-specific evidence, the two reported attacks occurring on the same day lend it concrete support: high-value bridge reserves make these systems attractive targets, and architectural complexity makes comprehensive hardening a significant challenge.

An important asymmetry exists between the two incidents. Blockaid's reporting on the AFX case was accompanied by Goldfeder's clarification that Arbitrum's native bridge was not compromised, suggesting the problem originated in third-party integration or bridge controls tied to a specific protocol. In contrast, Blockaid's description of the Verus incident emphasizes how the bridge import mechanism can produce Ethereum-side payouts that are not properly backed—an issue that may relate more directly to settlement logic and state assumptions.

Implications for Affected Ecosystems

Bridge-related incidents typically trigger emergency measures including pause controls, heightened monitoring, and modifications to custody or authorization workflows. Affected parties should monitor follow-up disclosures from AFX and the Verus ecosystem, particularly regarding what Blockaid and other investigators determine about root cause—whether key compromise, an authorization failure, or a repeatable weakness in import/export settlement.

More broadly, these events reinforce that cross-chain exposure extends beyond bridge operators alone. Decentralized applications and traders relying on bridges for liquidity and settlement should treat bridge security as a continuously evolving risk rather than a one-time consideration. The Verus incident in particular demonstrates that a known and previously exploited attack vector may persist across incidents months apart, meaning that awareness of a past breach is not sufficient evidence that the underlying issue has been resolved.