An everyday-use encrypted card turns into an unusable piece of plastic after an attack—and that gap itself is information.

After relevant platforms confirmed that the cross-chain bridge contract had been attacked, they paused transfers, withdrawals, and card payments. On-chain records show that about $1.83 million in stablecoins were transferred out from its Ethereum contract. The platform said it is investigating and promised to share further updates later; for now, users cannot access funds through the original channels.

The scope of the pause is noteworthy. Most platforms, when something goes wrong, only freeze on-chain transfers. This time, even card purchases were halted as well, indicating that the fund channel and the payment channel share the same ledger. If any part is breached, the entire service becomes unusable, and the time to restore it is hard to guarantee in advance.

For users, what this kind of incident reveals is the custodial structure. A card balance looks like a bank deposit, but in fact it depends on the platform’s own contracts and settlement arrangements. Once the contract is compromised, what users can do is only wait for recovery—not receive compensation from deposit protection. The two are fundamentally different in nature.

The industry takeaway is clear. Cross-chain bridges remain the most heavily targeted component. Products that put payments, settlement, and bridging into the same system will have their risk exposure merged and amplified. A distributed design is therefore more effective than pursuing remedies afterward—and it’s also more worth having written into the solution at the architecture stage.

When the card won’t work, the risk becomes visible.

#跨链安全 #支付