Two blockchain protocols connected to Bitcoin and Ethereum were drained of roughly $35 million in a series of exploits that unfolded within hours of one another, underscoring persistent security weaknesses in cross-chain infrastructure.
What Happened
The attacks struck Verus, B² Network and other systems that move assets between separate blockchains. According to reports, the incidents occurred in quick succession, catching operators off guard and highlighting how vulnerable interoperability layers remain despite years of high-profile bridge hacks.
Rather than breaking the underlying cryptography that secures these networks, attackers exploited operational weak points. Compromised private keys, overly powerful upgrade permissions and flawed validation checks allowed malicious actors to siphon funds without ever cracking the math that protects blockchain transactions.
The cryptography held — but the humans and the code around it did not.
How The Exploits Worked
Cross-chain protocols rely on complex mechanisms to verify and transfer value between networks that were never designed to communicate directly. That complexity creates a wide surface area for attackers to probe. When a single key is compromised or an upgrade function is left insufficiently guarded, the entire protocol can be emptied in minutes.
The near-simultaneous nature of the attacks raised questions about whether the same group targeted multiple protocols after identifying a shared class of weakness. Security researchers have long warned that bridges and interoperability tools represent some of the most attractive targets in crypto because they concentrate large amounts of value in a handful of contracts.
Key failure points identified in the incidents included:
- Compromised private keys granting unauthorized access
- Excessive upgrade powers that let attackers alter contract behavior
- Weak validation checks that failed to catch fraudulent transfers
The Bigger Picture
The losses add to a long and costly record of bridge and cross-chain exploits, a category that has drained billions from the industry over the years. Each incident tends to follow a familiar pattern: the base-layer cryptography remains intact, but the surrounding operational and administrative controls prove to be the weak link.
For users and developers, the events serve as a reminder that interoperability comes with heightened risk. As the ecosystem continues to build tools connecting Bitcoin, Ethereum and other networks, security experts argue that hardening key management and limiting administrative privileges will be essential to preventing the next round of nine-figure losses
