Cross-Chain Bridge Exploit Losses
Bridge and cross-chain protocol vulnerabilities are endemic to the ecosystem, exposing users to repeated theft and eroding confidence in these platforms
Too little corroboration in the last 3 days to call a trend (8 articles). Watching for it to gain traction.
Still mostly niche and specialist coverage — not yet picked up broadly by mainstream press.
"Community reports also alleged that the same attackers stole almost 4,000 ETH through similar methods over the previous 12 months."
"Wallets linked to crypto payment processor Coinsbuy were reportedly drained of more than $7.9 million across Ethereum and TRON around 13:00 UTC on Aug. 9, according to blockchain investigator Specter and follow up monitoring from security firms."
"Ethereum incurred the highest losses from incidents in H1 2026, with attackers primarily focusing on vulnerabilities in applications built on the network. By count, code exploits were the dominant driver of Ethereum incidents."
"AFX and the Verus-Ethereum bridge suffered about $31.69 million in combined losses within hours of each other... AFX attributed the incident to coordinated social engineering and infrastructure compromise... SlowMist's analysis said the bridge approved eight withdrawals without proving that matching assets backed them."
"The Verus Ethereum Bridge has suffered another exploit, with an attacker draining about $7.54 million in assets from the same contract hit in May. Blockaid said the July attack 'appears related to the previous Verus Ethereum Bridge incident in May 2026.' It also described the two incidents as involving the 'same bridge contract, same entry path, and same bug class.'"
"Blockaid said the new Verus exploit appears to involve the same type of weakness seen in May, but stopped short of confirming that the exact earlier vulnerability caused the July drain. Further technical details could clarify whether the May flaw remained exploitable, whether a related weakness caused the new incident, or whether the attacker used another route through the same import process."
"The attack adds to several bridge-related security incidents this year. As crypto.news previously reported, Stake DAO closed its vsdCRV bridge after an unauthorized mint on Arbitrum in May. Earlier in April, a larger exploit hit Kelp DAO's LayerZero-powered bridge. Attackers drained roughly 116,500 rsETH worth about $292 million."
"At least three were drained in quick succession in a 6-hour period for a combined total exceeding $35 million. Such repeated failures do not just cost the money stolen in any single attack, but drain the confidence that keeps assets on the platform at all."