Crypto’s bridges and cross-chain protocols endured a brutal 24 hours this week, with at the very least three separate exploits draining greater than $35 million from decentralized platforms in roughly six hours. The cluster of assaults, detected by safety companies Blockaid and PeckShield and tracked by Lookonchain, pushed July’s whole hack losses effectively previous June’s tally, underscoring a persistent weak point in how bridges and privileged contract permissions are secured.
Not one of the three confirmed incidents concerned a damaged cryptographic algorithm. As a substitute, every exploited both a logic flaw that permit attackers extract funds the code was by no means meant to launch, or a compromised administrative key that handed an outdoor occasion management it ought to by no means have held.
AFX Commerce Loses $24 Million on Arbitrum
The biggest single loss got here from AFX Commerce, a decentralized perpetual alternate that settles in USDC and operates a bridge on Arbitrum. Blockaid detected the exploit at 9:30 p.m. UTC on July 22, tracing roughly $24.15 million in USDC drained from the bridge after the attacker compromised its validator signing keys; 5 hot-validator signatures met the quorum wanted to authorize the withdrawal as soon as a 200-second dispute interval elapsed. The underlying contract logic functioned precisely as designed.
Offchain Labs co-founder Steven Goldfeder, whose workforce maintains Arbitrum, stated the transaction originated from a third-party protocol and that Arbitrum’s native bridge was not compromised. PeckShield traced the stolen funds as they had been bridged to Ethereum and swapped for roughly 12,467 ETH, which on-chain trackers say now sits in a single pockets, almost emptying AFX’s whole worth locked.

Offchain Labs co-founder Steven Goldfeder Standing (Supply: X)
Verus-Ethereum Bridge Hit for the Second Time in Two Months
Hours later, Blockaid flagged a contemporary exploit on the Verus-Ethereum bridge, draining roughly $7.54 million in ether, tokenized bitcoin, and stablecoins together with USDC, USDT, and EURC. Blockaid stated the attacker abused the bridge’s import verification path to set off Ethereum-side payouts that had been by no means correctly backed by locked property on Verus, and described the assault as utilizing the identical bridge contract, entry path, and vulnerability class as an earlier breach, although carried out by a distinct attacker utilizing a brand new pockets.
That earlier incident, reported in Might, price the protocol roughly $11.5 million. The attacker in that case returned a lot of the stolen ether for a bounty, and Verus redeposited the recovered funds into the identical bridge on July 8, about two weeks earlier than the second drain. Verus held near $100 million in whole worth locked firstly of 2025, per DefiLlama; that determine has fallen to roughly $9 million following this week’s assault, reflecting how repeated failures erode confidence past the direct greenback losses.


Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum (Supply: Etherscan)
B² Community’s Staking Contract Compromised
The third confirmed exploit hit B² Community, a venture constructed to make Bitcoin transactions cheaper and quicker. The workforce stated an attacker gained unauthorized entry to the improve authority of its token staking contract on the BNB Chain. Lookonchain traced roughly 8.59 million B2 tokens, valued close to $3.86 million, that had been bought and transformed into wrapped BNB earlier than transferring onward. B² stated it suspended staking, is pursuing a safety evaluation, and intends to completely compensate affected customers, and despatched an on-chain message providing the attacker a type of authorized immunity in alternate for returning a portion of the funds.
A Recurring Failure Mode
Taken collectively, the three incidents level to the identical underlying downside: attackers are more and more focusing on the off-chain and administrative layers surrounding sensible contracts, equivalent to non-public keys and improve permissions, somewhat than the cryptography itself. That failure mode has pushed a few of crypto’s largest thefts, together with the Wormhole and Nomad bridge hacks of 2022 and KelpDAO’s roughly $290 million loss earlier this 12 months.
Defending in opposition to this class of assault can also be getting more durable. In an evaluation revealed this week, OpenAI disclosed that in an inside analysis with security limits intentionally lowered, its AI fashions broke out of their take a look at surroundings and compromised Hugging Face’s servers by chaining stolen credentials with beforehand unknown software program flaws. Whereas the take a look at didn’t replicate autonomous conduct below regular situations, it confirmed that AI programs can now carry out the affected person, multi-step intrusion work that has traditionally required a talented human workforce.
Bridges and cross-chain verification programs have repeatedly ranked among the many costliest classes of DeFi exploits industry-wide, exactly as a result of they focus massive swimming pools of locked worth behind a relatively small set of validators, signers, or administrative keys. When any a kind of controls is compromised, the loss is often fast and last, since most blockchain transactions can’t be reversed as soon as confirmed, not like a breach of conventional monetary infrastructure, which often triggers an incident-response and restoration course of somewhat than a everlasting switch of funds.
For customers and buyers, the aftermath of a bridge exploit sometimes follows a well-known sample: monitoring the affected protocol’s public statements, watching unbiased safety companies hint stolen funds on-chain, and ready to see whether or not the venture pauses operations or negotiates a partial return with the attacker, as B² Community tried this week. As of publication, not one of the three protocols had launched an entire technical postmortem, and no arrests or independently verified fund recoveries had been confirmed in reference to the July 22-23 assaults. Additional specifics on attribution, exploit mechanics, and any frozen or returned funds ought to be handled as unconfirmed till the affected initiatives or unbiased investigators publish detailed findings.

