0x5f474c845f47…5f474c87

ConfirmedSecurity624 vB116 sat/vB3 min decode

AFX and Verus Bridges Lose $31.5M in Same-Day Exploits

Two cross-chain bridges lost a combined $31.5 million in separate exploits within a single day, with AFX reporting $24 million in losses and Verus losing $7.5 million, according to a Bitcoin Foundation summary.

Outputs

  1. AFX cross-chain bridge lost $24 million in a same-day exploit

  2. Verus bridge lost $7.5 million in a separate incident reported the same day

  3. Combined losses across both bridges totaled $31.5 million

  4. Both incidents targeted cross-chain bridge infrastructure within a 24-hour window

  5. Specific exploit vectors, attacker addresses and post-mortem disclosures had not been publicly released at the time of the summary

$31.5 million in digital assets were drained from two separate cross-chain bridges within a single day, with AFX reporting $24 million in losses and Verus recording $7.5 million in losses from its own bridge operations, according to a summary published by Bitcoin Foundation.

The back-to-back exploits put a fresh spotlight on the bridge architecture that connects otherwise isolated blockchain networks. Bridges lock assets on a source chain and mint equivalent representations on a destination chain, concentrating custody in smart contracts and validator sets that have repeatedly proven exploitable. Because every transfer routes through a single contract layer, a successful exploit yields direct control over the entire locked pool — a payoff profile that has historically made bridges the highest-value targets in the digital-asset sector.

What's known about each incident?

AFX, the bridge that absorbed the larger loss at $24 million, operates cross-chain asset transfer infrastructure. Verus, which also runs a bridge component as part of its broader blockchain platform, lost $7.5 million the same day.

Details of the specific exploit vectors, attacker addresses and post-mortem disclosures had not been published in the materials reviewed. The Bitcoin Foundation summary did not specify whether the two incidents were linked operationally, technically or by a common threat actor, and neither bridge had issued a public acknowledgment at the time of writing.

Why do bridges remain a persistent target?

Cross-chain bridges collectively control some of the largest pools of crypto collateral in the industry. Volume routed through major bridges has grown alongside the proliferation of layer-1 and layer-2 networks, but the security perimeter of each bridge often remains narrower than the chains it connects.

A successful base-layer blockchain compromise typically requires coordinating across thousands of independent validators. A bridge often requires only a smart-contract bug, a logic flaw in the verification routine, or control over a small multisig of signers. Security firms have long recommended independent audits, formal verification of the wrapping logic, real-time monitoring of mint-and-burn volumes, and time-locked upgrade mechanisms. The repeated pace of high-value bridge exploits indicates those controls are still not deployed uniformly across the sector.

What's the operational fallout for users?

For users of the affected bridges, the immediate consequences split along two axes. Withdrawals tied to locked assets on the source chain typically freeze until a governance vote or migration plan is approved, leaving legitimate holders unable to access funds. Meanwhile, any wrapped or minted representations circulating on destination chains lose their backing, often trading at heavy discounts or collapsing to zero as arbitrageurs and market makers unwind positions.

Recovery depends on the project treasury, insurance funds, or a negotiated return from an identified attacker. Neither project had published a recovery plan in the materials reviewed, and the size of the AFX loss likely exceeds the cash reserves most early-stage bridge operators maintain on hand.

What happens next?

The incidents also land amid intensifying regulatory focus on cross-chain infrastructure. U.S. and European authorities have signaled that bridge operators may face money-transmitter or securities-custody obligations depending on how their products are structured, a development that could reshape compliance costs and operational footprints across the sector.

For affected users, the practical timeline hinges on post-mortem disclosures both protocols are expected to publish in the coming days. Until those documents land, the specific code paths compromised, the operational failures that enabled the drain, and any potential restitution mechanism will remain undisclosed. The next round of public statements from AFX and Verus will determine whether this episode joins the list of bridges that recovered through treasury bailouts and insurance funds — or the longer list of those that did not.

via Google News - Crypto Hack Exploit (Source)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles