EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Multiple cross-chain bridge attacks cost Bitcoin and Ethereum networks $35 million in losses

2026-07-24 00:40:37
Bookmark

Encryption infrastructure has been hit hard again this week: Three security incidents have lost more than US$35.5 million

This week, encryption infrastructure has been hit again. Three separate security incidents occurred under three different protocols, resulting in cumulative losses of more than $35.5 million. The targets involve cross-chain bridges, managed bridges and token permissions. These incidents once again demonstrate that the real risk area lies in how the project handles asset transfers and controls, rather than the underlying blockchain itself.

The biggest loss came from AFX Trade on Arbitrum, followed by another disturbing repeat attack on the Verus Ethereum Bridge. The third incident occurred on the B² Network, bringing an end to a terrible 24 hours in the field.


The Verus Ethereum Bridge suffered almost the same attack again

Just a few months after the May attack, the Verus Ethereum Bridge once again lost approximately US$7.54 million. According to Blockaid, the attacker used a very small amount of VRSC on the Verus side to trigger large unsecured payments on the Ethereum side, stealing ETH, tBTC, USDC, USDT and other reserve assets. Funds are quickly exchanged for ETH and transferred through privacy services.


Blockaid has detected an attack on the @VerusCoin Ethereum Bridge. The attacker used the bridge's import path to trigger unsecured payments on the Ethereum side, stealing approximately US$7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD from the bridge's reserves.

-- Blockaid (@blockaid_) July 23, 2026

The attack was particularly harrowing because it was strikingly similar to the attack in May that caused $11.58 million in damage. Security researchers pointed out at the time that although the bridge correctly verified the signature and certificate, it did not verify whether the value sent by one side matched the value released by the other side. The same attack vector succeeded again, raising questions about how thorough the repairs were after the first incident.


AFX Trade lost US$24.15 million from the Arbitrum Bridge USDC

The largest attack occurred on July 22. Attackers stole approximately $24.15 million in USDC from a bridge operated by perpetual contract agreement AFX Trade on Arbitrum. Blockaid discovered this early, and the stolen funds were quickly bridged to Ethereum and exchanged for approximately 12,467 ETH.

Blockaid detected an attack against @AFX_XYZ (the protocol on Arbitrum) on July 22, 2026 at 21:30 UTC. The attack targeted a specific bridge operated by AFX. As of now, approximately 24.15 million USDC have been stolen from the agreement.

-- Blockaid (@blockaid_) July 22, 2026

Important clarification: Arbitrum's native bridge has not been affected. Offchain Labs co-founder Steven Goldfeder confirmed that the core L2 infrastructure remains secure. This vulnerability is limited to AFX's own hosting settings. Details of the root cause are still under investigation, but appear to have something to do with the protocol's bridge authorization logic rather than the chain itself.


The B² network encountered a privilege breach that resulted in asset loss

In the third incident, B² Network lost approximately 8.59 million B2 tokens worth approximately US$3.86 million. Analysts pointed out that a wallet with high-level privileges transferred tokens before the privileges were revoked. Attackers exchanged it for WBNB, bridged it to other chains, and continued to move towards privacy channels through services such as NEAR Intention.

An attack involving @BSquaredNetwork may have occurred on the BSC. The attackers stole 8.591 million $B2 tokens (worth US$3.86 million) and exchanged them for 5,409 WBNB (US$3.11 million), bridging the funds to Ethereum, which is currently being transferred to Zcash through NEAR Intention.

-- Specter (@SpecterAnalyst) July 22, 2026

This move caused the B2 token price to immediately drop by approximately 15%. The team publicly called on the attackers to return some of the funds or face legal consequences. The case stands out because it is more like an operational-level authority issue than a classic smart contract vulnerability.


What these attacks reveal

Three different protocols, three different attack paths, but a clear pattern emerges: attackers focus on the layer where assets are actually held or transferred. Verus exposed the weaknesses of cross-chain economic verification, AFX highlighted the risks of managed bridges, and B² demonstrated the dangers that long-standing privileged access can pose.

None of these attacks touched the core consensus mechanisms of Ethereum or Arbitrum. Instead, they target application-level trust assumptions. It is worth noting that in multiple cases stolen funds flowed to Ethereum before being laundered further-a tactic we have seen repeatedly in past large-scale fund thefts.

This week's events add to the list of bridge and custody accidents in 2026. It reminds us that smart contract audits alone are not enough. Projects require equally strong operational security, rights management, and business logic checks that truly match the real economic value across chains.

For users and builders, the conclusion is straightforward: bridges and large token vaults remain high-value targets. Until the team demonstrates greater post-event repair capabilities and transparency, cross-chain activities are expected to continue to fluctuate and caution needs to be exercised.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP