Hackers Steal $31.6M in Two Crypto Bridge Attacks Just Hours Apart

Bybit


Set as Google Preferred SourceFollow on Google News

TLDR

  • Hackers stole over $31.6 million across two separate crypto bridge exploits on July 22–23, 2026
  • AFX Trade lost $24.15 million after attackers compromised validator signing keys on its Arbitrum bridge
  • The Verus Ethereum Bridge lost $7.5 million using the same attack method as a May 2026 incident
  • Arbitrum confirmed its own native bridge was not affected — the breach was isolated to third-party protocols
  • Most stolen funds from AFX were converted to roughly 12,467 ETH and moved to a single wallet

Two crypto bridges were exploited within seven hours of each other on July 22–23, 2026, with hackers making off with more than $31.6 million in total.

The first and larger attack hit AFX Trade, a decentralized perpetuals exchange built on Arbitrum that settles trades in USDC. Blockchain data shows an attacker compromised the private validator signing keys that authorize withdrawals on AFX’s bridge.

Five of the bridge’s hot-validator signatures approved a withdrawal of 24,150,000 USDC to the attacker’s wallet. That met the two-thirds quorum the bridge requires, so the contract executed the transaction as designed.

The bridge’s code itself was never broken. The problem was that the keys controlling it were in the wrong hands.

How the AFX Attack Played Out

Security firm Blockaid detected the exploit at 9:30 pm UTC on July 22. After a 200-second dispute window, the funds were released and quickly bridged to Ethereum.

The attacker swapped the stolen USDC for approximately 12,467 ETH, worth around $24 million. On-chain trackers show those funds now sit in a single wallet.


Zuna


AFX’s trading volume had been climbing to multi-month highs in mid-July, and the $24 million drained represented almost the protocol’s entire total value locked at the time.

Stephen Goldfeder, co-founder of Offchain Labs, which develops Arbitrum, confirmed the network’s native bridge was untouched. “The transaction in question originated from a third-party protocol,” he said on X.

Verus Bridge Hit Hours Later

Hours after the AFX attack, Blockaid detected a second exploit on the Verus Ethereum Bridge. Around $7.5 million was drained, including Ether, tBTC, USDC, USDt, EURC, MKR, and scrvUSD.

Blockaid said the attacker used the bridge’s import path to trigger unbacked payouts on the Ethereum side. The method mirrors a May 2026 attack on the same bridge that drained $11.58 million, though a different attacker wallet was used this time.

The two incidents are unrelated, but they follow the same pattern seen across DeFi in 2026 — attackers targeting off-chain infrastructure rather than smart contract code.

Security researcher SunSec, founder of DeFiHackLabs, said compromised keys, not a code bug, were responsible for the AFX breach. The pattern matches a roughly $285 million Drift Protocol loss in April, where attackers gained privileged access over time.

This attack comes after an oracle exploit drained $18 million from RWA platform Ostium just a week earlier, continuing a difficult stretch for Arbitrum-based protocols.

Crypto security researchers have flagged bridges as a persistent weak point. “Bridges will always be a weak link, until security is upgraded,” said on-chain investigator TheCrypticWolf on X.





Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*