Cross-chain infrastructure faced renewed scrutiny Wednesday after back-to-back exploits drained tens of millions of dollars from bridge protocols within hours. A custody bridge operated by Arbitrum-based perpetual exchange AFX Trade lost approximately $24 million to compromised validator keys, while the Verus-Ethereum bridge suffered a $7.5 million repeat attack exploiting the same vulnerability class used in May Cointelegraph. The incidents, which also impacted other systems including B² Network, pushed total losses to roughly $35 million across multiple Bitcoin and Ethereum-linked protocols, underscoring persistent weaknesses in cross-chain custody and validation mechanisms that continue to plague the sector CoinDesk.
The AFX Trade exploit specifically targeted the decentralized perpetual exchange's proprietary custody bridge rather than Arbitrum's native network infrastructure. Security firms reported that attackers gathered sufficient signatures from hot validators to authorize a withdrawal of 24.15 million USDC, draining the protocol's reserves CoinDesk. Blockchain analytics subsequently tracked the movement of stolen funds as the perpetrator bridged assets from Arbitrum to Ethereum and swapped them for 12,467 ETH, consolidating the loot on the mainnet The Block. In an effort to recover the assets, AFX Trade publicly offered the attacker a 30% bounty—representing approximately $7.2 million—if the remaining funds were returned Decrypt.
Hours after the AFX breach, the Verus-Ethereum bridge fell victim to a nearly identical exploit method that had already cost the protocol millions two months prior. The attacker drained $7.54 million by leveraging the same vulnerability class identified in the May incident, according to security firm Blockaid, raising questions about why the previously exploited vector remained unpatched The Block. The timing of the incidents—occurring within a seven-hour window—suggested either a coordinated campaign or opportunistic attacks against bridge architectures during a period of heightened market activity Cointelegraph.
Analysts examining the attacks noted that neither exploit relied on breaking underlying cryptographic systems or consensus mechanisms. Instead, the thefts succeeded through practical compromises including stolen private keys, unchecked upgrade powers held by validators, and inadequate validation checks that allowed malicious withdrawal transactions to process without proper multi-party authorization CoinDesk. Arbitrum developers moved quickly to emphasize that their native bridge remained completely unaffected by the AFX incident, drawing a sharp distinction between layer-2 infrastructure security and the security of third-party custody solutions built atop the network Decrypt.
The consecutive breaches highlight an ongoing pattern where bridge protocols—frequently custodial by design—present concentrated, high-value targets for attackers seeking to move assets across chains while bypassing traditional settlement guarantees. With AFX Trade attempting to negotiate recovery through its bounty offer and Verus facing its second multimillion-dollar breach in as many months, the episodes serve as the latest evidence that cross-chain interoperability continues to carry significant operational and custodial risks that have yet to be fully mitigated by current security practices.