In July 2026, two major cross-chain bridges were attacked, causing losses of more than US$31 million.
In July 2026, security breaches occurred in two major cross-chain bridges one after another. The attackers launched attacks on AFX Trade and VerusCoin, stealing more than $31 million in very short periods of time. Blockaid, a blockchain security company, discovered and disclosed the two incidents in time during the attack, exacerbating industry concerns about security vulnerabilities in the underlying bridge infrastructure of decentralized finance (DeFi).
AFX Trade Bridge was hacked on Arbitrum and lost US$24 million.
Blockaid first detected an attack on the AFX Trade protocol in the Arbitrum ecosystem at 21:30 (UTC) on July 22. The hacker successfully broke the signatures of five hot-verified nodes on the protocol's escrow bridge, circumvented the required quorum verification, and performed an unauthorized transfer and stole USDC tokens worth $24.15 million.
The security team revealed that the stolen USDC was transferred to an Ethereum wallet and subsequently exchanged for 12,467.5 ETH. PeckShieldAlert tracked the flow of the funds and found that they were still stored at the address 0x6276... ebAC.
Blockaid said they identified this as a targeted attack against a bridge operated by AFX on Arbitrum. The incident resulted in the attacker withdrawing approximately $24.15 million in USDC from the agreement in one go.
AFX suspended bridge operations immediately after discovering the vulnerability and clarified that its core trading infrastructure and the broader Arbitrum network were not affected. Steven Goldfeder, who represents the Arbitrum Foundation, also separately confirmed that the Arbitrum native bridge had not been breached and attributed the unauthorized withdrawal to integration issues with third-party agreements.
AFX revealed that all stolen funds are still in the attacker's wallets. Security company SlowMist has reported the wallet address to the Crypto Defense Alliance, an industry network that tracks stolen digital assets. Zellic, which previously audited the bridge code, has joined the ongoing investigation.
AFX promises to provide regular updates on progress as more facts are verified and recovery efforts continue to advance.
Small Dictionary: Arbitrum is Ethereum's Layer 2 expansion solution. It aims to provide a faster and cheaper trading experience by processing transactions outside the Ethereum main chain and then settling the results back to the main network.
The VerusCoin Bridge was attacked again and lost US$7.5 million.
Blockaid also flagged a security vulnerability in the VerusCoin Ethereum Bridge, resulting in an additional loss of approximately US$7.54 million. The attackers manipulated the bridge's import mechanism, triggered payments lacking the necessary asset reserves, and stole multiple cryptocurrencies, including ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD. Stolen funds were transferred from the bridge contract to a wallet ending in C142D54.
Analysis showed that there were similarities between the attack and the incident that occurred on the same bridge in May 2026. Both attacks exploited the same vulnerability, but the July attack appears to have come from a different attacker using a new wallet.
Blockaid pointed out that the recent vulnerability exploited the same contract and entry path as the May attack, and described both incidents as having the same vulnerability category, indicating a persistent flaw in the bridge's transfer verification logic.
PeckShieldAlert reported that attackers soon began laundering stolen assets through Tornado Cash. As of the time of the incident, VerusCoin had not issued any public statements.
The May incident on the VerusCoin Bridge involved manipulation of its cross-chain export process, allowing attackers to steal $11.58 million for relatively low transaction fees.
Small Dictionary: VerusCoin is a blockchain platform focused on privacy and interoperability that allows users to transfer assets between different chains through its bridge technology.
Event Summary
·Bridge: AFX Trade (Arbitrum) --Bug date: July 22, 2026--Amount stolen: US$24.15 million--Assets affected: USDC
·Bridge: VerusCoin Ethereum Bridge--Bug date: July 23, 2026--Amount stolen: US$7.54 million-Assets affected: ETH, tBTC, USDC, USDT, EURC, MKR, scrvUSD
·Bridge: VerusCoin Ethereum Bridge--Bug Date: May 2026--Amount stolen: US$11.58 million--Affected assets: Multiple currencies
Security Industry Response and Continuing Investigation
These incidents have once again aroused the industry's attention to the recurring security vulnerabilities of cross-chain bridges. Previously, bridges such as Wormhole and Nomad also suffered major attacks in 2022.
Blockaid pointed out that the root cause of the VerusCoin attack was a lack of checking the value of incoming transfers, a vulnerability that has previously appeared in this area. Security companies including SlowMist and PeckShieldAlert are actively monitoring stolen funds and working with exchanges and other ecosystem partners to track suspicious wallet activity.
Neither AFX nor VerusCoin provided a specific date for resuming bridge operations. Both investigations are still ongoing, and authorities and security teams are working to track the movement of stolen assets, and no recovery or remediation plans have been announced.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
EURC