7OrStone

Market Prices

BTC Bitcoin
$65,411.8 +1.63%
ETH Ethereum
$1,945.76 +3.79%
SOL Solana
$76.54 +2.90%
BNB BNB Chain
$575.8 +1.09%
XRP XRP Ledger
$1.11 +1.22%
DOGE Dogecoin
$0.0732 +1.51%
ADA Cardano
$0.1660 +0.67%
AVAX Avalanche
$6.73 -0.90%
DOT Polkadot
$0.8294 +1.60%
LINK Chainlink
$8.77 +4.62%

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$65,411.8
1
Ethereum ETH
$1,945.76
1
Solana SOL
$76.54
1
BNB Chain BNB
$575.8
1
XRP Ledger XRP
$1.11
1
Dogecoin DOGE
$0.0732
1
Cardano ADA
$0.1660
1
Avalanche AVAX
$6.73
1
Polkadot DOT
$0.8294
1
Chainlink LINK
$8.77

🐋 Whale Tracker

🔴
0x58c1...10ec
12h ago
Out
2,875 ETH
🔴
0x8725...27c1
30m ago
Out
4,966,409 USDC
🟢
0xc012...ed2b
6h ago
In
3,201 ETH

The Bridge Trilemma: When Bounties Become Ransomware

Magazine | 0xCred |

Three bridges drained in 24 hours. Total losses: $35 million. Cumulative annual damage: $329 million. The chart shows growth. The ledger shows theft.

The Bridge Trilemma: When Bounties Become Ransomware

This is not a single hack. It is a systemic failure of governance, key management, and incentive design. Verus, AFX, and BSquared – each with a different architecture, but a shared vulnerability: they trusted centralised logic to guard decentralised value. And the market is now pricing in that trust as a liability.

Context: The Three Victims

Verus Bridge – a cross-chain bridge on Arbitrum and BNB Chain. On May 8, it lost $5 million. The attacker returned 75% after a 25% bounty was offered. On July 2, it lost another $7 million. Same root cause: defective cross-chain import validation. The fix was cosmetic.

AFX Bridge – a 5-of-7 multisig bridge connecting Arbitrum. On July 1, $24 million vanished. The attacker used an authorised validator key to sign malicious messages. The project paused the bridge and proposed a 30% bounty for return.

BSquared – a Bitcoin Layer 2 on BNB Chain. On July 2, an attacker gained unauthorised access to the staking contract upgrade rights. They minted 8.59 million B2 tokens, swapped them for WBNB, and drained the pool of $3.86 million. The team promised compensation but refused to pay a bounty.

Core Insight: The On-Chain Evidence Chain

Trace the ghost in the machine. Each attack shares a forensic signature: the attacker exploited privileged access points, not novel cryptographic flaws. Verus’s bridge logic allowed forged cross-chain messages. AFX’s multisig approved transactions without verifying intent. BSquared’s upgrade function was callable by a key that had been active for over a year – a key that, according to Specter’s analysis, may have belonged to an internal actor.

Data doesn't lie. The Verus attacker reused the same exploit pattern twice. After the first hack, the team issued a partial fix but never rewrote the core validation logic. The result: a 75% return didn't signal good faith. It signalled reconnaissance. The second attack was a surgical removal of the remaining liquidity.

The image is innocent; the metadata confesses. AFX’s transaction logs show the attacker calling verifyMessage() with a signature that matched a known validator. The validator key was not stolen from a hardware module – it was used from a wallet that had previously interacted with the project’s deployer address. Coincidence? Forensics say no.

BSquared raises the most uncomfortable question. The privileged role that executed the upgrade had been dormant for over a year. It was not a new compromise. It was a sleeper cell. Internal actor? Perhaps. But even if external, the implication is clear: permissioned systems rot from within when access control is not rotated, monitored, or revoked.

The Bridge Trilemma: When Bounties Become Ransomware

Forensic architecture reveals the architect. The architect here is not a person but a paradigm: the belief that a multisig and a smart contract audit are sufficient to secure billions. They are not. SlowMit audited Verus. BlockSec audited AFX. PeccShield tracked BSquared. The audits identified the bugs but did not prevent the attacks. Why? Because auditors test code, not governance. They verify logic, not key hygiene.

Contrarian Angle: Bounties Are Not the Problem – They Are a Symptom

The article asks: "Are bounties inviting more hacks?" I argue the inverse. Bounties reveal a deeper sickness: the absence of systemic risk preemption. When a project pays 30% of stolen funds to an attacker, it admits it cannot protect user assets. The bounty is a bandage on a haemorrhage.

But correlation ≠ causation. Verus’s first bounty did not cause the second hack. The second hack happened because the underlying bug was not fixed. AFX’s 30% bounty did not incentivise the attack; the attacker likely knew the vulnerability existed and exploited it before any bounty could be negotiated. Bounties are a reaction, not a root cause.

Yet the optics are damaging. High bounties may attract copycat attacks from actors who see negotiation as a profit centre. And when projects offer bounties without reporting to law enforcement, they risk violating anti-money laundering rules – especially if the attacker uses Tornado Cash, as the Verus attacker did.

The real contrarian takeaway: the market should not reward bounties. It should reward protocols that never need them. Bounties signal weak governance. Investors who hold tokens of projects that have been hacked or that rely on bounty-based recovery are holding a depreciation asset. The next signal will be a project that refuses to pay a bounty and instead coordinates with law enforcement. That will be the mark of a mature protocol.

Takeaway: Next-Week Signal

Monitor Verus, AFX, and BSquared’s next moves. If they issue a post-mortem that admits architectural failure and commits to a trust-minimised redesign (e.g., zkBridge) – that is a buy signal for the broader ecosystem. If they offer more bounties or blame the attackers without changing code – that is a sell signal for the entire L2 bridge narrative.

Yields decay, but the logic remains immutable. The logic here is that centralised bridges are dead ends. The market will reprice them to zero. The next hot sector will be zk-native bridges and shared sequencers that remove the privilege layer. Until then, trace the wallet, trust nothing.

This is not FUD. It is forensics. And the data speaks clearly: the architecture of trust is broken. We are now rebuilding it, one transaction at a time.

Fear & Greed

26

Fear

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x5f0d...d3b8
Experienced On-chain Trader
-$0.4M
79%
0xf25d...5c6c
Market Maker
+$2.1M
89%
0xe5ba...3f31
Early Investor
-$0.9M
85%