
Verus has now suffered two bridge exploits in roughly two months, with investigators pointing to striking technical similarities.
AFX Trade, BSquaredNetwork, and Verus have all fallen victim to exploits over the last 24 hours.
In what many are calling “Hackers Day,” the three protocols have collectively lost over $35 million in crypto assets.
Crypto Industry Hit With Three Separate Hacks
PeckShieldAlert said it detected an attack on Arbitrum-based protocol AFX on July 22, with estimated losses of about $24.15 million USDC. The on-chain security firm added that the exploiter bridged the stolen funds from Arbitrum to Ethereum, after which they swapped them for 12,467.5 ETH.
Less than an hour later, PeckShieldAlert reported that attackers had drained BSquaredNetwork of $8.59 B2 tokens on BNB Chain, resulting in it losing approximately $3.86 million. The hackers then quickly swapped the tokens for more than 5,000 WBNB, converted them into 1,128 ETH, and bridged the funds out using NEAR Intents. The impact on the market was quick, with B2’s price dropping by over 15% in the aftermath of the exploit.
It doesn’t stop there; blockchain security firm Lookonchain also alerted the public to another incident, this time affecting the Ethereum-based cross-chain bridge Verus protocol. In this case, the exploiters made off with $7.55 million.
Additionally, the latest exploit comes about two months after Verus lost roughly $11.58 million in a separate incident. Blockaid said that the July attack seems to be related to the previous exploit, describing the two as involving the same bridge contract, same entry path, and same bug class.
Monahan Questions AFX’s Security
Steven Goldfeder, a contributor at Arbitrum, has confirmed that the compromised bridge was operated independently by AFX and was not one of its native bridges.
You may also like:
Meanwhile, there seems to be a storm brewing elsewhere, with on-chain security expert Taylor Monahan questioning why the AFX bridge had $24 million on it in the first place.
She revealed that she had found some “terrifying” details after going through a recently published audit of the bridge. According to her, the protocol had almost no test coverage, several issues flagged by auditors were acknowledged but never fixed, and the auditors allegedly could not even fully review the code because they received only parts of it.
“Honestly, they seem like a super chill team. Ah yeah it’s probably fine we’ll just wait it out and then manually send if we need to,” she wrote.
Monahan says that the biggest red flags were what the technical vulnerabilities revealed about the team’s approach to security, explaining that the situation suggested a culture that didn’t prioritize it.
LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!
