Two cryptocurrency blockchain bridges suffered devastating attacks within hours of each other, resulting in combined losses exceeding $31.6 million. The blockchain bridge attacks targeted the AFX decentralized exchange and the Verus protocol, highlighting ongoing security vulnerabilities in cross-chain infrastructure that stores large volumes of assets for transfers between different blockchain networks.
According to Web3 security firm Blockaid, AFX—a decentralized exchange operating on the Arbitrum network—was the first victim. Attackers extracted approximately $24.15 million through one of the platform’s cross-chain bridges on Wednesday evening. Hours later, Blockaid specialists detected a second attack against the Verus protocol bridge on the Ethereum network, where hackers stole various cryptocurrency assets totaling approximately $7.5 million.
How Did Attackers Compromise the AFX Bridge?
Blockaid discovered the AFX bridge exploit at 21:30 UTC. Steven Goldfeder, co-founder of Offchain Labs (the company behind Arbitrum development), confirmed on social network X that the breach affected a third-party protocol bridge rather than Arbitrum’s native infrastructure. Security specialist SunSec, founder of the DeFiHackLabs community and SEAL initiative participant, indicated that available data pointed to stolen private keys rather than exploitation of smart contract logic.
Ido Ben-Natan, co-founder and head of Blockaid, stated that preliminary investigation reached the same conclusions: five hot key validator addresses were compromised. He characterized the incident as an operational security (OpSec) breach rather than a smart contract vulnerability. The unauthorized fund withdrawal was accompanied by validator signatures, meaning the bridge’s blockchain verification mechanism functioned exactly as designed. Ben-Natan added that the required validator signature quorum was achieved through genuine signatures, indicating the breach occurred at the off-chain infrastructure level. AFX has not yet commented on the situation.
What Happened to the Verus Protocol Bridge?
The second incident targeted the Verus protocol’s Ethereum bridge, where attackers withdrew Ether, tBTC (an ERC-20 token backed by Bitcoin), plus USDC, USDt, EURC, MKR, and scrvUSD totaling approximately $7.5 million. Blockaid specialists noted this attack resembled a May incident involving the same Verus bridge, when $11.58 million was stolen. The attacker used the same attack method but a different wallet. Blockaid observed the attacker exploited the bridge’s import mechanism to initiate unbacked payments on the Ethereum network.
During the previous attack, the Verus team offered the attacker a deal to return 75 percent of stolen funds while keeping 25 percent as a bug bounty. Ultimately, the hacker returned 4052 ETH to the team. Nearly all funds returned in May were stolen again during this latest incident.
Why Are Blockchain Bridges Targeted?
Blockchain bridges remain among the most popular targets for attackers due to the large liquidity volumes necessary for their operation. Several of the largest cryptocurrency heists involved bridges. In February 2022, the Wormhole Bridge was hacked, resulting in $326 million stolen. In June 2022, the BNB Bridge was compromised, with over $580 million withdrawn.
Source: Xakep