← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] Bridge Exploits Drain $47M in One Week, $340M YTD

Zephyra|July 26, 2026|BPF
EXECUTIVE SUMMARY

Cross-chain bridge protocols lost $47 million in confirmed exploits during the week of July 19–25, 2026, across five separate incidents targeting four distinct bridge implementations. July 23 alone saw three simultaneous attacks — dubbed "Hackers' Day" by security analysts — draining $35.55 milli...

"The $292 million Kelp DAO exploit shows why crypto bridges are still one of the industry's weakest links." — CoinDesk Editorial, April 2026

Executive Summary

Cross-chain bridge protocols lost $47 million in confirmed exploits during the week of July 19–25, 2026, across five separate incidents targeting four distinct bridge implementations. July 23 alone saw three simultaneous attacks — dubbed "Hackers' Day" by security analysts — draining $35.55 million in a single 24-hour period. The incidents bring 2026 year-to-date bridge-specific losses above $340 million across 14 confirmed attacks, according to PeckShield.

Total crypto hack losses in H1 2026 reached $972 million across 207 incidents, per TRM Labs. Bridge exploits accounted for approximately 41% of all May losses despite constituting a single attack category. The week's incidents underscore a persistent structural weakness: compromised validator keys, single-point-of-failure verification networks, and flawed message-encoding schemes — not broken cryptography — remain the dominant attack surface. North Korea-linked actors, primarily the Lazarus Group, are responsible for an estimated $643 million (66%) of all H1 2026 losses, per TRM Labs analysis.

Table of Contents

  1. The July 19–25 Exploit Timeline
  2. Attack Vector Analysis
  3. 2026 Year-to-Date Bridge Loss Data
  4. H1 2026 Aggregate Hack Statistics
  5. The White-Hat Bounty Negotiation Pattern
  6. Economic Value Implications
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The July 19–25 Exploit Timeline

Five confirmed exploits struck cross-chain bridge and DeFi infrastructure during a seven-day window. Below is the chronological sequence.

July 21 — Wanchain Cardano Bridge: $13M

An attacker exploited a non-injective signed-message encoding flaw in the Wanchain-operated bridge connecting Cardano's Midnight network and BNB Chain. According to blockchain security firm BlockSec Phalcon, the bridge created signed messages by concatenating 14 variable-length redeemer fields without separators or length identifiers. The attacker reused a legitimate signature for a larger transaction, draining 515 million NIGHT tokens. The NIGHT token fell more than 30% to a record low near $0.016. Wanchain took the bridge offline. The Midnight Foundation confirmed its core protocol was not compromised.

July 22 — B² Network Staking Contract: $3.86M

An attacker seized the upgrade authority of B² Network's staking contract, extracting 8.59 million B2 tokens. The exploiter sold all tokens for 5,409 BNB ($3.01 million), then bridged to Ethereum and swapped for ETH and USDT. Funds were routed through NEAR Intents and HOT Protocol. B² Network suspended staking operations and offered the attacker legal immunity in exchange for returning 10% of stolen funds within 24 hours.

July 23 — "Hackers' Day": $35.55M Across Three Protocols

Three separate exploits occurred within hours of each other:

  • AFX Trade Arbitrum Bridge — $24.15M: Blockchain security firm Blockaid detected the exploit at approximately 9:30 p.m. UTC on July 22. An attacker compromised enough validator signing keys to assemble the required quorum signatures, then authorized a single withdrawal of 24.15 million USDC after the bridge's approximately 200-second dispute period elapsed. The attacker bridged stolen funds from Arbitrum to Ethereum and swapped for 12,467 ETH. AFX's head of growth offered the attacker a 30% retention "white hat bounty" in exchange for returning 70%. Arbitrum's native bridge was not breached; the incident affected only AFX's third-party bridge.

  • Verus Ethereum Bridge — $7.54M: The Verus–Ethereum bridge was exploited for the second time in 66 days. The attacker used a 0.01 VRSC transaction to trigger unbacked payouts of 1,137 ETH, 71.5 tBTC, and other tokens. The same import path was weaponized in May 2026, when $11.6 million was stolen. After the May incident, the attacker returned 4,052.4 ETH (retaining a 25% bounty), and recovered funds were redeposited into the bridge on July 8. The bridge was drained again 15 days later. Combined Verus bridge losses now total $19.1 million. The July attacker has routed funds through Tornado Cash.

  • B² Network (additional impact) and Allbridge Core were also affected during this period, though the B² incident had been initiated the prior day.

July 24 — Lien Finance: $542K

Lien Finance, an Ethereum-based structured products protocol, was exploited for 542,144 USDC. The attacker manipulated pricing inside the protocol's GeneralizedDotc bond-to-ERC20 OTC pools, exploiting a protocol logic gap that permitted permissionless bond minting to bypass intended burn logic and drain live pool liquidity.

Attack Vector Analysis

The week's five incidents reveal three distinct attack classes. None involved breaking cryptographic primitives.

| Attack Class | Incidents | Combined Loss | Mechanism | |---|---|---|---| | Compromised Validator/Signing Keys | AFX Trade, B² Network | $28.01M | Attacker obtains sufficient signing authority to authorize fraudulent withdrawals | | Message Encoding / Verification Flaws | Wanchain, Verus (repeat) | $20.54M | Non-injective encoding or single-verifier configurations allow forged or replayed messages | | Smart Contract Logic Gaps | Lien Finance | $0.54M | Permissionless minting bypasses intended accounting constraints |

Compromised keys accounted for the largest single-incident loss ($24.15 million, AFX Trade). Verification flaws produced the most recurring damage — Verus was exploited twice via the same import path within 66 days. Smart contract logic gaps produced the smallest loss but demonstrated that even lower-TVL protocols face non-trivial risk.

The common thread: bridge security depends on off-chain infrastructure (key management, verifier networks, RPC node integrity) as much as on-chain code. On-chain logic at AFX "functioned as designed," per Blockaid. The failure was in the key management layer surrounding it.

2026 Year-to-Date Bridge Loss Data

PeckShield tracked $328.6 million in bridge-specific exploits through eight incidents by mid-May 2026. Subsequent incidents — including the July cluster — push the running total above $340 million across 14+ confirmed bridge attacks.

The two largest individual bridge exploits of 2026:

| Date | Protocol | Loss | Root Cause | Attribution | |---|---|---|---|---| | April 1 | Drift Protocol (Solana) | $285M | Social-engineered multisig signers; zero-timelock governance migration | Lazarus Group (TRM Labs) | | April 18 | Kelp DAO (LayerZero) | $292M | Compromised RPC nodes; 1-of-1 DVN verification | Lazarus Group (Chainalysis) |

The Kelp DAO incident was 2026's largest single DeFi exploit. Attackers compromised internal RPC nodes and DDoS'd external nodes to feed false data to a single-point-of-failure verification network (1-of-1 DVN setup). The attacker tricked LayerZero's cross-chain messaging layer into releasing 116,500 rsETH. After the initial theft, the attacker used stolen tokens as collateral on Aave to borrow an additional $236 million in ETH, amplifying downstream impact.

The Drift Protocol attack used social engineering rather than code exploits. Attackers convinced multisig signers to pre-sign hidden authorizations, then pushed a zero-timelock governance migration that removed the protocol's review window. TRM Labs identified it as the 18th DPRK-linked operation of 2026.

April 2026 became crypto's most-hacked month on record, with 30 separate incidents — nearly one per day.

H1 2026 Aggregate Hack Statistics

TRM Labs reported 207 crypto hacks in H1 2026, a record count. Total stolen funds reached $972 million — less than half the $2.3 billion stolen in H1 2025, reflecting a shift toward more frequent but individually smaller attacks.

| Metric | H1 2026 | H1 2025 | Change | |---|---|---|---| | Total incidents | 207 | ~130 (est.) | +59% | | Total losses | $972M | $2.3B | -57% | | Average loss per incident | $4.7M | $17.7M | -73% | | DPRK-attributed losses | $643M (66%) | $1.3B (57%) | -51% |

Monthly breakdown (per PeckShield):

  • January: $86M across 16 incidents
  • February: ~$26.5M
  • March: $52M across 20 incidents
  • April: $600M+ (Drift, Kelp DAO, others)
  • May: $68.3M with no single mega-hack; bridges accounted for 41% of May losses
  • June: $75.87M across 40 incidents

The data shows two dynamics operating simultaneously. The frequency of attacks has increased, but the average per-incident loss has fallen by 73%. This may reflect improved response times, smaller TVL targets, or attacker migration toward numerous mid-size protocols rather than large concentrated pools. April remains an outlier, driven by two state-sponsored operations that collectively accounted for $577 million.

The White-Hat Bounty Negotiation Pattern

Three of the five July incidents involved protocols offering attackers a percentage of stolen funds as a "white hat bounty" in exchange for returning the remainder.

| Protocol | Offer | Outcome (as of July 26) | |---|---|---| | AFX Trade | 30% retention ($7.2M) | Pending; no response from attacker | | B² Network | 10% retention (~$386K) + legal immunity | Pending; 24-hour deadline expired with no return | | Verus (May incident) | 25% retention | Accepted; 4,052 ETH returned; funds redeposited July 8 |

The Verus case is instructive. The May attacker returned funds under a 25% bounty arrangement. Those returned funds were redeposited into the bridge — and stolen again 15 days later by a different attacker. This sequence raises questions about whether bounty-funded recoveries create moral hazard when the underlying vulnerability remains unpatched, or when patching is incomplete.

According to Protos, the pattern of post-exploit bounty offers has drawn criticism from security researchers who argue it creates perverse incentives — effectively advertising that protocols will negotiate rather than pursue legal action, potentially encouraging attacks.

Economic Value Implications

From an economic value distribution perspective, bridge exploits represent a direct transfer of user deposits to attackers. Unlike protocol revenue disputes or fee structure debates, exploits create pure deadweight loss to the ecosystem.

The $340 million in bridge-specific losses YTD represents capital permanently removed from protocol liquidity pools, reducing the economic base available for legitimate transaction activity. For context, this figure exceeds the combined annual fee revenue of most Layer-2 networks.

Bridge infrastructure occupies a critical position in the cross-chain value chain. It sits between Layer-1 settlement and application-layer activity, meaning a bridge failure can cascade upstream (locking assets on source chains) and downstream (destroying collateral positions on destination chains, as seen in the Kelp DAO/Aave cascade). The economic cost of bridge failures therefore exceeds the headline theft figure.

The persistence of key management failures — rather than cryptographic breaks — suggests the industry's security investment is misallocated. Auditing smart contract code addresses only one component of bridge risk. Off-chain operational security (key storage, verifier diversity, RPC integrity) requires equivalent or greater investment but receives less systematic attention.

Key Takeaways

  • $47 million confirmed lost across five bridge/DeFi exploits during the week of July 19–25, 2026. Three occurred on a single day (July 23), which security analysts labeled "Hackers' Day."

  • $340 million+ in bridge-specific exploit losses year-to-date across 14+ incidents. Bridges accounted for 41% of all May 2026 hack losses.

  • Zero cryptographic breaks. All five July incidents stemmed from compromised keys, verification architecture flaws, or smart contract logic gaps. Off-chain infrastructure failures remain the dominant attack surface.

  • Repeat exploitation is an active risk. The Verus bridge was drained twice via the same import path within 66 days. Funds returned under a bounty arrangement after the first exploit were stolen again in the second.

  • North Korea-linked actors account for an estimated 66% ($643 million) of all H1 2026 crypto hack losses, per TRM Labs. The two largest incidents (Drift Protocol, Kelp DAO) are both attributed to the Lazarus Group.

  • White-hat bounty negotiations are now standard post-exploit protocol, with three of five July incidents involving return-of-funds offers. Efficacy is mixed. The practice draws criticism for potentially incentivizing attacks.

  • H1 2026 saw 207 hacks — a record count — but total losses ($972 million) fell 57% from H1 2025 ($2.3 billion). Average loss per incident dropped 73% to $4.7 million.

Conclusion

The week of July 19–25, 2026, concentrated the cross-chain bridge security problem into a seven-day window. Five protocols, four bridge implementations, $47 million gone. The mechanisms were not sophisticated cryptographic attacks. They were compromised keys, flawed message encoding, and unpatched vulnerabilities exploited a second time.

The data pattern across H1 2026 is clear: attacks are more frequent, individually smaller, and operationally focused. The two exceptions — Drift Protocol ($285 million) and Kelp DAO ($292 million) — were both attributed to state-sponsored actors who targeted off-chain infrastructure rather than on-chain code.

For bridge operators, the implication is direct. Smart contract audits, while necessary, address only part of the attack surface. Key management architecture, verifier redundancy (moving beyond 1-of-1 configurations), and dispute period design require at least equivalent security investment. For users, the implication is equally direct: bridge TVL is not equivalent to bridge security, and a protocol's audit history does not guarantee the integrity of its operational infrastructure.

The $340 million in bridge losses YTD is not an anomaly. It is the cost of an infrastructure layer that has not yet solved its most basic operational security problems.

Sources & References

  1. Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked — CryptoTimes, July 26, 2026
  2. Arbitrum-based AFX Trade drained of $24 million after bridge keys compromised — CoinDesk, July 23, 2026
  3. Verus Bridge Suffers Second Exploit in 66 Days as Flaw Pushes Total Losses to $19.1M — Bitcoin.com News, July 23, 2026
  4. Wanchain Bridge Hack Drains $13M in NIGHT Tokens, Cardano Midnight Network Remains Secure — TokenPost, July 21, 2026
  5. B² Network Suffers $3.86M Exploit, Offers Attacker Legal Immunity For Partial Refund — Metaverse Post, July 2026
  6. Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit — CryptoTimes, July 24, 2026
  7. Crypto's 'Hackers' Day': AFX Trade Hit for $24M, Losses Reach $35.55M — CryptoTimes, July 23, 2026
  8. Two Cross-Chain Bridges Hacked in One Day — $31.5M Lost — Bitcoin Foundation, July 2026
  9. H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion — TRM Labs, 2026
  10. Crypto Bridge Exploits Hit $328.6M in May as Peckshield Tracks 8 Major Incidents — Bitcoin.com News, May 2026
  11. Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains — CoinDesk, April 19, 2026
  12. Inside the KelpDAO Bridge Exploit — Chainalysis, April 2026
  13. North Korean Hackers Attack Drift Protocol In USD 285 Million Heist — TRM Labs, April 2026
  14. Drift Protocol Hit by $285M Exploit: Crypto's Biggest Hack of 2026 — Bloomberg, April 1, 2026
  15. DeFi loses $35M in a day: Are 'bounties' inviting more hacks? — Protos, July 2026
  16. PeckShield: Hackers Drained from Crypto $750M in H1 of 2026 — Bitcoin Foundation, 2026