Crypto bridge hacks and key/upgrade exploits drain $35M+ to $770M YTD
Crypto bridge hacks are again showing up as a persistent cross-chain risk. A report citing CoinDesk and security firms (BlockAid, PeckShield) says at least three bridges/cross-chain protocols were drained in a six-hour window for $35M+.
Crypto bridge hacks did not break Bitcoin or Ethereum cryptography. The newer cases mainly involved compromised keys/permissions that control withdrawals or contract upgrades:
- Verus (Ethereum-linked bridge): ~$7.54M lost (ETH, tBTC, and stablecoins). Attackers reused the same bridge contract and entry path as a prior May incident (~$11.5M). After the earlier attack, funds were partially returned via a bounty, but Verus redeposited on July 8 and was hit again two weeks later.
- B² Network: ~$3.86M lost after attackers seized staking-contract upgrade authority. B² suspended staking and said it will fully compensate affected users.
This fits a broader pattern from earlier reporting: bridge hacks were a major threat in May and contributed to rising totals—Q1 was contained (~$169M) but YTD is near $770M. Earlier biggest-ticket events included THORChain (~$10M), Verus–Ethereum Bridge (~$11.4M), Gravity Bridge (~$5.4M), and IoTeX Bridge (~$8.8M), plus the April KelpDAO/LayerZero loss (around $292M).
Trading impact: repeated crypto bridge hacks can lift risk-off sentiment toward cross-chain assets, reduce liquidity in connected DeFi routes, and increase short-term volatility for tokens tied to the affected ecosystems.
Bearish
Short-term, repeated crypto bridge hacks concentrated within hours can quickly change sentiment. Traders may price in higher protocol-risk premia for cross-chain tokens, widen spreads, and rotate liquidity away from DeFi routes that depend on the compromised bridges.
For the specific cases, the key/upgrade-permission angle matters: it suggests governance/operational weaknesses are exploitable, so even “resolved” incidents can recur if the same bridge configuration or permissions are reused (as shown by Verus’s re-deposit and subsequent second drain). This increases the probability of additional surprises and makes rallies in affected ecosystems more fragile.
Long-term, the pattern across months (May bridge losses, earlier April mega-losses, and past permission-driven incidents like Wormhole/Nomad) reinforces that bridge hacks remain an ongoing category risk rather than a one-off. That backdrop typically supports a cautious, risk-managed positioning stance until stronger architectural controls and reduced funds-in-contract practices become more widespread.