Two separate cryptocurrency bridge exploits within a seven-hour window resulted in combined losses of roughly $31.6 million, according to blockchain security researchers tracking the incidents.
AFX Protocol Hit for $24 Million
AFX, a decentralized perpetual exchange running on the Arbitrum network, reportedly suffered the larger of the two attacks, losing an estimated $24.15 million on Wednesday. The exploit targeted the platform's bridging infrastructure, which is designed to move assets between blockchain networks.
Bridges have long been a favored target for attackers because they concentrate large pools of value and often contain complex smart contract code that can harbor vulnerabilities. AFX's losses represent the bulk of the day's damage across both incidents.
Cross-chain bridges remain among the most lucrative and frequently exploited targets in decentralized finance.
Verus Bridge Attacked Hours Later
The second incident struck the Verus Ethereum bridge only hours after the AFX exploit. Combined, the two attacks pushed total stolen funds to approximately $31.6 million, underscoring how quickly threat actors can move against multiple protocols in rapid succession.
The clustering of the two events raised questions among analysts about whether the attacks were coordinated or simply the product of a period of heightened activity by bad actors probing DeFi infrastructure for weaknesses.
A Persistent Threat to DeFi
Bridge exploits have accounted for some of the largest losses in the history of decentralized finance, and Wednesday's twin attacks add to a growing tally of stolen crypto assets in 2025. Security experts continue to urge users and developers to exercise caution when interacting with cross-chain services.
Key takeaways from the incidents include:
- AFX, a perpetual exchange on Arbitrum, reportedly lost about $24.15 million
- The Verus Ethereum bridge was exploited within roughly seven hours of the AFX attack
- The combined losses reached an estimated $31.6 million
Neither protocol had issued full post-mortem reports at the time of the initial disclosures, and recovery efforts along with the extent of the underlying vulnerabilities remained under investigation.
