DeFi Hacking Spree Claims $35M in One Day: Are Bounties to Blame?
Another wave of hacking has swept through the decentralized finance (DeFi) space, claiming over $35 million in just one day. The attacks targeted various platforms, including Verus bridge and AFX's USDC custody bridge on Arbitrum.
The latest victim was Verus bridge, which lost over $7.5 million, just two months after being hit by a similar hack that claimed $11 million. Following the return of 75% of the funds lost in May's hack, the assets were sent from the recovery address back into the Verus bridge just 14 days ago.
According to blockchain auditor SlowMist, both exploits share a root cause of 'flawed cross-chain import validation,' though with slightly different attack vectors. This time it looks less likely that Verus will see the money again, as the attacker has since deposited a total of 3,916 ETH (over $6.6 million) to Tornado Cash.
AFX's USDC bridge was also drained of over $24 million due to 'malicious use of authorized validator keys.' The security firm BlockSec believes this is a 'malicious use of authorized validator keys,' which were used to sign 'the bridge's 5-of-7 validator quorum.'
AFX has offered a 30% bounty, worth $7.2 million, for the return of the remaining funds, 'as a white hat bounty.' However, security expert Taylor Monahan questions the wisdom of such a move.
The recent hacking spree has left many wondering if 'bounties' are inviting more hacks. In an increasingly bleak landscape for legitimate security researchers, generous offers like AFX's may even tempt those with such skills to the dark side.




