Over the past 24 hours, three separate bridge attacks drained $35 million from Verus, AFX, and BSquared. The raw numbers are alarming, but the real story is the repetition: Verus Bridge got hit with the same flawed cross-chain import validation vulnerability twice in two months. That is not a hack. That is a pattern. And it tells us something deeper about how DeFi treats security as a one-time expense rather than a continuous discipline.
To understand why this keeps happening, you have to look past the headlines. Verus Bridge was first exploited in May – hackers made off with a significant sum, and the team retrieved 75% of the funds via a 25% bounty. They deployed a fix, or so they claimed. By July, attackers found the same backdoor, exploiting the identical flawed import validation logic. Meanwhile, AFX Bridge fell to a compromised 5-of-7 validator key – a sign of centralized privilege rather than cryptographic failure. And BSquared saw an unauthorized access to its staking contract upgrade function, leading to 8.59 million B2 tokens dumped onto the market. Three bridges, three failures, one common root: weak assumptions about who can be trusted.
The narrative around bounties has now shifted. What was once seen as a white-hat safety valve is increasingly viewed as an invitation to attack. Taylor Monahan and others have openly questioned whether 25-30% retrieval bounties create a moral hazard – they turn security incidents into negotiation tables. But blaming the bounty alone misses the point. The real problem is that these projects built their security models around static audits and centralised control, then treated a bounty as a silver bullet. I have spent years tracking narrative velocity in this space, and what I see is a market that has already discounted these protocols. The sentiment is not fear; it is exhaustion. Liquidity is fleeing to trust-minimized alternatives like LayerZero and native ZK-rollup bridges, not because they are perfect, but because they at least admit that no single authority should hold the keys.
The technical commonalities are striking. Verus relied on a multi-sig bridge with flawed verification logic – a classic 'security through obscurity' approach that fails when the obscurity is removed. AFX's 5-of-7 validator set sounds robust, but any 3-validator collusion (or key compromise) breaks the system. BSquared's upgrade permissions were a single point of failure, and the attacker had access for over a year, according to Specter's investigation. Reading between the code to find the human story, these are symptoms of a governance failure: teams that do not rotate privileges, that do not simulate worst-case scenarios, and that treat security audits as a compliance checkbox rather than a living process. My own experience from the DeFi Summer of 2020 taught me that social cohesion is more resilient than any smart contract. Here, the social fabric is torn – users who lost money on Verus twice will not return.
Now the contrarian angle. You might think these attacks are pure negatives for DeFi. I see something different: they are forcing a necessary evolution. The bridge sector has been coasting on hype for years. Every exploit accelerates the migration to trust-minimized architectures, which ultimately strengthens the entire ecosystem. The bounties, despite their flaws, have exposed a deeper blind spot: we have been rewarding attackers instead of rewarding proactive defense. The market is already pricing this in. Look at the price action of B2 – the attacker sold into thin liquidity, causing a 15% drop. That is a market signal that the project had no depth, no real value backing the token. The real opportunity lies not in betting against these bridges, but in anticipating the next narrative shift: from 'bridge security' to 'operational security' – real-time monitoring, time-locked upgrades, multi-party computation for key management.
I am unearthing value where others see only chaos. The chaos is data. These attacks tell us that the most vulnerable protocols are those that rely on centralised privilege without continuous oversight. The next cycle will reward projects that treat security as an ongoing narrative – one that is told through transparent governance, regular stress tests, and a culture of paranoia rather than optimism. The takeaway is not to fear bridges, but to demand that they be built with the expectation of failure. The question remains: will the industry learn from this echo chamber of repeated mistakes, or will it just write another cheque to the next attacker?