Three bridges drained in 24 hours. Total losses: $35 million. Cumulative annual damage: $329 million. The chart shows growth. The ledger shows theft.

This is not a single hack. It is a systemic failure of governance, key management, and incentive design. Verus, AFX, and BSquared – each with a different architecture, but a shared vulnerability: they trusted centralised logic to guard decentralised value. And the market is now pricing in that trust as a liability.
Context: The Three Victims
Verus Bridge – a cross-chain bridge on Arbitrum and BNB Chain. On May 8, it lost $5 million. The attacker returned 75% after a 25% bounty was offered. On July 2, it lost another $7 million. Same root cause: defective cross-chain import validation. The fix was cosmetic.
AFX Bridge – a 5-of-7 multisig bridge connecting Arbitrum. On July 1, $24 million vanished. The attacker used an authorised validator key to sign malicious messages. The project paused the bridge and proposed a 30% bounty for return.
BSquared – a Bitcoin Layer 2 on BNB Chain. On July 2, an attacker gained unauthorised access to the staking contract upgrade rights. They minted 8.59 million B2 tokens, swapped them for WBNB, and drained the pool of $3.86 million. The team promised compensation but refused to pay a bounty.
Core Insight: The On-Chain Evidence Chain
Trace the ghost in the machine. Each attack shares a forensic signature: the attacker exploited privileged access points, not novel cryptographic flaws. Verus’s bridge logic allowed forged cross-chain messages. AFX’s multisig approved transactions without verifying intent. BSquared’s upgrade function was callable by a key that had been active for over a year – a key that, according to Specter’s analysis, may have belonged to an internal actor.
Data doesn't lie. The Verus attacker reused the same exploit pattern twice. After the first hack, the team issued a partial fix but never rewrote the core validation logic. The result: a 75% return didn't signal good faith. It signalled reconnaissance. The second attack was a surgical removal of the remaining liquidity.
The image is innocent; the metadata confesses. AFX’s transaction logs show the attacker calling verifyMessage() with a signature that matched a known validator. The validator key was not stolen from a hardware module – it was used from a wallet that had previously interacted with the project’s deployer address. Coincidence? Forensics say no.
BSquared raises the most uncomfortable question. The privileged role that executed the upgrade had been dormant for over a year. It was not a new compromise. It was a sleeper cell. Internal actor? Perhaps. But even if external, the implication is clear: permissioned systems rot from within when access control is not rotated, monitored, or revoked.

Forensic architecture reveals the architect. The architect here is not a person but a paradigm: the belief that a multisig and a smart contract audit are sufficient to secure billions. They are not. SlowMit audited Verus. BlockSec audited AFX. PeccShield tracked BSquared. The audits identified the bugs but did not prevent the attacks. Why? Because auditors test code, not governance. They verify logic, not key hygiene.
Contrarian Angle: Bounties Are Not the Problem – They Are a Symptom
The article asks: "Are bounties inviting more hacks?" I argue the inverse. Bounties reveal a deeper sickness: the absence of systemic risk preemption. When a project pays 30% of stolen funds to an attacker, it admits it cannot protect user assets. The bounty is a bandage on a haemorrhage.
But correlation ≠ causation. Verus’s first bounty did not cause the second hack. The second hack happened because the underlying bug was not fixed. AFX’s 30% bounty did not incentivise the attack; the attacker likely knew the vulnerability existed and exploited it before any bounty could be negotiated. Bounties are a reaction, not a root cause.
Yet the optics are damaging. High bounties may attract copycat attacks from actors who see negotiation as a profit centre. And when projects offer bounties without reporting to law enforcement, they risk violating anti-money laundering rules – especially if the attacker uses Tornado Cash, as the Verus attacker did.
The real contrarian takeaway: the market should not reward bounties. It should reward protocols that never need them. Bounties signal weak governance. Investors who hold tokens of projects that have been hacked or that rely on bounty-based recovery are holding a depreciation asset. The next signal will be a project that refuses to pay a bounty and instead coordinates with law enforcement. That will be the mark of a mature protocol.
Takeaway: Next-Week Signal
Monitor Verus, AFX, and BSquared’s next moves. If they issue a post-mortem that admits architectural failure and commits to a trust-minimised redesign (e.g., zkBridge) – that is a buy signal for the broader ecosystem. If they offer more bounties or blame the attackers without changing code – that is a sell signal for the entire L2 bridge narrative.
Yields decay, but the logic remains immutable. The logic here is that centralised bridges are dead ends. The market will reprice them to zero. The next hot sector will be zk-native bridges and shared sequencers that remove the privilege layer. Until then, trace the wallet, trust nothing.
This is not FUD. It is forensics. And the data speaks clearly: the architecture of trust is broken. We are now rebuilding it, one transaction at a time.