For anyone holding crypto through a bridge, this was the kind of night that turns confidence into panic.
In roughly six hours, attackers drained more than $35 million from three cryptocurrency protocols linked to Bitcoin and Ethereum. The losses did not come from breaking Bitcoin or Ethereum themselves. They came from the tools built around them.
That difference matters. Many retail investors hear Bitcoin, Ethereum, Arbitrum or wrapped tokens and assume similar safety. In reality, money often sits inside separate smart contracts, bridges, staking systems and private key setups. These layers can fail even when the major blockchains keep running normally.
The biggest hit came at AFX Trade, a perpetual futures platform that used an independently managed bridge on Arbitrum. Attackers removed about $24.15 million in USDC, moved the funds from Arbitrum to Ethereum, and swapped them for around 12,467 ether.
Perpetual futures platforms already carry high trading risk. They allow traders to bet on crypto prices without owning the underlying coin. When such a platform also depends on its own bridge, users face another risk layer: the security of the bridge itself.
That is where ordinary buyers often misread the market. A token may appear inside a wallet. A platform may show liquidity. A bridge may process transactions smoothly for months. But none of that proves the contract logic, admin keys or validation checks can survive a targeted attack.
A second breach hit B² Network, a Bitcoin scaling project. The attacker gained unauthorised access to the upgrade authority controlling its token-staking contract. That access allowed the intruder to generate or obtain about 8.59 million B2 tokens.
The attacker then sold those tokens through decentralised markets and moved the proceeds across several networks. The stolen B2 tokens eventually became more than 5,000 wrapped BNB, then about 1,128 ether, before moving through a cross-chain transaction system.
B² suspended its staking service after detecting the breach. It also said affected users would receive full compensation. That will matter for users, but it does not erase the market shock.
The B2 token fell by more than 15 percent after the incident. Traders reacted to the sudden increase in supply and uncertainty around the contract. For token holders, that price fall shows a second kind of damage. Even users who were not directly drained can lose money when confidence breaks.
The third attack struck Verus Protocol’s Ethereum bridge. About $7.54 million in assets left the bridge. The stolen funds included ether, tokenised bitcoin, stablecoins such as USDC, USDT and EURC, Maker, and tokenised savings products held in bridge reserves.
The Verus case looks especially troubling because the weakness had appeared before. In May, a similar validation failure caused an estimated $11.58 million loss. Most assets from that earlier attack returned after bounty discussions.
Verus placed recovered funds back into the bridge on July 8. Two weeks later, attackers drained the system again using a comparable method. That sequence raises a blunt question for the wider DeFi market. Was enough testing done before liquidity returned?
The technical issue sits at the heart of bridge security. Cross-chain bridges help users move value between networks that do not naturally speak to each other. Usually, the bridge locks an asset on one chain and issues a matching token or claim on another.
That sounds simple, but the trust problem is huge. The bridge must confirm that every claim on one network has real backing somewhere else. If it accepts a false message, an attacker can withdraw genuine assets without making the required deposit.
In the Verus attack, the bridge’s import function authorised Ethereum-side payments that did not have matching value on the Verus blockchain. The contract accepted the message and released real assets. The claim behind that message had little or no value.
For a regular investor, the lesson is not about one line of code. It is about where the money actually sits. A wrapped token or bridged asset depends on reserves, software checks and operational controls. It is not the same as holding the original asset on its native network.
Administrative control creates another risk. In B² Network’s case, the attacker used upgrade authority tied to the staking contract. Whoever controls an upgrade key may change contract behaviour without breaking the original code.
This is why decentralisation claims deserve scrutiny. A protocol may use decentralised markets and public blockchains, but still rely on a small number of privileged keys. If those keys fall into the wrong hands, users can face losses quickly.
AFX Trade’s case also points to a common blind spot. Its affected bridge did not belong to Arbitrum’s native bridging infrastructure. It was operated independently by the platform. Arbitrum contributors said the underlying network and official bridges were not compromised.
That distinction matters for Indian and Gulf users who move funds across chains. Seeing a familiar network name in a transaction does not mean every connected bridge has the same security standard. The network may be sound while a third-party bridge remains fragile.
Security reviewers had earlier identified limited test coverage and unresolved issues in the AFX bridge assessment. Parts of the code were also unavailable for a complete review. That restricted the ability to inspect the full system before funds entered it.
For traders, that should be a warning sign. Audits are useful, but they are not guarantees. An audit with incomplete code access or unresolved issues offers much less comfort than many users assume.
The wider pattern is hard to ignore. Cross-chain bridges have lost more than $2.8 billion through exploits over their operating history. A large share of stolen blockchain assets has come from these systems, not from attacks on Bitcoin or Ethereum core security.
Past bridge failures have often followed familiar routes. Attackers have used stolen validator credentials, forged transaction messages, weak proof checks and admin keys held by too few people. The methods vary, but the theme stays the same. Bridges concentrate risk.
This matters in Dubai, Abu Dhabi and the wider Gulf because crypto access has become more mainstream. More users now move between exchanges, wallets, DeFi apps and chains. Each movement can add convenience, but it can also add hidden exposure.
Retail investors often focus on coin price. They ask whether ether will rise, whether bitcoin will hold support, or whether a new token can multiply. These attacks show another question matters more. Can the plumbing safely hold the money?
Stablecoins also need special attention. Many users treat USDC or USDT as a cash-like parking spot. But when stablecoins sit inside a bridge reserve, their safety depends on that bridge. A stablecoin can keep its peg while the bridge holding it fails.
The practical takeaway is simple. Users should know whether they hold native assets, wrapped assets or bridge-issued claims. They should also check whether a protocol uses independent bridges, upgrade keys, recent audits and public incident history.
Compensation promises may reduce direct losses, but they cannot always restore market trust. Liquidity can leave quickly after a breach. Token prices can fall before users understand what happened. Smaller investors usually react after professional traders have already moved.
The three attacks did not end the case for cross-chain finance. Bridges still serve a real need in a fragmented crypto market. But they underline the cost of speed without strong controls.
Crypto users want instant movement across chains. Attackers want the same thing. Until bridges prove stronger validation, tighter admin controls and deeper testing, the weakest link in DeFi will remain the place where real money disappears fastest.