Bitcoin- and Ethereum-linked bridges hit in rapid-fire exploits, losses top $35 million
AI مارکیٹ کا خلاصہ
A cluster of bridge and cross-chain exploits drained $35M+ within hours, including a Verus–Ethereum bridge bug enabling unbacked Ethereum-side payouts and a B² staking contract admin-key compromise. The common failure mode was governance/logic control rather than broken cryptography, reinforcing operational risk around bridges and privileged keys. Near-term impact is risk-off positioning across DeFi infrastructure and assets most exposed to bridge liquidity on Ethereum.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT-0.25%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
A wave of attacks hit crypto bridges and cross-chain protocols over a brutal six-hour stretch, with at least three projects drained for a combined total of more than $35 million, according to blockchain data reviewed by CoinDesk and security firms BlockAid and PeckShield.
The incidents did not involve broken cryptography. Investigators say the losses stemmed from either logic flaws that allowed value to be released as the code "correctly" executed, or from compromised keys and permissions that gave attackers control they should never have had.
The most severe case involved Verus. BlockAid said it detected an exploit early Thursday on the Verus–Ethereum bridge that siphoned roughly $7.54 million from bridge reserves, including ETH, tokenized bitcoin and multiple stablecoins. According to BlockAid, the attacker abused the bridge's import path to trigger Ethereum-side payouts that were not properly backed on the Verus side, draining about $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.
BlockAid also noted the exploit reused the same bridge contract and entry path as an earlier incident. CoinDesk previously reported that May hack, which resulted in about $11.5 million in losses. The attacker later returned most of those funds in exchange for a bounty.
On-chain records compiled by security researchers show Verus redeposited the recovered assets into the same bridge on July 8. Roughly two weeks later, the bridge was drained again.
The repeated breaches have been reflected in Verus' own metrics. DefiLlama data show Verus started 2025 with close to $100 million in total value locked. As of Thursday, that figure was about $9 million, following a steady decline and an additional drop this week tied to the latest exploit.
Another confirmed attack involved B² Network, a Bitcoin scaling network designed to make transactions cheaper and faster. B² said Thursday morning in Asia that an attacker obtained unauthorized access to the upgrade authority for its token staking contract, an administrative permission governing how the contract operates. Security firm Lookonchain traced about $3.86 million in B2 tokens that were sold, converted into ether and stablecoins, and moved away. B² said it had contained the incident, suspended staking and would fully compensate affected users.
The events underscore a familiar pattern in crypto security: smart contracts can fail even without code bugs if attackers gain control of privileged keys or admin permissions. That failure mode has driven some of the industry's largest thefts, including the Wormhole and Nomad bridge hacks in 2022 and KelpDAO's roughly $290 million loss earlier this year.
Defending against those attacks may also be getting harder. In an analysis published this week, OpenAI said an internal evaluation showed its AI models were able to escape a test environment and compromise Hugging Face servers by chaining stolen credentials with previously unknown software flaws. The test reduced the models' safety limits, so it was not an autonomous system acting independently. Still, the result demonstrated that AI can carry out the kind of patient, multi-step intrusion work that has traditionally required skilled human teams.
In crypto, the stakes are amplified. When a contract is drained, transactions are final and there is no chargeback. Over a 24-hour period, four teams — Verus, B², AFX and Balance — were drained for the same underlying reason, according to the report: trusted controls failed. None of the losses were caused by broken ciphers, and the tools for finding and exploiting privileged access continue to improve.