Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Hackers steal over $31 million in two separate crypto bridge exploits within hours
00

Hackers steal over $31 million in two separate crypto bridge exploits within hours

Jul 23, 2026

In a span of six hours, hackers exploited three separate crypto protocols for over $35 million. The attacks drained $24.15M from AFX Trade's Arbitrum bridge, $7.54M from the Verus-Ethereum bridge via a repeat vulnerability, and $3.86M from B² Network. The exploits stemmed from compromised keys and logic flaws, not broken cryptography, highlighting persistent security weaknesses in cross-chain systems.

Three bridge exploits

  • ▪The Verus-Ethereum bridge was exploited for about $7.54 million in a separate attack
  • ▪AFX Trade, a decentralized perpetuals exchange on Arbitrum, was exploited for approximately $24.15 million on July 22, 2026
  • ▪B² Network, a Bitcoin scaling network, lost roughly $3.86 million after an attacker compromised its token staking contract
  • ▪The attacks on AFX, Verus, and B² Network resulted in a combined loss exceeding $35 million over a 6-hour period
  • ▪The attacker moved the stolen $24.15 million from the AFX bridge to Ethereum and swapped the funds for approximately 12,468 ETH

Verus repeat vulnerability

  • ▪Verus redeposited funds recovered from the May 2026 hack into the same vulnerable bridge on July 8, 2026, two weeks before it was exploited again
  • ▪The exploit on the Verus-Ethereum bridge reused the same contract path and bug class as a previous hack in May 2026 that caused an $11.5 million loss
  • ▪The Verus vulnerability allowed an attacker to trigger payouts on the Ethereum side that were not backed by assets on the Verus side

B² Network compromised keys

  • ▪An attacker gained unauthorized access to the upgrade authority of B² Network's token staking contract, allowing them to drain funds
  • ▪B² Network suspended staking operations and announced it would fully compensate affected users

Smart contract permission failures

  • ▪Arbitrum co-founder Steven Goldfeder stated that the network's native bridge was not hacked or exploited in the AFX incident
  • ▪The recent series of exploits were caused by logic flaws or compromised administrative keys, not by breaking the underlying cryptography
  • ▪AFX suspended its bridge and publicly offered the attacker 30% of the stolen funds as a "white hat bounty" in exchange for the return of the other 70%

AI-driven intrusion capabilities

  • ▪The OpenAI test demonstrated that AI can now perform complex, multi-step intrusion work that previously required a skilled human team
  • ▪A recent OpenAI analysis showed its AI models could compromise servers by chaining stolen credentials and unknown software flaws in a test environment

4 sources

Coindesk
Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart
View source article
The Defiant
Attacker Drains $24M in USDC From AFX Bridge on Arbitrum
View source article
Decrypt
Arbitrum Perp DEX AFX Trade Drained of $24M, Offers Hacker 30% to Return It - Decrypt
View source article
Cointelegraph
Hackers steal $31.6M in 2 crypto bridge attacks within 7 hours
View source article

Story comments

Loading comments…

Related entities

Bridge exploitVenus Protocol

Related Projects

Arbitrum

Topics

Blockchain interoperabilityCrypto hacksDeFi