Two bridge exploits, one lesson: crypto exchange infrastructure still needs tighter controls

A pair of bridge attacks that reportedly drained more than $31.6 million in seven hours is a reminder that exchange, settlement, and treasury workflows need strong controls around asset movement.

Radom Insights

Two bridge exploits, one lesson: crypto exchange infrastructure still needs tighter controls

Crypto markets got another reminder this week that bridge design and asset movement controls still matter as much as trading logic. Cointelegraph reported that hackers stole more than $31.6 million in two unrelated bridge exploits within seven hours, with AFX reportedly losing $24.15 million and the Verus Ethereum bridge attacked later the same day. The report described AFX as a decentralized perpetual exchange operating on Arbitrum. Cointelegraph

The immediate issue is not just theft. It is how quickly a weakness in cross-chain infrastructure can turn into a balance, settlement, and liquidity problem for the teams running the platform. Bridges sit between assets, wallets, and chains, so they often become the point where operational assumptions break down. When something goes wrong there, the impact can spread beyond the protocol itself into user withdrawals, treasury planning, and reconciliation.

That is why the quote from the report matters. Cointelegraph said the incidents were "two unrelated crypto bridge exploits" Cointelegraph. Unrelated attacks in a short window do not prove a single systemic flaw, but they do show that bridge risk is still a live category for any business moving value across chains.

For exchanges, platforms, and payment operators, the practical lesson is simple. Asset movement should be treated as an operational control surface, not just a backend convenience. Teams need clear limits on where funds can move, who can approve transfers, how settlement is recorded, and what happens when a conversion path fails or is compromised. The more steps a workflow takes between receipt and final settlement, the more important visibility becomes.

This is especially relevant for businesses that use crypto conversion as part of normal operations. A platform may accept digital assets, convert part of the balance, and settle the rest into another asset or fiat currency. That is a useful workflow when it is controlled, but it also creates exposure to liquidity, routing, and reconciliation issues if the rails are fragmented. A single incident in the conversion layer can slow payouts, complicate treasury management, or force manual intervention at the worst possible time.

That is the broader market context behind Radom’s crypto conversion tooling. Radom positions its crypto convert workflow around moving between cryptocurrencies and settling in the asset a business needs, which is the kind of control finance and operations teams look for when they are managing exchange, treasury, and settlement in one place. The point is not speculation. It is reducing the number of disconnected systems involved in moving value.

Security and resilience also affect customer trust. Users rarely care about the mechanics of a bridge until withdrawals are delayed or balances look wrong. Once that happens, the platform has to explain whether funds are safe, whether conversion is paused, and when normal operations will resume. In practice, the best risk management is the kind customers never notice because it is built into the workflow from the start.

The latest bridge attacks will probably not be the last. For operators, the useful response is not to avoid exchange or conversion altogether. It is to design those flows with tighter permissions, clearer settlement records, and fewer moving parts than the average ad hoc crypto stack. In a market where a few hours can separate one exploit from another, that discipline is becoming a competitive advantage.

Sources

Exploring how this affects your operating model?

Sign up to Radom to get started