Jul 24, 2026 · 7:39 AM
Subscribe
Home Crypto

Three crypto bridges lost $35 million in a single day and the biggest victim is negotiating with its hacker

AFX Trade lost $24.15 million in USDC after an attacker compromised its bridge's validator signing keys, leading a day in which three crypto protocols were drained of a combined $35.55 million. The Verus Ethereum Bridge was hit for $7.54 million using the same exploit path from May. AFX is now publicly negotiating a 70/30 white-hat bounty deal with its attacker.

Ron Patel
· 4 min read · 536 reads
Three crypto bridges lost $35 million in a single day and the biggest victim is negotiating with its hacker

AFX Trade's $24.15 million bridge drain led a brutal July 22-23 stretch in which three crypto protocols lost about $35.55 million, and the pattern tells you where this industry's security problem really lives.

The attacker hit AFX Trade first. The Arbitrum-based perpetuals DEX lost 24.15 million USDC after enough hot-validator signatures approved a withdrawal from a bridge the protocol operates. According to CoinDesk, the attacker used five validator signatures, cleared the bridge's quorum, waited through the short dispute window, moved the stolen USDC to Ethereum, and swapped it for about 12,467 ETH.

That distinction matters. This was not Arbitrum's native bridge failing. It was AFX's own bridge infrastructure. Offchain Labs CEO Steven Goldfeder said publicly that the transaction "originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way." The network underneath AFX kept working. The protocol sitting on top of it did not.

AFX's response was to negotiate. Decrypt reported that the protocol offered the attacker a deal: return 70% of the stolen funds and keep the remaining 30% as a white-hat bounty. On a $24.15 million theft, that means roughly $7.2 million for the attacker and about $16.9 million returned to the protocol if the offer is accepted. As of the latest reports, no recovery had been announced.

Verus was worse in a different way. The Verus Ethereum Bridge was drained for about $7.54 million on July 23, after an attacker abused the bridge's import path to trigger Ethereum-side payouts without matching value on the Verus source chain. Blockaid said the July exploit appeared related to the May 2026 Verus bridge incident: same bridge contract, same entry path, same bug class. That is hard to dress up. A known class of failure was still reachable.

Seven assets went out, including ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD, according to CoinCentral's summary of the Blockaid and Cyvers findings. The May incident had already cost the bridge about $11.58 million before a partial bounty settlement returned most of the funds. Then July came, and a different attacker found the same route. That is not just a bug story. It is a management story.

B² Network rounded out the day with a $3.86 million loss on BNB Chain. Lookonchain traced 8.59 million B2 tokens stolen from the protocol, sold for 5,409 BNB, then bridged onward and split into other assets. B² said the breach involved unauthorized access to the upgrade authority of its token staking contract, suspended staking, and offered legal immunity for a partial refund. Three attacks. Roughly seven hours. One ugly theme.

Why bridges keep losing

The $35 million question is not whether bridges can be hacked. It's why the same types of attacks keep working. In AFX's case, the failure was key management. Enough validator signatures could authorize a withdrawal of almost the entire bridge balance. In Verus, the failure sat in cross-chain validation logic. In B², privileged upgrade authority became the open door.

Crypto has seen this movie before. The Ronin Network bridge lost about $625 million in 2022 after attackers compromised validator keys. Harmony's Horizon bridge lost about $100 million the same year, also after private keys were compromised. You don't need a new kind of exploit when old operational weaknesses still control large pools of user funds.

Frankly, the white-hat negotiations reveal as much as the hacks. Once stolen funds move out, convert into ETH, and start traveling through mixers or cross-chain routes, the victim usually has very little room left to manoeuvre. The public offer becomes the recovery plan because the real security plan already failed. Sometimes that works. It is still a poor substitute for keeping the keys, import paths and upgrade rights locked down in the first place.

There is also a reader point here, because anyone using DeFi has to stop treating "built on Arbitrum" or "built on Ethereum" as a security guarantee. The underlying chain can be fine while the bridge, admin wallet or off-chain signer set attached to an app is fragile. AFX is the clean example. Goldfeder's clarification protected Arbitrum from blame, but it did nothing for AFX users waiting to see whether an attacker takes a bounty deal.

Bridge risk is not an edge case. It is a structural weakness in the way many cross-chain systems still move assets between networks, with small signer groups, upgrade powers and validation checks carrying far more money than their controls deserve. The negotiation with AFX's attacker is the live story. The bigger one is simpler: $35.55 million left three protocols in a single stretch, and none of the failures required magic.

They required targets that had not done the basics.

Also read: America's emergency oil tank is nearly empty and the timing could not be worseThe liquidation cascade crypto traders fear most is entirely mechanicalBitMEX is shutting down on September 23 and users who don't act face punishing fees

TOPICS
Ron Patel covers cryptocurrency markets, blockchain developments, and digital asset news for Startup Fortune. With a background in financial journalism and over eight years tracking crypto markets through multiple cycles, Ron brings analytical perspective to Bitcoin, Ethereum, and emerging token ecosystems.
Related Articles
More posts →
Loading next article…
You're all caught up