TLDR
- Two independent crypto bridge breaches resulted in combined losses exceeding $31.6 million during a seven-hour period on July 22ā23, 2026
- AFX Trade suffered a $24.15 million loss when threat actors gained control of validator signing keys on its Arbitrum-based bridge infrastructure
- The Verus Ethereum Bridge experienced a $7.5 million drain utilizing an identical exploit technique previously deployed in May 2026
- Arbitrum developers verified that the network’s core bridge infrastructure remained secure ā breaches affected only third-party protocol implementations
- The bulk of AFX’s stolen assets were liquidated into approximately 12,467 ETH and consolidated into a single address
During a concentrated seven-hour window spanning July 22ā23, 2026, two distinct cryptocurrency bridge protocols fell victim to sophisticated exploits that collectively drained over $31.6 million in digital assets.
The more substantial breach targeted AFX Trade, a decentralized perpetual futures platform operating on the Arbitrum network and conducting settlements in USDC. On-chain forensic analysis reveals that malicious actors successfully obtained the private validator signing keys responsible for authorizing fund withdrawals across AFX’s bridging infrastructure.
The attacker secured approval signatures from five hot-validator nodes to execute a withdrawal of 24,150,000 USDC directly to their controlled address. This satisfied the bridge’s two-thirds consensus threshold requirement, causing the smart contract to process the transaction according to its programmed parameters.
Critically, the bridge’s underlying codebase remained intact and uncompromised. The vulnerability stemmed entirely from unauthorized access to the cryptographic keys governing bridge operations.
Timeline and Mechanics of the AFX Compromise
Blockchain security firm Blockaid identified the malicious activity at precisely 9:30 pm UTC on July 22. Following a mandatory 200-second challenge period, the stolen assets were released and immediately transferred across to Ethereum.
The perpetrator rapidly exchanged the pilfered USDC holdings for roughly 12,467 ETH, valued at approximately $24 million at current market rates. Blockchain intelligence platforms confirm these converted funds remain concentrated within a solitary wallet address.
AFX had experienced surging trading activity reaching multi-month peak volumes throughout mid-July, making the timing particularly devastating. The $24 million extraction represented nearly the protocol’s complete total value locked at the moment of attack.
Stephen Goldfeder, co-founder of Offchain Labs (the development team behind Arbitrum), issued clarification that the network’s official native bridge infrastructure remained completely unaffected. “The transaction in question originated from a third-party protocol,” he stated via X.
Secondary Exploit Targets Verus Bridge
Just hours following the AFX incident, Blockaid’s monitoring systems flagged a separate exploitation event affecting the Verus Ethereum Bridge. This secondary attack extracted approximately $7.5 million across multiple token types, including Ether, tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
According to Blockaid’s analysis, the attacker exploited the bridge’s import functionality to generate unauthorized payouts on the Ethereum network side. This methodology directly replicates a May 2026 breach of the identical bridge infrastructure that resulted in $11.58 million in losses, despite evidence pointing to a different attacker wallet in this instance.
While the two July incidents appear operationally independent, they exemplify a consistent attack vector increasingly prevalent throughout DeFi ecosystems in 2026 ā threat actors focusing on off-chain infrastructure components rather than exploiting smart contract logic vulnerabilities.
Security analyst SunSec, who founded DeFiHackLabs, attributed the AFX breach specifically to compromised cryptographic keys rather than any flaw in the protocol’s code architecture. This attack signature closely resembles the approximately $285 million Drift Protocol loss recorded in April, where malicious actors gradually accumulated privileged system access.
These bridge exploits follow closely behind an oracle manipulation attack that extracted $18 million from RWA platform Ostium merely one week prior, extending a challenging period for protocols building on Arbitrum infrastructure.
Cryptocurrency security professionals continue highlighting bridges as an enduring structural weakness. “Bridges will always be a weak link, until security is upgraded,” remarked on-chain investigator TheCrypticWolf via X.


