Two cryptocurrency bridge exploits hit within hours Wednesday, draining $31.6 million from users. AFX, a decentralized perpetual futures exchange built on Arbitrum, lost $24.15 million in the first attack. Hours later, hackers targeted the Verus Ethereum bridge, capturing the remaining portion of stolen funds.
The rapid succession of attacks underscores persistent vulnerabilities in cross-chain bridge infrastructure. Bridges enable token transfers between blockchains but remain high-value targets for exploiters. They often rely on custodial mechanisms or complex smart contract logic that hackers systematically probe for flaws.
AFX's incident appears to stem from a logic error or vulnerability in its perpetual exchange contract. The platform, operating on Arbitrum's Layer 2 network, manages significant leverage positions and collateral pools. Attackers likely identified a path to extract collateral or manipulate price feeds that determine liquidations and funding rates.
The Verus bridge attack followed a similar pattern. Cross-chain bridges have proven repeatedly vulnerable to oracle manipulation, signature spoofing, or fund custodian exploits. Verus, which facilitates Ethereum connectivity, likely exposed a verification gap that allowed unauthorized asset transfers.
The timing raises questions about whether attackers coordinated strikes or simply capitalized on identical vulnerabilities across separate platforms. Security researchers often disclose exploits or share attack vectors within hacker communities, creating brief windows where multiple targets face identical risks.
Both protocols likely face pressure to pause operations, audit smart contracts, and recover funds. AFX and Verus must communicate damage assessments to affected users and clarify whether insurance mechanisms or protocol reserves can cover losses. Arbitrum's ecosystem, which hosts multiple DeFi protocols, now faces scrutiny over governance and security standards.
The $31.6 million haul reinforces that bridge infrastructure remains far risk
