Particle.news

Multiple Bridge Attacks Drain About $35 Million From Cross‑Chain Infrastructure

These incidents demonstrate how a single failure of validator signing keys or import‑path checks can let attackers authorize legitimate on‑chain withdrawals that are laundered rapidly.

Overview

  • AFX Trade’s third‑party Arbitrum bridge was drained of about $24.15 million after attackers obtained enough hot validator signatures to meet the bridge quorum on Wednesday, allowing a valid withdrawal to be executed.
  • The stolen USDC from AFX was bridged to Ethereum and swapped into roughly 12,467 ETH that analysts say now sit consolidated in a single wallet and are being tracked by forensic firms.
  • Early Thursday the Verus Ethereum bridge lost about $7.54 million when an attacker abused the bridge import path to trigger unbacked Ethereum‑side payouts using the same contract entry class that was exploited in May.
  • Security trackers report at least three related incidents in a six‑hour window, including a B² Network loss, producing combined reported drains near $35.5 million and showing repeated exposure in bridge and off‑chain controls.
  • Victim teams have suspended affected bridge operations, engaged forensic partners and started recovery efforts with uncertain outcomes, and AFX has publicly offered a 70/30 return/bounty to recover funds while investigators trace laundered flows.