Crimes and Fraud News

Two Cross-Chain Bridges Hacked in One Day — AFX Loses $24 Million, Verus $7.5 Million

Nana K.
23 July 2026 3 min read

Total losses from two hacks on Arbitrum and Ethereum exceeded $31.5 million. We break down how the attacks unfolded.

On July 22-23, 2026, decentralized (DeFi) protocols AFX Trade and Verus suffered attacks on their cross-chain bridges. Combined losses topped $31.5 million.

Hot topic: Bitcoin’s Bear Market May End Before the Four-Year Cycle Predicts

In the first case, attackers gained access to private keys from five AFX bridge validators and withdrew $24.15 million in USDC$0.9999. In the second, a hacker reused the same vulnerability from May to steal $7.54 million from the Verus-Ethereum bridge.

Contents

AFX Trade: Hackers Accessed Validators, Drained $24 Million in a 200-Second Window

The AFX Trade attack occurred on July 22 at 21:30 UTC. Attackers withdrew 24,150,000 Circle’s USDC from the protocol’s custodial bridge on Arbitrum (ARB). According to Blockaid, the hackers obtained private keys from five validators, allowing them to reach the required quorum to confirm the transaction. The bridge’s smart contract had a 200-second challenge period, but no challenge was filed, and the contract automatically validated the transaction.

The stolen funds were bridged to Ethereum and swapped for 12,467.5 ETH$1,761.17 at an average price of roughly $1,937. Offchain Labs co-founder Steven Goldfeder confirmed that Arbitrum’s underlying infrastructure was not compromised.

The AFX team is investigating with help from SlowMist and Zellic, which previously audited the bridge’s code. The protocol offered the hacker a deal: return 70% of the stolen assets and keep 30% as a whitehat bounty.

Read more: Arbitrum Price Prediction 2026 — Is ARB the Next 10x Crypto?

Verus: Repeated Attack Through Same Vulnerability — Hacker Begins Laundering via Tornado Cash

On July 23, the Verus-Ethereum bridge was hit again. The attacker withdrew about $7.54 million in various assets and converted them to 3,916.1 Ethereum (ETH). According to Blockaid, the attack used the same contract, the same entry path, and the same vulnerability class as the May exploit, but was carried out by a different attacker from a new crypto wallet. The hacker has already started laundering the stolen funds through Tornado Cash.

The vulnerability lies in the VerusProof.checkExportAndTransfers function, which checked the transfer hash but didn’t verify that the assets were actually backed on the Verus side. As a result, the bridge executed fake transfers without confirming they were collateralized.

In May, the Verus developers offered the hacker a deal: they returned 75% of the stolen funds and kept 25% as a bounty. This time, the team has not commented–the project’s social media has been abandoned since May.

Read more: Ethereum ETFs Are Back — Could Institutional Money Finally Ignite the Next ETH Rally?

What This Means for the Crypto Market

Two hacks in a single day highlight the systemic risks of cross-chain bridges, especially those relying on validator mechanisms without sufficient collateral verification. Bridges have been targeted in at least eight major exploits in 2026, with total losses of $328.6 million.

Learn more: What Is FBTC Crypto: Bitcoin vs Function (FBTC) – What’s the Difference?