⚠️ Three exploits, in one day, $35.55M lost: DeFi had its “black Tuesday” in 24 hours
Yesterday wasn’t a bad day for a protocol. It was a bad day for the entire sector.
AFX Trade: $24.15M for a key, not for a bug
The AFX bridge contract on $ARB did exactly what it was supposed to do: it verified valid signatures and released the funds. The problem is that those signatures came from compromised validator keys. In 200 seconds, the attacker moved the money to Ethereum and converted it into more than 12,400 ETH. Arbitrum as a network had nothing to do with it—it was isolated by AFX’s own bridge.
Verus: the same wound, twice
The Verus–Ethereum bridge lost $7.54M by exploiting the same route and the same type of failure that had already hit it in May. Repeating the same bug twice in a year says something uncomfortable: patching the symptom isn’t the same as fixing the cause.
B² Network: when the “admin” is the attack vector
Here there wasn’t even a hacked bridge. Someone took control of the staking contract’s administrative permission, and from there sold the stolen tokens. No broken cryptography—just poorly secured permission management.
This is a direct continuation of what we saw with Ostium a week ago. Three weeks in a row—three different ways of saying the same thing: the code of smart contracts is no longer the weak link in DeFi. Private keys and administrative permissions are, and this problem isn’t solved with a Solidity audit.
Do you trust a protocol with its own bridge more, or one that uses an established bridge? 👇
#DeFiSecurity #Arbitrum #CrossChainBridges #Blockaid