Cross-Chain Bridge Hacks Drain $31.6 Million from AFX and Verus Protocols, Exposing DeFi Vulnerabilities

Verus Protocol’s Ethereum Bridge was compromised in a separate hack nearly simultaneously, with losses around $7.5 million across multiple assets including ETH, tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
The AFX breach did not affect Arbitrum’s native bridge. Five hot-validator signatures on a third-party bridge approved the withdrawal of 24,150,000 USDC, clearing roughly two-thirds of the bridge’s quorum.
After the withdrawal, the attacker bridged the 24.15 million USDC to Ethereum and converted the proceeds into 12,467 ETH at an average price of about $1,937 per ETH.
Offchain Labs co-founder Stephen Goldfeder stated the vulnerability was strictly isolated to a third-party protocol and that the Arbitrum native bridge remained secure, emphasizing containment of the incident.
The incidents resemble a May attack on Verus’ bridge, which previously drained about $11.58 million, underscoring a recurring risk pattern in cross-chain bridges beyond the AFX event.
Two cross-chain bridge hacks drained a combined $31.6 million from decentralized finance protocols in quick succession. AFX Trade, a perpetuals exchange on Arbitrum, lost $24.15 million after attackers compromised the validator signing keys behind its third-party bridge, according to CoinDesk. Nearly simultaneously, Verus Protocol's Ethereum Bridge was hit for roughly $7.5 million across multiple assets including ETH, USDC, and tBTC.
Blockaid detected the AFX exploit at 9:30 p.m. UTC. The attacker used five compromised hot-validator signatures to approve a single withdrawal of 24.15 million USDC — clearing about two-thirds of the bridge's required quorum. Offchain Labs co-founder Stephen Goldfeder stressed that Arbitrum's native bridge was never touched, calling the breach strictly isolated to a third-party protocol.
The AFX bridge used a multi-signature system, meaning several validators must approve large withdrawals. Attackers compromised five of those validator keys, which was enough to meet the quorum threshold. That gave them full control to authorize the 24.15 million USDC withdrawal without triggering any automatic block, according to CoinDesk.
After pulling the funds, the attacker moved fast. They bridged all 24.15 million USDC from Arbitrum to Ethereum. Then they converted it into 12,467 ETH at an average price of roughly $1,937 per ETH, according to LCX. This rapid conversion into ETH is a classic pattern in bridge exploits — it makes the stolen funds much harder to freeze or trace.
Offchain Labs moved quickly to contain the panic. Co-founder Stephen Goldfeder said the vulnerability was "strictly isolated to a third-party protocol." The Arbitrum native bridge — the official gateway for moving assets in and out of the Layer-2 network — remained fully secure throughout the attack, according to Grafa.
The distinction matters. Layer-2 networks like Arbitrum rely on third-party bridges to connect to other blockchains. Those external bridges introduce new risks that the core network cannot control. In this case, the flaw was not in AFX's own code either — it was in the external bridge service AFX used to move funds, according to LCX.
The $7.5 million Verus Protocol hack was not the first. A nearly identical attack drained about $11.58 million from Verus' bridge just months earlier in May. That makes this the second major exploit of the same bridge in a short window — a sign of a recurring, unresolved vulnerability, according to Head Topics.
Assets stolen in the latest Verus hack included ETH, tBTC, USDC, USDt, EURC, MKR, and scrvUSD — a wide spread across multiple token types. This suggests the attacker had broad access to the bridge's holdings, not just one asset pool.
Cross-chain bridges are a known target. They hold large pools of assets and often rely on off-chain validator systems that can be compromised. The AFX and Verus hacks follow a long line of major bridge exploits that have cost the DeFi industry hundreds of millions of dollars in recent years, according to CoinDesk.
Security experts say the core problem is trust. Bridges must trust a group of validators to behave honestly. If even a handful of those validator keys are stolen or corrupted, attackers can drain the entire bridge. These two hacks — totaling $31.6 million — add fresh pressure on DeFi teams to rethink how they secure third-party bridge infrastructure.
Publishers
30
Articles
13
Reach
43