Two bridge failures have exposed about $31.7 million in losses, while B² Network has halted staking after an unauthorized party accessed a key upgrade control. The practical message is blunt: moving assets between chains, or locking tokens for yield, still carries risks that sit outside Ethereum itself.
AFX, a decentralized trading protocol on Arbitrum, said attackers took 24.15 million USDC from its third-party custody bridge. Its preliminary account points to social engineering that began in a development environment and reached internal build and validator systems. AFX says its trading infrastructure, mainnet and Arbitrum’s native bridge were not affected, but the recovery and compensation outcome remains unresolved.
Hours later, the Verus-Ethereum bridge released roughly $7.54 million in ETH and tokens without matching reserves. Security analysis cited by CryptoSlate says eight withdrawals were approved without proof that the assets were actually backed. Separately, B² suspended normal staking after unauthorized access to its staking contract’s upgrade authority. Users seeking to leave must use a manual, ownership-verified exit process while the review continues; B² has promised compensation but has not reported a loss figure or completed restitution.
This is downside and risk-management news, not an Ethereum-wide failure. It matters most to users holding bridged stablecoins, cross-chain assets or staked B² tokens, and to builders relying on upgrade keys and off-chain operational systems. The incidents show that a secure base chain cannot protect funds when bridge accounting, employee access or administrator controls fail.
