Three separate cross-chain bridge exploits drained $35.55 million on July 22-23, 2026, in what security firm Blockaid labeled "Hackers' Day." The incidents — a $24.15 million key compromise at AFX Trade on Arbitrum, a $7.54 million repeat exploit of the Verus Ethereum Bridge, and a $3.86 million ...
"The transaction in question originated from a third-party protocol. The Arbitrum native bridge has not been hacked or exploited in any way." — Stephen Goldfeder, Co-founder, Arbitrum Labs (Offchain Labs)
Three separate cross-chain bridge exploits drained $35.55 million on July 22-23, 2026, in what security firm Blockaid labeled "Hackers' Day." The incidents — a $24.15 million key compromise at AFX Trade on Arbitrum, a $7.54 million repeat exploit of the Verus Ethereum Bridge, and a $3.86 million staking contract drain at B² Network — pushed July 2026 crypto hack losses past $97 million and total bridge-related theft in 2026 above $370 million.
The attacks shared no common attacker or exploit code, but they shared a common structural deficiency: operational security failures in key management, access control, and patch verification. In each case, the underlying cryptography held. The humans and processes around it did not.
Since 2022, cross-chain bridges have produced more than $2.9 billion in cumulative losses — roughly 40% of all value ever hacked in Web3 — despite holding a fraction of total DeFi TVL. In May 2026, PeckShield documented that bridges accounted for 42% of all crypto exploit losses while representing fewer than 5% of monitored protocols. The concentration of risk is not improving.
Between 21:30 UTC on July 22 and approximately 04:00 UTC on July 23, three unrelated bridge-adjacent protocols were exploited in rapid succession. The combined take: $35.55 million across three chains (Arbitrum, Ethereum, BNB Chain/Solana).
Blockaid, the onchain security firm, detected all three incidents in real time. According to Blockaid CEO Ido Ben-Natan, the AFX Trade compromise appeared "to have been an operational security incident rather than a smart contract vulnerability." None of the three exploits breached the underlying blockchain layer. Arbitrum's native bridge was unaffected. Ethereum's consensus was unaffected. The exploits targeted application-level bridge infrastructure: validator key sets, import validation logic, and upgrade authority permissions.
| Protocol | Chain | Loss | Attack Vector | Funds Traced | |----------|-------|------|---------------|--------------| | AFX Trade | Arbitrum → Ethereum | $24.15M USDC | Compromised 5 hot-validator keys | 12,467.5 ETH to wallet 0x6276...ebAC | | Verus Bridge | Ethereum | $7.54M (ETH, tBTC, USDC, USDT, EURC, MKR, scrvUSD) | Unbacked import payout (repeat of May 2026 bug) | Partially returned ($8.5M from May incident) | | B² Network | BNB Chain → Ethereum | $3.86M (8.59M B2 tokens) | Seized staking contract upgrade authority | Converted to 5,409 BNB, bridged to ETH, routed through Tornado Cash and NEAR Intents |
AFX Trade, an Arbitrum-based perpetual DEX, operated its own custody bridge with a multisig validator set. At 21:30 UTC on July 22, an attacker who had obtained five hot-validator private keys met the bridge's quorum threshold and authorized a withdrawal of 24.15 million USDC.
The on-chain logic functioned as designed. Five valid signatures were presented. The bridge executed the withdrawal as intended. The failure was upstream: key storage, key rotation, and validator independence were insufficiently hardened.
According to PeckShield's analysis, the stolen USDC was bridged from Arbitrum to Ethereum and swapped into 12,467.5 ETH, traced to wallet 0x6276...ebAC.
Within hours, AFX's head of growth, identified as Ken C, posted a public bounty offer: return 70% of the stolen funds and keep $7.2 million (30%) as a "white hat bounty." As of July 25, no funds have been returned.
The incident pattern mirrors the 2022 Ronin Bridge hack ($624 million), where compromised validator keys — not broken cryptography — enabled the theft. Four years later, the same attack class remains effective against smaller protocols using similar architectures.
The Verus-Ethereum Bridge was exploited for the second time in two months. On May 18, 2026, attackers stole approximately $11.58 million using a flaw in the bridge's cross-chain import validation. On July 23, a different attacker — using a new wallet — exploited the same vulnerability class for $7.54 million.
According to analysis by security auditor Halborn, the root cause was a missing validation check: neither side of the bridge verified that the input amount on Verus matched the payout amount on Ethereum. The attacker used the bridge's submitImports function to trigger Ethereum-side payouts that were never backed by corresponding value on the Verus source chain.
The stolen assets included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD — indicating the bridge held a diversified pool of assets that could be drained through a single validation gap.
According to SlowMist, both the May and July exploits shared the same bridge contract, entry path, and bug class. The patch applied after the May exploit was incomplete. This raises a direct question about the protocol's remediation process: how a known, exploited vulnerability remained exploitable for 66 days.
Following the May exploit, Verus offered a bounty of 1,350 ETH. The attacker returned 4,052 ETH (approximately $8.5 million), according to reporting by MEXC News. The July attacker has not responded to similar overtures.
B² Network, a Bitcoin Layer 2 protocol, lost $3.86 million when an attacker seized upgrade authority over the network's staking contract. This was a permissions-based failure: the attacker gained control of the proxy contract's admin key and drained 8.59 million B2 tokens.
According to CryptoAdventure's tracking, the exploiter sold all B2 tokens for 5,409 BNB ($3.01 million), bridged the proceeds to Ethereum, swapped into ETH and USDT, and routed funds through Tornado Cash and NEAR Intents to obfuscate the trail.
B² Network suspended staking operations, stated it had contained the incident, and offered the attacker legal immunity in exchange for returning 90% of stolen funds. The team pledged full compensation for affected users.
The July 22-23 cluster is part of an accelerating pattern. Key figures from security firms and on-chain data:
| Metric | Value | Source | |--------|-------|--------| | Bridge exploit losses, Jan-May 2026 | $328.6M (8 major incidents) | PeckShield | | Bridge exploit losses, Jan-Jul 2026 (est.) | $370M+ | PeckShield, DefiLlama | | Bridge share of total crypto exploit losses (May 2026) | 42% | PeckShield | | Bridge share of monitored DeFi protocols | <5% | Immunefi | | Cumulative bridge losses since 2022 | $2.9B+ | Multiple sources | | Bridge losses as share of all Web3 hacks (since 2022) | ~40% | CCN, Phemex | | Total crypto hack losses, July 2026 | ~$97M (13+ incidents) | DefiLlama | | Total crypto hack losses, H1 2026 | $972M (207 incidents) | Multiple sources | | Bridge TVL, June 2026 | $45.38B | DeFi Llama |
The disproportionality is stark. Protocols representing less than 5% of monitored DeFi hold less than 5% of total DeFi TVL but generate 40-42% of all exploit losses. No other protocol category exhibits this risk concentration.
All three exploited protocols in the July 22-23 cluster offered post-hack bounties: AFX at 30% ($7.2M), Verus at 25% implied, and B² at 10% with legal immunity.
This practice is now standard. It is also increasingly controversial.
Protos reported that security expert Taylor Monahan questioned the wisdom of escalating bounty offers, noting that Verus had already set a 25% bounty after its May exploit, and AFX raised the bar to 30% — $7.2 million in potential payout.
The track record is mixed. The May Verus attacker returned $8.5 million after a bounty offer. The IoTeX attacker did not return funds after a 10% bounty offer on a $4.4 million exploit. The Solv Protocol attacker ignored a 10% bounty on a $2.7 million exploit.
The concern, as framed by multiple security analysts: rising bounty percentages may create a perverse incentive structure where attacking a protocol with $20 million in bridge TVL carries an expected "bounty" payout of $4-7 million even in the worst case. Whether this dynamic is measurable remains an open question. Data is inconclusive.
The July 2026 cluster demonstrates three distinct failure modes, none of which involved broken cryptography:
1. Key Management Failures (AFX Trade) Low-threshold multisigs remain the dominant bridge architecture for mid-tier protocols. According to security firm Zealynx, a 2-of-3 or even 5-of-9 multisig is insufficient for bridges holding $100 million or more in TVL. The recommended minimum for large-TVL bridges is 7-of-11 with geographically distributed, organizationally independent validators using HSM-based key storage.
AFX's validator set appears to have used hot keys without adequate rotation or isolation. The attack required compromising five keys — a high bar for a consumer application, but a low bar for a bridge custodying $24 million.
2. Incomplete Patch Cycles (Verus) The Verus bridge was exploited twice through the same vulnerability class in 66 days. The May fix was incomplete, leaving the same import validation gap exploitable. Trail of Bits has documented that multi-chain protocol audits are "systematically harder than single-chain audits" because attack surfaces span interactions between environments.
Every major exploited bridge — Wormhole, Ronin, Nomad — had prior audit coverage. Point-in-time audits cannot guarantee ongoing security through subsequent upgrades and code changes.
3. Access Control Gaps (B² Network) B² Network's staking contract used a proxy pattern with insufficiently protected upgrade authority. Proxy contract admin keys represent a single point of failure. Time-locks, multi-party upgrade governance, and key ceremony protocols exist but were evidently not implemented.
Pseudonymous Ethereum researcher Polynya has argued that "the only long-term credible bridge design is one based on validity proofs" — meaning cryptographic verification of state rather than trusted validator sets. Zero-knowledge proof-based bridges (e.g., zkBridge, Succinct) are in development but not yet widely deployed.
The July 22-23 bridge exploit cluster is not an anomaly. It is the latest data point in a four-year pattern: cross-chain bridges concentrate disproportionate risk, fail through operational rather than cryptographic weaknesses, and continue to attract capital despite a cumulative $2.9 billion loss record.
The economic structure of bridge security is misaligned. Protocols custodying tens of millions in user funds operate with validator key management practices that would be rejected by any regulated financial institution. Patch cycles leave known vulnerabilities exploitable for months. Upgrade authorities are insufficiently protected.
The bridge sector faces a binary outcome. Protocols that survive will be those that invest in HSM-based key management, continuous audit cycles, time-locked upgrades, and — eventually — validity-proof architectures. Those that do not will continue to generate losses at a rate of approximately $370 million per year in 2026, with no structural improvement in sight.
Total value locked of $45.38 billion sits atop infrastructure that has leaked 40% of all Web3 exploit losses since 2022. The question is not whether another cluster of bridge exploits will occur. The question is whether the next one will involve three protocols or thirty.