Loading prices…
🩸BEARISH

Ethereum Bridges Lose $31.7M in Hours as Third Protocol Halts

The $31.7M drained from two bridges is the headline; the third protocol pulling staking is the broader signal that DeFi is treating post-exploit contagion as the real threat.

Two Ethereum bridges lost a combined $31.7M within hours of each other, while a third DeFi protocol independently halted staking in what operators are calling a coordinated stress response rather than a coincidence.

Why it matters

Bridge exploits have been the single most expensive category of DeFi attack over the last cycle, and two near-simultaneous compromises on Ethereum-linked infrastructure break the assumption that incidents are isolated events. Separately, a new malware campaign targeting crypto developers shows attackers now moving upstream, stealing GitHub tokens, SSH keys, cloud credentials, wallets, and environment variables before a protocol ever ships vulnerable code. The combination suggests the threat model has shifted from deployed contracts to developer machines and cross-chain infrastructure simultaneously.

Market impact

The third protocol's decision to pause staking rather than absorb the contagion risk signals how seriously DeFi teams are now treating post-exploit blast radius. With $31.7M already drained, the cost of a single weak link in bridge architecture is again being repriced, and staking desks across Ethereum-linked protocols will be watching for copycat pause announcements through the week.

Related tokens
$ETH

Frequently asked questions

  1. Which Ethereum bridges lost the $31.7M?

    The seed reports a combined $31.7M drained from two Ethereum bridges within hours, but does not name the specific bridge protocols. Details on the affected venues are pending on-chain confirmation.

  2. Why did the third protocol halt staking?

    A third DeFi protocol paused staking as a preemptive containment step rather than a confirmed exploit on its own contracts, treating cross-protocol contagion from the two bridge drains as the primary risk.

  3. How does the new malware campaign target crypto developers?

    Researchers say the campaign steals GitHub tokens, SSH keys, cloud credentials, wallets, and environment variables from developer machines, allowing attackers to compromise code before it is deployed rather than exploiting contracts after launch.

  4. What is the market impact of these incidents?

    The combined signal is a repricing of bridge and cross-chain risk. With $31.7M drained and a third protocol voluntarily pausing, desks across Ethereum-linked DeFi are reassessing blast radius and the cost of a single weak infrastructure link.

  5. Are these incidents connected?

    The two bridge drains occurred within hours and the third protocol's staking pause followed closely, but the seed does not confirm a coordinated exploit. The malware campaign against developers is a separate, parallel threat vector reported in the same window.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →