Key Takeaways
- Over $31.6 million was stolen through two distinct cryptocurrency bridge exploits between July 22 and 23, 2026
- AFX Trade suffered a $24.15 million loss when threat actors gained control of validator signing keys on its Arbitrum-based bridge
- A separate $7.5 million breach targeted the Verus Ethereum Bridge using an identical technique deployed in a previous May 2026 attack
- Arbitrum developers verified that the network’s native bridging infrastructure remained secure throughout both incidents
- The majority of AFX’s stolen assets were converted into approximately 12,467 ETH and consolidated into one address
In a devastating 7-hour window spanning July 22–23, 2026, cybercriminals successfully exploited two separate blockchain bridges, siphoning off a combined total exceeding $31.6 million.
The more substantial breach targeted AFX Trade, a decentralized derivatives platform operating on the Arbitrum network that processes transactions in USDC. Analysis of blockchain records reveals that malicious actors obtained unauthorized access to the private validator signing keys responsible for authorizing bridge withdrawals.
The attacker secured approval from five hot-validator signatures to withdraw 24,150,000 USDC directly into their controlled address. This satisfied the bridge’s required two-thirds majority threshold, causing the smart contract to process the fraudulent transaction according to its programmed logic.
Notably, the bridge’s underlying code remained intact and functional. The vulnerability stemmed entirely from the unauthorized acquisition of critical authentication keys.
Timeline of the AFX Trade Breach
Cybersecurity company Blockaid first identified the malicious activity at 9:30 pm UTC on July 22. Following a mandatory 200-second challenge period, the stolen assets were released and immediately transferred to Ethereum.
The perpetrator quickly exchanged the pilfered USDC for roughly 12,467 ETH, valued at approximately $24 million. Blockchain monitoring services indicate these digital assets remain concentrated in a singular wallet address.
Trading activity on AFX had surged to peak levels not seen in months during mid-July, making the timing particularly damaging. The $24 million extraction essentially depleted the protocol’s entire total value locked.
Stephen Goldfeder, who co-founded Offchain Labs (the team behind Arbitrum), clarified that the network’s official bridge infrastructure was never compromised. “The transaction in question originated from a third-party protocol,” he stated via X.
Second Attack Targets Verus Bridge
Within hours of the AFX incident, Blockaid identified another exploitation affecting the Verus Ethereum Bridge. This attack resulted in approximately $7.5 million being stolen across multiple assets, including Ether, tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
According to Blockaid’s analysis, the perpetrator exploited the bridge’s import functionality to initiate unauthorized payouts on the Ethereum network. This technique precisely replicates a May 2026 assault on the identical bridge that resulted in $11.58 million in losses, though investigators confirmed a different wallet address was employed in this instance.
While these two breaches appear unconnected, they exemplify a troubling trend throughout DeFi during 2026 — threat actors increasingly focusing on off-chain infrastructure vulnerabilities rather than exploiting smart contract code weaknesses.
SunSec, a security analyst and founder of DeFiHackLabs, confirmed that compromised authentication keys, not software vulnerabilities, enabled the AFX breach. This attack vector resembles the approximately $285 million Drift Protocol incident from April, where attackers gradually obtained elevated system privileges.
These exploits follow just one week after an oracle manipulation attack extracted $18 million from RWA platform Ostium, extending a challenging period for protocols built on Arbitrum.
Cryptocurrency security experts continue highlighting bridges as an ongoing vulnerability. “Bridges will always be a weak link, until security is upgraded,” remarked blockchain investigator TheCrypticWolf on X.





