Key Takeaways
- Cybercriminals drained more than $31.6 million through two distinct bridge exploits targeting DeFi protocols between July 22–23, 2026
- The AFX Trade platform saw $24.15 million stolen when malicious actors gained control of validator signing keys on its Arbitrum-based bridge
- A separate attack on Verus Ethereum Bridge resulted in $7.5 million in losses, utilizing an identical technique to a previous May 2026 breach
- Offchain Labs clarified that Arbitrum’s native bridging infrastructure remained secure — only third-party protocols were compromised
- The majority of AFX’s stolen assets were swapped into approximately 12,467 ETH and consolidated in one address
In a remarkable display of coordinated crypto theft, two blockchain bridges fell victim to separate security breaches within a seven-hour window on July 22–23, 2026, resulting in combined losses exceeding $31.6 million.
The primary incident targeted AFX Trade, a decentralized perpetual futures platform operating on the Arbitrum network with USDC settlement capabilities. Analysis of blockchain transactions reveals that threat actors successfully obtained unauthorized access to the private validator keys responsible for approving bridge withdrawals.
Using five compromised hot-validator signatures, the perpetrators authorized a massive 24,150,000 USDC withdrawal directed to their controlled wallet address. This authorization satisfied the bridge’s required two-thirds validator consensus, causing the smart contract to process the fraudulent transaction according to its programmed logic.
Notably, the bridge’s underlying code remained intact throughout the incident. The vulnerability stemmed entirely from unauthorized key access rather than any technical flaw in the protocol architecture.
Timeline of the AFX Trade Breach
Security monitoring platform Blockaid first identified suspicious activity at 9:30 pm UTC on July 22. Following the protocol’s built-in 200-second challenge period, the illicit withdrawal was finalized and immediately transferred to Ethereum.
The stolen USDC was rapidly exchanged for roughly 12,467 ETH, valued at approximately $24 million at the time. Blockchain forensics indicate these assets remain concentrated in a single wallet address.
AFX’s trading activity had reached several-month peaks during mid-July, making the $24 million loss particularly devastating as it essentially wiped out the protocol’s total value locked.
Stephen Goldfeder, co-founder at Offchain Labs—the team behind Arbitrum development—emphasized that the network’s official bridge infrastructure was never compromised. “The transaction in question originated from a third-party protocol,” he clarified via X.
Secondary Attack Targets Verus Infrastructure
Just hours following the AFX incident, Blockaid’s monitoring systems flagged another exploitation targeting the Verus Ethereum Bridge. This second breach resulted in approximately $7.5 million in stolen assets, including Ether, tBTC, USDC, USDt, EURC, MKR, and scrvUSD.
According to Blockaid’s assessment, the attacker exploited the bridge’s import functionality to generate unauthorized distributions on the Ethereum network. This technique is virtually identical to a May 2026 compromise of the same infrastructure that resulted in $11.58 million losses, though forensic evidence indicates a different wallet address was employed in this latest incident.
While these two exploits appear operationally independent, they exemplify a broader DeFi security trend throughout 2026—malicious actors increasingly focus on off-chain infrastructure vulnerabilities rather than smart contract code weaknesses.
SunSec, a security analyst and founder of DeFiHackLabs, confirmed that compromised cryptographic keys, not code vulnerabilities, enabled the AFX breach. This attack pattern closely resembles the approximately $285 million Drift Protocol incident from April, where attackers gradually accumulated privileged system access.
These breaches follow closely on the heels of an oracle manipulation attack that siphoned $18 million from RWA platform Ostium just days earlier, highlighting an increasingly challenging security environment for Arbitrum ecosystem projects.
Cryptocurrency security professionals continue identifying bridges as a fundamental vulnerability in DeFi infrastructure. “Bridges will always be a weak link, until security is upgraded,” stated blockchain investigator TheCrypticWolf via X.



