Security Current Affairs ETH

Three Bridges, Three Failures: How $31.7M Vanished in Six Hours

2026-07-25

Blockaid spotted the first breach on July 22 at 9:30 p.m. UTC. About $24.15 million in USDC had been drained from the AFX-operated bridge. Not Arbitrum's native bridge—this was AFX's own sovereign infrastructure, and it had fallen apart.

The compromise was straightforward: a hacker got the validator keys. With those, moving assets became trivial because the protocol's dispute mechanism never triggered. The $24.15 million went from Arbitrum to Ethereum, got converted to ETH, and the attacker walked away with roughly 12,467 tokens at around $1,937 each. Offchain Labs co-founder Steven Goldfeder made sure to clarify that Arbitrum's native bridge wasn't touched. This was purely AFX's mess.

Hours later, a second exploit hit the Verus-Ethereum bridge. Different attack vector, same result: $7.54 million gone. The attacker abused the same import path that had worked in May, which begged an obvious question. Didn't anyone fix this?

The mechanism was elegant in its stupidity. The bridge accepted the signatures and Merkle proofs without actually checking whether the amount being released matched what was committed on the source chain. Not a cryptography problem. Just a missing value check inside the contract.

Back in May, this same vulnerability had cost $11.5 million. The attacker had eventually returned 4,052.4 ETH after pocketing a 25% white-hat bounty. Now, two months later, the same door was still open. The July attacker converted 3,916 ETH through decentralised exchanges, then started routing chunks of it through Tornado Cash.

The third incident on the same day involved B² Network, a Bitcoin scaling protocol, but the entry point was completely different. Someone got unauthorized access to the staking contract's upgrade authority and drained 8.59 million B2 tokens—about $3.86 million at the time. This wasn't a logic flaw. It was pure governance failure, a straightforward compromise of admin controls.

B² suspended staking, said the issue was contained, and promised full compensation. They offered users a manual exit through Discord: request unstaking with verified ownership, and it'd be processed within a business day. The attacker, meanwhile, sold the entire haul—8.59 million B2—on BNB Chain for 5,409 BNB, clearing about $3.01 million.

Three incidents across a single day. Three different failure modes. AFX lost money because signing keys were compromised. Verus lost money because it never validated what it was supposed to validate. B² lost money because administrative authority was sitting there unguarded.

In six hours, these protocols bled over $35 million. Not through broken cryptography. Through broken governance. Broken access control. Broken validation logic. The infrastructure was running, the signatures checked out, the protocols executed exactly as they were written. It just turned out they were written by people who hadn't thought through what happens when bad actors have the keys.


Source & further reading:

Sources