ACCEPT CRYPTO AND PAY YOUR TEAM OR CONTRACTORS.

Issue crypto card to cover infra costs: servers, hotels, flights etc

LEARN MORE

ACCEPT CRYPTO AND PAY YOUR TEAM OR CONTRACTORS.

Issue crypto card to cover infra costs: servers, hotels, flights etc

LEARN MORE

DeFi Bridge Exploits Continue

Introduction: A Challenging Week for Cross-Chain Bridges

This week, several high-profile exploits struck the decentralized finance (DeFi) ecosystem, focusing on cross-chain bridges such as Verus-Ethereum, Wanchain Cardano, and TeleSwap. Together, these incidents led to the loss of over $17 million in digital assets. The recurrence and variety of these attacks have brought renewed attention to the security challenges and transparency issues that continue to affect bridge protocols, reinforcing the need for ongoing vigilance and improved risk management across the sector.

Verus-Ethereum Bridge: Repeat Exploit Reveals Persistent Flaws

The Verus-Ethereum Bridge suffered its second major exploit in just two months, with attackers draining approximately $7.54 million in assets, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Investigators found that the attacker manipulated the bridge’s import path, allowing unbacked payouts on Ethereum. Notably, this exploit targeted the same contract and vulnerability class as a previous $11.5 million incident in May, though it was executed by a different party using a new wallet. Despite earlier remediation efforts and a partial fund recovery through a white-hat arrangement, the recurrence of this exploit demonstrates how certain vulnerabilities can persist and be re-exploited. The conversion of stolen assets to ETH in both attacks highlights the challenges of tracking and recovering funds once they leave the bridge ecosystem.

Wanchain Cardano: Signature Weakness Results in Major Token Loss

Wanchain’s Cardano bridge was exploited for approximately 515 million NIGHT tokens, the native asset of the Midnight privacy blockchain. Early analysis suggests the vulnerability may have stemmed from non-injective encoding in the TreasuryCheck validator, which could allow attackers to reuse signed messages and launch signature replay attacks. This flaw undermined the security of the bridge treasury and enabled the rapid withdrawal of assets. The aftermath was immediate: NIGHT’s price dropped over 30 percent intraday, reaching a record low, and the value of the drained tokens was estimated at around $9 million. The incident illustrates the particular risks associated with bridging assets from privacy-focused or experimental chains, where validator logic may introduce unexpected weaknesses.

TeleSwap: Lack of Disclosure Raises Transparency Concerns

TeleSwap, another cross-chain bridge, reportedly lost $735,000 in an exploit on July 15. What distinguishes this case is the absence of any public acknowledgment from the TeleSwap team, even several days after the suspicious outflows were detected. Following the exploit, TeleSwap’s Bitcoin hot wallet stopped processing transactions, and the attacker transferred the stolen funds into Tornado, a popular mixing service, further complicating any recovery efforts. The delay in disclosure has raised concerns about user protection and the overall transparency of bridge operators. When teams fail to promptly inform users about security incidents, it leaves users exposed to ongoing risks and can erode trust in cross-chain infrastructure. This situation highlights the need for clear and timely communication when incidents occur.

Industry Patterns: Security Gaps and Communication Failures

While each exploit had its own technical cause, a clear pattern has emerged: cross-chain bridges remain attractive targets for attackers, and their complex architectures make them difficult to secure. The recurrence of similar vulnerabilities, as seen with the Verus-Ethereum Bridge, and the emergence of signature-based flaws, as in the Wanchain Cardano case, indicate that validation and patching practices across the industry are still evolving. Transparency is also a pressing issue. The delayed response from TeleSwap shows that not all teams are equipped to communicate about major incidents in a timely manner, which can leave users in the dark and at risk. These events underscore the importance of standardized incident reporting and thorough post-incident analysis to improve both protocol resilience and user safety.

What Users Should Watch Next

This week’s events reinforce the need for careful due diligence when moving assets across chains. Users should assess not only the technical security of bridges but also how transparent and responsive the teams are when issues arise. As cross-chain activity remains central to DeFi, the sector will likely face increased scrutiny over how bridges manage security incidents and communicate with their communities. For those planning cross-chain transactions, it is essential to compare available routes and review the security track record of each bridge. To find efficient and secure onchain paths for your next move, visit the Chainspot router to compare bridge options and check for the latest updates.

Rate this article
( No ratings yet )
Chainspot News
Add a comment