Loading prices…
STKR NewsSTKR News0 of 3 free this month
Markets

Two Ethereum bridges lose $31.7M within hours as third protocol halts staking

A brutal 24-hour stretch for Ethereum bridges and staking protocols reveals the persistent danger of centralized control in a supposedly decentralized industry.

Originally on CryptoSlate
AB

Adrian Boysel

Contributor

Jul 25, 2026

5 min read

Photo illustration / STKR News

We talk a lot about the future of finance and the sovereignty of code, but every few months, reality decides to punch us in the gut. In a span of just a few hours, the brittle nature of our cross-chain infrastructure was laid bare again. Between the LiFi and Orbit Chain exploits, we are looking at over $31 million vanishing into the ether. Meanwhile, B² Network had to hit the emergency brakes on its staking. It is a messy reminder that if you are building on top of these protocols, you are often building on a foundation of faith rather than math.

The Multi-Sig Problem Strikes Again

Let's look at the numbers. The recent drain on LiFi and Orbit Chain totaled roughly $31.7 million. For those of us in the trenches, these aren't just figures on a spreadsheet. They represent the erosion of user trust and the failure of basic security assumptions. The LiFi exploit specifically targeted an aggregation contract. It wasn't a complex cryptographic failure; it was an exploit of a specific function that allowed the attacker to drain assets from users who had previously granted infinite approvals to the contract.

This is a recurring nightmare for developers. We build these elegant front-ends, but the underlying plumbing often relies on permissions that users don't fully understand and developers don't always restrict properly. If your protocol requires a user to sign off on an infinite spend limit, you are essentially asking them to hand over the keys to their vault and hope the security guard doesn't fall asleep. In this case, the guard didn't just fall asleep; they left the front door propped open with a brick.

The Orbit Chain Hangover

Then we have Orbit Chain. This is a different flavor of failure but equally sour. The bridge was hit for about $26 million in a series of coordinated transactions. The pattern suggests an exploit of the bridge's validation logic or a compromise of the private keys governing the bridge's vault. When you look at the flow of funds, it follows the standard North Korean hacker playbook: fast movement, splitting of assets, and an immediate run for the mixers.

For builders, this is the part that should keep you up at night. We are creating these massive honeypots. A bridge is fundamentally just a locked box sitting in the middle of a digital highway. The bigger the bridge grows, the more incentive there is for the best hackers in the world to spend months looking for a single crack. Orbit Chain's loss is a signal that even established cross-chain players are struggling to secure the vaults they have built.

Why B² Network Had to Stop

While the bridges were burning, B² Network decided to stop the clock. They suspended their staking activities on July 22, citing a need to move toward a more decentralized governance model. On the surface, it looks like a proactive move. In reality, it highlights the 'training wheels' problem deeply embedded in Layer 2 and Bitcoin-adjacent protocols. If you can simply flip a switch and stop the protocol, is it actually a protocol or just a managed service?

I have a bit of a skeptical take on this. Halting a protocol to 'improve decentralization' is an oxymoron. It shows that the centralized controls are currently so absolute that the team can pause the movement of capital at will. For founders, this is the ultimate trade-off: do you launch with a centralized kill-switch for safety, or do you launch fully decentralized and risk a fatal exploit that you can't stop? B² chose the former, and while it might save them from a hack today, it reminds everyone that their assets are still under a central team's thumb.

The Developer's Dilemma

If you are building in this space right now, you have to ask yourself a hard question: what are you actually inheriting when you integrate with a bridge? When you use an aggregator like LiFi, you aren't just using their code. You are inheriting their security debt, their contract permissions, and their human risks. The industry spends millions on audits, yet we keep seeing the same types of failures:

  • Contract logic errors that allow unauthorized withdrawals.
  • Overly broad user permissions (the infinite approval trap).
  • Centralized multi-sigs that act as a single point of failure.

The honest truth is that 'bridge' is becoming a dirty word. We have tried to solve the fragmentation of liquidity by creating more bridges, but all we have done is create more points of failure. As a founder, I would be looking very closely at how to minimize bridge dependency. The cost of 'convenient' liquidity is becoming too high.

A Reality Check on Security

We need to stop pretending that an audit is a shield. An audit is a snapshot of a moment in time. Both LiFi and Orbit have had eyes on their code before. The problem isn't just the code; it is the complexity. The more chains we try to connect, the more edge cases we create. Every time a new token standard or a new Layer 2 is added, the attack surface grows exponentially.

The B² situation is a different kind of warning. It’s a warning about transparency. If your protocol is centralized, say so. Don't wait until you have to halt the network to talk about your path to decentralization. Builders who are honest about their limitations tend to survive longer because their users understand the risks they are taking. We need fewer 'decentralized' labels and more 'experimental' labels.

What This Means for the Builders

If you are currently launching a project, don't just follow the trend of integrating every bridge possible. Every integration is a liability. Focus on security-first design where user funds aren't sitting in a single, massive smart contract that acts as a beacon for every malicious actor from Pyongyang to Moscow.

The most secure bridge is the one you don't build. If you must build one, don't assume your job is done once the code is live.

We are seeing a shift in the market. Users are starting to realize that the 'yield' they get from staking or bridging isn't worth the risk of losing their entire principal. As builders, our job isn't just to make things work; it is to make things robust. That means moving away from the 'move fast and break things' mantra, because in crypto, when you break things, people lose their life savings.

The Takeaway

The loss of $31.7 million in a single afternoon isn't just bad luck. It is the result of a system that prioritizes speed and liquidity over fundamental safety. For founders, the lesson is clear: audit your dependencies as much as you audit your own code. If you are relying on a bridge or a third-party staking protocol, you are only as secure as their weakest multi-sig. The training wheels on these protocols are starting to feel less like safety features and more like structural flaws. It is time to get honest about the risks of the tech we are building.


Read the original at CryptoSlate →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses