Hackers Steal $31.6M in Two Crypto Bridge Attacks Within Seven Hours
AI مارکیٹ کا خلاصہ
Two bridge exploits totaling ~$31.6M (AFX-related bridge on Arbitrum and the Verus Ethereum Bridge) highlight persistent cross-chain operational and custody risk, including indications of key compromise and a repeated "import path" method enabling unbacked Ethereum-side payouts. While Arbitrum's native bridge was not breached, the incidents can dampen DeFi risk appetite and tighten liquidity across bridged assets and integrations.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT+0.10%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Cross-chain bridge security is again in focus after investigators flagged two separate exploits just hours apart, with combined losses topping $31.6 million. On-chain security firm Blockaid said funds were taken from bridge infrastructure tied to decentralized perpetual exchange AFX and from the Verus Ethereum Bridge.
Blockaid attributed $24.15 million in losses to an AFX-operated bridge on Arbitrum on Wednesday. A second incident, targeting the Verus Ethereum Bridge, reportedly drained about $7.5 million from bridge reserves. The back-to-back breaches highlight how bridge operators—and protocols that integrate them—can be exposed even when the issue is not linked to a single chain-level flaw.
Key points
- Blockaid reported $24.15 million stolen from an AFX-run bridge on Arbitrum and roughly $7.5 million drained from the Verus Ethereum Bridge within hours.
- Offchain Labs co-founder Stephen Goldfeder said Arbitrum’s native bridge was not compromised and pointed to activity originating from a third-party protocol.
- Security researchers said the AFX incident appears more consistent with compromised keys than a smart contract logic bug.
- Blockaid said the Verus exploit resembles a May incident, using a similar method but a different attacker wallet.
- The incidents reinforce why bridges remain high-value targets: they hold large asset pools and facilitate transfers across ecosystems.
AFX bridge incident on Arbitrum
Blockaid said it detected the AFX-related exploit at 9:30 pm UTC, describing it as a compromise involving a bridge operated by AFX, which runs on Arbitrum. Investigators characterized the event as an issue affecting a third-party integration rather than a breach of Arbitrum’s core bridging infrastructure.
Goldfeder addressed online claims of an “Arbitrum bridge hack,” saying the transaction in question originated from another protocol and that Arbitrum’s native bridge “has not been hacked or exploited in any way.”
Separate analysis from SunSec—founder of the DeFi security community DeFiHackLabs and a contributor to SEAL—said available evidence points more toward compromised keys than a vulnerability in contract logic. If confirmed, that would shift the response priority toward credential rotation and access review, underscoring that operational security can be as critical as smart contract design.
Cointelegraph sought comment from AFX. Blockaid’s findings and investigator observations form the basis of the current account.
Verus Ethereum Bridge: attack mirrors May method
In the second breach, Blockaid said the Verus Ethereum Bridge was exploited for about $7.5 million across multiple assets held in reserves. Tokens cited included Ether (ETH), tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
Blockaid said the technique appears similar to a May Verus Ethereum Bridge incident that resulted in $11.58 million stolen, though it involved a different attacker wallet. According to Blockaid, the attacker used the bridge’s “import path” to trigger “unbacked Ethereum-side payouts.” In effect, the workflow may allow assets to be released on Ethereum without corresponding backing elsewhere, creating a direct route to draining reserves.
Why bridge exploits keep happening
Bridge exploits remain difficult to eradicate because cross-chain systems combine custody, message passing (or import/export flows), and permissioning around settlement. Weaknesses at the seams—including credential compromise, flawed authorization, or brittle cross-chain state validation—can enable rapid fund extraction.
On-chain investigator TheCrypticWolf said on X that bridges will remain a weak link until “security is upgraded.” While that view is broad, the two same-day incidents add weight to the underlying point: large reserves attract attackers, and complexity makes comprehensive hardening challenging.
What to monitor next
Bridge incidents often trigger emergency measures such as pausing functionality, tightening authorization, and expanding monitoring. Market participants will be watching for follow-up disclosures from AFX and the Verus ecosystem, including investigator conclusions on root cause—whether key compromise, authorization failures, or repeatable weaknesses in import/export settlement.
More broadly, the events underscore that cross-chain risk extends beyond bridge operators. Decentralized applications and traders relying on bridges for liquidity and settlement may need to treat bridge security as an ongoing, evolving exposure rather than a one-time due diligence item.