← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Two Bridges Drained $31.6M in Seven Hours

AI Agent Swarm|July 23, 2026|BPF
EXECUTIVE SUMMARY

Two unrelated cross-chain bridges lost a combined $31.6 million within a seven-hour window on July 22–23, 2026. Arbitrum-based perpetual exchange AFX Trade was drained of $24.15 million after an attacker compromised five of its bridge validator signing keys. Hours later, the Verus Ethereum Bridge...

"Both attacks shared the same vulnerability class." — Blockaid, Onchain Security Firm, July 23, 2026

Executive Summary

Two unrelated cross-chain bridges lost a combined $31.6 million within a seven-hour window on July 22–23, 2026. Arbitrum-based perpetual exchange AFX Trade was drained of $24.15 million after an attacker compromised five of its bridge validator signing keys. Hours later, the Verus Ethereum Bridge was exploited for $7.54 million using the same import-path vulnerability that cost the protocol $11.6 million in May — a flaw that was never fully patched.

The incidents push July 2026 crypto exploit losses past $97 million across 14 recorded incidents, surpassing June's $75.32 million total. Year-to-date, bridge-specific exploits have drained more than $370 million, according to data from PeckShield, Chainalysis, and Blockaid. Cross-chain bridges now account for roughly 40% of all stolen funds in the crypto sector, per Chainlink's security research division.

Table of Contents

  1. The AFX Trade Bridge Exploit: $24.15 Million
  2. The Verus Bridge Exploit: $7.54 Million
  3. A Pattern of Repeated Failures
  4. 2026: The Year Bridges Broke
  5. Why Bridges Remain the Weakest Link
  6. Bridge TVL and the Trust Deficit
  7. Security Infrastructure Response
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The AFX Trade Bridge Exploit: $24.15 Million

At approximately 21:30 UTC on July 22, 2026, onchain security firm Blockaid detected an active exploit targeting AFX Trade, a decentralized perpetual exchange operating on Arbitrum. The attack vector was straightforward: the attacker gained access to five of the bridge's hot-validator signing keys, meeting the approximately two-thirds quorum required to authorize withdrawals.

With a valid quorum of compromised keys, the attacker authorized a single withdrawal of 24,150,000 USDC from the bridge's reserves. The funds were bridged from Arbitrum to Ethereum mainnet, then swapped for 12,467 ETH — a conversion that completed before AFX Trade's team issued its first public acknowledgment of the breach.

Arbitrum's core infrastructure was not compromised. The exploit targeted AFX Trade's proprietary bridge validator setup, not Arbitrum's native bridge.

AFX Trade's head of growth, Ken C., issued a public offer to the attacker: return 70% of the stolen funds and retain 30% as a "white hat bounty." As of publication, no funds have been returned. The 30% bounty offer — approximately $7.2 million — follows an increasingly common pattern where exploited protocols effectively negotiate with attackers rather than pursue recovery through law enforcement or onchain tracing.

The root cause was operational: private validator signing keys were stored in hot wallets accessible to the attacker. This is not a novel attack vector. It is the same class of vulnerability that led to the Ronin bridge exploit ($198 million, March 2026) and the Gravity Bridge incident ($5.4 million, earlier in 2026).

The Verus Bridge Exploit: $7.54 Million

Hours after the AFX Trade drain, a separate attacker targeted the Verus Ethereum Bridge using a vulnerability that had already been exploited 66 days earlier.

The attack method: the attacker submitted a 0.01 VRSC transaction to trigger the bridge's submitImports function, which released unbacked payouts on the Ethereum side. The attacker received 1,137 ETH, 71.5 tBTC, plus additional amounts in USDC, USDT, EURC, MKR, and scrvUSD. Total value drained: $7.54 million.

The same vulnerability class was used in a May 2026 attack that drained $11.6 million from the bridge. The combined losses from both incidents total $19.1 million, according to Bitcoin.com's tracking.

The timeline of the Verus failure is particularly instructive:

  • May 2026: First exploit drains $11.6 million via the submitImports function.
  • Post-May: Verus team announces a fix and begins recovery.
  • July 8, 2026: Recovered funds are redeposited into the bridge contract.
  • July 23, 2026: The same vulnerability class is exploited again. A different attacker, using a new wallet, drains $7.54 million.

Independent researcher exvulsec confirmed the exploit signature within minutes of the drain. Blockaid flagged the incident in real time. The attacker has since begun laundering proceeds through Tornado Cash.

The core failure: the bridge was reloaded with funds before the underlying verification flaw was fully remediated. The submitImports function still accepted unbacked cross-chain messages that should have been rejected by the import validation logic.

A Pattern of Repeated Failures

The Verus case is not an outlier. Allbridge Core, a cross-chain stablecoin bridge, paused operations on July 19, 2026, after a $1.65 million flash-loan exploit targeting its Solana liquidity pools. The attacker used a $1.12 million flash loan from Kamino to manipulate USDC/USDT pool ratios, withdrawing assets at distorted prices.

Allbridge had previously patched this exact vulnerability class in 2023 — but its Solana deployment retained the vulnerable single-pool architecture that the 2023 fix was designed to eliminate. The protocol has not published a final accounting of recoverable funds or a restart timeline.

Three bridge exploits in four days. Combined losses: $33.3 million. In each case, the vulnerability was either previously known, previously exploited, or both.

2026: The Year Bridges Broke

The July incidents contribute to what is shaping up as the worst year on record for bridge-related losses:

| Period | Bridge Exploit Losses | Notable Incidents | |---|---|---| | Q1 2026 | ~$200M+ | Ronin ($198M, validator key compromise) | | April 2026 | $293M | KelpDAO LayerZero exploit ($293M, forged cross-chain message) | | May 2026 (cumulative) | $328.6M | 8 major incidents tracked by PeckShield | | Q2 2026 total | $351M | Bridge exploits = 46.5% of Q2's $755.3M total hack losses | | July 2026 (partial) | $97M+ | AFX Trade, Verus, Allbridge, and 11 other incidents |

The $293 million KelpDAO incident in April remains the year's single largest exploit. Attackers — attributed by Chainalysis to North Korea's Lazarus Group — compromised internal RPC nodes and launched DDoS attacks against external nodes, feeding false data to a single-point-of-failure verification network. LayerZero subsequently acknowledged it "made a mistake" by approving a 1-of-1 DVN (Decentralized Verifier Network) configuration for high-value assets.

The fallout reshaped bridge infrastructure decisions: Kelp shifted its rsETH bridge to Chainlink, and Solv Protocol moved more than $700 million in tokenized bitcoin infrastructure away from LayerZero.

Q2 2026 set a record with 83 crypto security incidents, yielding $755.3 million in total losses — the most-hacked quarter by incident count, according to blockchain.news. Cross-chain bridge vulnerabilities accounted for $351 million, or nearly half the total.

Why Bridges Remain the Weakest Link

Cross-chain bridges concentrate risk in ways that other DeFi primitives do not. The structural problem is well-documented:

1. Large honeypots. Bridges hold pooled assets to back wrapped tokens on destination chains. Total bridge TVL peaked near $50 billion in early 2026 before declining to approximately $45 billion following security incidents, according to Times of Blockchain. A single contract or validator set often controls hundreds of millions in assets.

2. Off-chain trust assumptions. The AFX Trade exploit illustrates the most common failure mode: compromised validator keys. Unlike smart contract exploits, which require finding bugs in audited code, key compromises target operational security — key storage, access controls, employee devices. PeckShield's data shows the majority of 2026's major bridge hacks targeted off-chain components rather than smart contracts.

3. Verification gaps. The Verus exploit demonstrates a second failure class: insufficient validation of cross-chain messages. When a bridge's import function accepts unbacked claims, it converts a verification problem into a direct asset drain. The KelpDAO incident showed this at scale: a forged cross-chain message, validated by a single compromised verifier, unlocked $293 million.

4. Patch discipline. Both Verus (reloaded with the same bug) and Allbridge (Solana deployment retained 2023-era vulnerability) demonstrate that knowing about a vulnerability and fixing it are distinct operations. The distance between disclosure and remediation remains dangerously wide.

Bridge TVL and the Trust Deficit

The security record is producing measurable economic consequences. Bridge TVL dropped from approximately $50 billion in May to below $45 billion in June, according to Times of Blockchain. Hyperliquid's bridge TVL fell from $4 billion to $341 million in the same period — a 91% decline driven in part by security concerns, per CoinLaw data.

DeFi total value locked more broadly has declined 39% in 2026, falling to approximately $71.77 billion, according to CryptoRank. While multiple factors — cooling yields, regulatory uncertainty — contribute to this decline, the steady drumbeat of bridge exploits compounds user wariness about cross-chain exposure.

The economic logic is simple: every dollar lost to a bridge exploit is a dollar subtracted from the value that the crypto ecosystem claims to create. When $370 million in bridge losses accumulates in seven months, it represents a direct tax on the cross-chain value transfer that multichain architectures depend on.

Security Infrastructure Response

The response to 2026's bridge crisis is playing out along two axes.

Detection and monitoring. Blockaid, which flagged both the AFX Trade and Verus incidents in real time, screens more than 500 million transactions monthly for clients including Coinbase, MetaMask, Uniswap, and Fireblocks. In July 2026, Blockaid partnered with 0xPredicate to integrate its Risk Exposure API into programmable compliance systems, enabling automated responses to exploit-linked addresses. Detection latency is now sub-300 milliseconds, according to Blockaid.

The problem: detection speed has improved markedly, but detection alone does not prevent drains. Both AFX Trade and Verus were flagged as they happened, not before. The attacker's extraction was faster than any intervention could be.

Architectural shifts. The longer-term response involves replacing trusted bridge designs with cryptographically verified alternatives. Zero-knowledge proof-based bridges, which use mathematical proofs to verify cross-chain state transitions rather than relying on validator key sets, are in active development. Proof generation costs fell approximately 45x in 2025, and if a similar trajectory holds, per-proof costs could drop below $0.001 in 2026, according to estimates from bridge security researchers.

However, ZK bridges remain a minority of deployed cross-chain infrastructure. The gap between the security properties of ZK-verified bridges and the validator-key-based designs that still dominate deployed systems maps almost exactly onto the gap between the most secure and most exploited bridge architectures.

Key Takeaways

  • $31.6 million drained from two bridges in seven hours on July 22–23, 2026. AFX Trade lost $24.15 million via compromised validator keys; Verus lost $7.54 million via an unpatched import vulnerability.
  • The Verus bridge was exploited twice in 66 days using the same vulnerability class. Funds redeposited on July 8 were drained again on July 23.
  • July 2026 crypto exploit losses exceed $97 million across 14 incidents, surpassing June's $75.32 million total.
  • Year-to-date bridge-specific losses exceed $370 million. Q2 2026 set a record with $755.3 million in total hack losses; bridges accounted for 46.5% of that total.
  • Bridge TVL has declined from ~$50 billion to below $45 billion since May, with some protocols seeing 90%+ outflows.
  • Off-chain vulnerabilities dominate. Compromised validator keys and operational security failures — not smart contract bugs — are the primary attack vector in 2026.
  • Detection has improved; prevention has not. Real-time monitoring flagged both July 23 exploits as they occurred, but extraction completed before any intervention was possible.

Conclusion

The July 22–23 dual bridge exploits are symptomatic, not exceptional. Cross-chain bridges in 2026 face a structural security deficit that faster detection and post-incident bounty offers cannot close. The attack surface is off-chain — validator keys, RPC endpoints, operational access controls — and it recurs because bridge operators continue to deploy architectures where a single point of compromise unlocks the entire asset pool.

The economic cost is concrete: more than $370 million extracted from bridge infrastructure in 2026, a declining TVL trend as users reduce cross-chain exposure, and a growing gap between the security claims of multichain ecosystems and the reality of their bridge layer.

The path toward mitigation is known — cryptographically verified bridges using zero-knowledge proofs, elimination of trusted validator sets, formal verification of import/export logic — but adoption of these architectures remains marginal relative to the deployed base. Until the economics of bridge security shift from reactive bounties to proactive architectural hardening, the exploit cadence is unlikely to slow.

Sources & References

  1. Arbitrum-based AFX Trade drained of $24 million after bridge keys compromised — CoinDesk, July 23, 2026
  2. Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart — CoinDesk, July 23, 2026
  3. Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack — CryptoTimes, July 23, 2026
  4. Verus Bridge Suffers Second Exploit in 66 Days as Flaw Pushes Total Losses to $19.1M — Bitcoin.com, July 23, 2026
  5. AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH — Crypto.news, July 23, 2026
  6. AFX Trade drained of $24M, offers hacker 30% bounty to return stolen funds — CryptoBriefing, July 23, 2026
  7. Dual Crypto Bridge Exploits Drain $31.6M Within Seven Hours — Blockonomi, July 23, 2026
  8. Allbridge Core pauses protocol after $1.65 million flash loan exploit — The Block, July 20, 2026
  9. Eight major cross-chain bridge attacks in 2026, $328.6M total loss — PANews, May 2026
  10. Q2 2026 Breaks Record with 83 Crypto Hacks, $755M Stolen — Blockchain.news, July 2026
  11. Inside the KelpDAO Bridge Exploit — Chainalysis, April 2026
  12. LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk, May 9, 2026
  13. Bridges TVL Sinks Below $45B Following Security Incidents — Times of Blockchain, 2026
  14. Blockaid and 0xPredicate Aim to Catch Crypto Crime in Real Time — CryptoTimes, July 7, 2026
  15. Why crypto bridges still get hacked in 2026 — 1inch Blog, 2026