Newsgather
AtrásHackers Steal Over $31.6M in Back-to-Back Crypto Bridge Exploits Targeting AFX and Verus Protocol
Hackers Steal Over $31.6M in Back-to-Back Crypto Bridge Exploits Targeting AFX and Verus Protocol
En desarrollo
Cointelegraphhace 13 horasCrypto2 min de lectura

Hackers Steal Over $31.6M in Back-to-Back Crypto Bridge Exploits Targeting AFX and Verus Protocol

En resumen

  • Hackers stole over $31.6 million in two separate crypto bridge exploits targeting AFX's Arbitrum bridge ($24.15M) and the Verus Ethereum Bridge ($7.5M) within hours.
  • Blockaid detected both attacks, with the AFX incident likely due to compromised validator keys, underscoring persistent security risks for cross-chain bridges.

Resumen generado por IA

Por qué importa

Two crypto bridge exploits totaling over $31.6 million occurred hours apart, targeting AFX and Verus Protocol, highlighting continued security risks for cross-chain bridges.

Tamaño de fuente

Hackers stole more than $31.6 million across two unrelated crypto bridge exploits spaced just hours apart, targeting bridges operated by decentralized perpetual exchange AFX and Verus Protocol.

According to Blockaid, AFX, a decentralized perpetual exchange operating on Arbitrum, reportedly lost $24.15 million on Wednesday through a hack targeting one of its cross-chain bridges. Hours later, Blockaid said it detected an exploit targeting the Verus Ethereum Bridge that resulted in about $7.5 million in crypto being stolen.

The back-to-back exploits highlight the continued security risks facing crosschain bridges, which hold large pools of assets and move funds between separate blockchains.

“Another bridge, another exploit. Bridges will always be a weak link, until security is upgraded,” onchain investigator TheCrypticWolf said in a post on X.

Blockaid said Wednesday it detected an exploit at 9:30 pm UTC targeting a bridge operated by AFX. Offchain Labs co-founder Stephen Goldfeder confirmed a bridge hack had affected a third-party protocol.

“We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” Goldfeder said in a post on X.

SunSec, founder of the Web3 security community DeFiHackLabs and a contributor to SEAL, said the evidence suggested compromised keys, rather than a smart contract logic bug, were responsible for the exploit.

According to Ido Ben-Natan, co-founder and CEO of Blockaid, the company’s assessment was consistent with reports that five hot validator keys had been compromised.

“This appears to have been an operational security incident rather than a smart contract vulnerability,” Ben-Natan told Cointelegraph. “The unauthorized withdrawal carried genuine validator signatures, meaning the bridge’s onchain verification behaved exactly as designed rather than being bypassed.”

He added that the required validator quorum had been satisfied using authentic signatures, suggesting the compromise occurred in the bridge’s offchain signing infrastructure rather than in the bridge contract itself.

In a separate incident, Blockaid detected an exploit targeting the Verus Ethereum bridge, leading to $7.5 million in Ether, tBTC (a Bitcoin-backed ERC-20 token), USDC, USDt, EURC, MKR and scrvUSD drained from bridge reserves.

Blockaid said the attack appears similar to the previous Verus Ethereum Bridge incident in May that drained $11.58 million, using the same attack method but a different attacker wallet.

“An attacker used the bridge import path to trigger unbacked Ethereum-side payouts,” said Blockaid.

Preguntas abiertas

  • How were the validator keys for AFX compromised?
  • What specific vulnerabilities allowed the Verus exploit?
  • What measures will AFX and Verus Protocol take to prevent future attacks?

Temas relacionados

This article was originally published by Cointelegraph.

Noticias relacionadas

Más sobre este temacrypto