
Verus has now been hit by its second bridge exploit in roughly two months, with investigators identifying notable similarities between the two attacks.
Three cryptocurrency protocols, AFX Trade, BSquaredNetwork, and Verus, were exploited within a 24 hour period, resulting in combined losses exceeding $35 million in digital assets.
Three Separate Exploits Shake the Crypto Market
Blockchain security firm PeckShieldAlert reported that Arbitrum based protocol AFX was attacked on July 22, with approximately $24.15 million in USDC stolen. According to the firm, the attacker bridged the funds from Arbitrum to Ethereum before converting them into 12,467.5 ETH.
Less than an hour later, PeckShieldAlert disclosed another exploit targeting BSquaredNetwork on BNB Chain. Attackers stole around 8.59 million B2 tokens, valued at roughly $3.86 million. The stolen assets were quickly swapped for more than 5,000 WBNB, converted into 1,128 ETH, and transferred through NEAR Intents. Following the attack, the B2 token fell by more than 15%.
A third incident was reported by blockchain security company Lookonchain, which revealed that Ethereum based cross chain bridge Verus had also been compromised. Attackers escaped with approximately $7.55 million.
The latest Verus exploit comes only two months after the protocol suffered another breach that resulted in losses of around $11.58 million. Security firm Blockaid believes the two incidents are connected, noting that both attacks involved the same bridge contract, identical entry point, and the same category of vulnerability.
Security Practices Come Under Scrutiny
Steven Goldfeder, a contributor to Arbitrum, clarified that the compromised bridge was independently operated by AFX and was not part of Arbitrum’s native bridge infrastructure.
Meanwhile, blockchain security researcher Taylor Monahan questioned why the AFX bridge was securing as much as $24 million despite what she described as serious security shortcomings.
After reviewing a recently published audit, Monahan said she uncovered several alarming issues. According to her, the protocol had minimal test coverage, multiple vulnerabilities identified by auditors remained unresolved, and auditors were reportedly unable to conduct a full review because they received only portions of the project’s source code.
Mocking what she viewed as the team’s attitude toward risk, Monahan wrote, “Honestly, they seem like a super chill team. Ah yeah it’s probably fine we’ll just wait it out and then manually send if we need to.”
She argued that the most concerning aspect was not just the technical flaws themselves but what they suggested about the project’s overall security culture, which she believes failed to prioritize proper risk management.#crypto#cryptonews https://t.me/coinsignalpublic https://coinsignals.net