Security

Three Major Hacks in 24 Hours: How $35M Vanished from Bridges and Staking

2026-07-25

AFX Trade on Arbitrum lost roughly 24.15 million USDC on July 22 when an attacker exploited its bridge. Blockaid flagged it at 21:30 UTC. First of three major incidents that would unfold over the following hours.

The attacker had the validator signing keys. That meant they could move funds out without restriction. Blockaid confirmed the hackers obtained private keys from five validators—enough to hit quorum and confirm the transaction. The attacker then swapped 12,467.5 ETH worth of stolen USDC, complicating recovery because there were no freeze mechanisms in place.

Steven Goldfeder, co-founder of Offchain Labs, clarified that the transaction came from a third-party protocol. Arbitrum's native bridge wasn't touched. The vulnerability lived in AFX's bridge design, not in Arbitrum itself. At time of reporting, AFX hadn't published a complete technical postmortem or confirmed reimbursements. They later offered attackers a 30% bounty for return of funds.

Hours later, a second exploit hit the Verus-Ethereum bridge. An attacker used the import path to trigger unbacked payouts on the Ethereum side, draining roughly $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Bad enough on its own. Worse when you learn what it really meant.

This was a repeat vulnerability. Same contract. Same entry path. Same vulnerability class as the May exploit, but a different attacker using a new wallet. The previous attack in May had drained 11.6 million. That attacker converted it into 5,402 ETH and later returned 4,052 ETH, keeping a 25% white-hat bounty. Identical vulnerabilities persisted for two months. Critical questions about remediation efforts became unavoidable. The project's social media had been abandoned since May, suggesting minimal effort around recovery and fixes.

The third incident involved B² Network. Different attack vector entirely. Unauthorized access to the staking contract's upgrade authority allowed an attacker to drain 8.59 million B2 tokens, worth approximately 3.86 million dollars at the time. This wasn't a bridge exploit. It exploited administrative permissions instead of cryptographic validation logic.

B² suspended normal staking during security reviews, said the issue was contained, and promised full compensation. They also offered a manual exit: users could request unstaking through the official Discord. Ownership-verified requests would be processed within one business day. No specific loss amount announced. Still a critical failure in access control.

Collectively, these three incidents exposed a troubling pattern in decentralized finance infrastructure. Total losses from hacks during July 2026 reached nearly 97 million dollars. Bridge exploits dominate the year's security failures. The AFX incident revealed inadequate hot-key management for validator systems. Verus showed insufficient patching discipline. B² highlighted the enduring risk of centralized upgrade authority.

Three distinct failure modes. All required sophisticated operational security to prevent.

For users navigating these protocols, the implications extended beyond immediate fund recovery. Well-capitalized teams operating within established blockchain ecosystems could still fall prey to infrastructure compromises that bypassed smart-contract audits. Two hacks in a single day made clear the systemic risks of cross-chain bridges, especially those relying on validator mechanisms without sufficient collateral verification. The onus shifted to users to evaluate not just the security of trading interfaces but the robustness of the underlying deposit and withdrawal systems supporting them.


Source & further reading:

Sources