
Three independent DeFi exploits within hours targeted validator key management, cross-chain bridge validation, and contract upgrade authority, resulting in over $7.5 million in losses.
Three decentralized finance protocols were exploited within hours, with combined losses topping $7.5 million. The attacks targeted different layers of infrastructure – validator key management, cross-chain bridge validation, and contract upgrade authority – rather than a shared software vulnerability, blockchain security researchers said.
AFX Trade suffered the largest loss. Attackers compromised the signing infrastructure behind the protocol's USDC custody bridge on Arbitrum, researchers said. The bridge contracts executed as designed. The attackers obtained control of five hot-validator signing keys, the minimum threshold needed to authorize withdrawals, and used them to approve fraudulent transfers. The stolen USDC was bridged to Ethereum and exchanged for roughly 12,467 ETH. The protocol suspended bridge operations while investigating. Security firms and Offchain Labs said Arbitrum's native bridge was not affected.
A separate $7.55 million exploit hit the Verus Ethereum Bridge. Researchers from Blockaid said the attacker created a forged import payload that passed cryptographic verification despite representing virtually no economic value on the originating chain. By exploiting the missing validation step, the attacker triggered unbacked payouts of assets including ETH, tBTC, and USDC on Ethereum. Blockaid said the incident followed a similar exploit disclosed in May that relied on the same underlying failure mode, raising renewed questions about economic validation within cross-chain bridge designs.
The third breach affected B² Network. Attackers gained unauthorized control of the staking contract's upgrade authority, allowing changes to privileged contract functions. The project suspended staking while security teams investigated. The protocol later said the compromise had been contained, security reviews were completed, and no additional impact on protocol funds is expected.
The three incidents, though independent, each exploited a different operational component rather than a smart contract code flaw. The attacks renewed focus on how DeFi projects secure validator keys, validate cross-chain transfers, and manage administrative access controls, researchers said. The trend suggests attackers are shifting toward off-chain infrastructure and governance systems, making those areas as critical to protect as on-chain code.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.