The largest of the three exploits targeted AFX Trade, a decentralized perpetuals exchange operating on Arbitrum . Security firm Blockaid detected the exploit at approximately 21:30 UTC on July 22, 2026 .
The attacker compromised five out of seven bridge validator hot-signing keys. The on-chain smart contract logic was not bypassed — five legitimate validator signatures authorized the withdrawal, meaning the smart contract executed exactly as designed . The attacker drained approximately $24.15 million in USDC from AFX's cross-chain bridge, bridged the funds to Ethereum, and swapped them for about 12,467.5 ETH, consolidating the ETH in a single wallet .
AFX Trade responded by suspending bridge operations, launching an investigation with external security experts, and publicly offering the hacker a 30% bounty (roughly $7.2 million) for returning the remaining 70% of funds . The protocol stated that its trading infrastructure, mainnet, and other components were not affected . Offchain Labs, which develops Arbitrum, confirmed the native Arbitrum bridge was not compromised — only the third-party AFX-operated bridge .
The Verus-Ethereum cross-chain bridge was hit around 03:45 UTC on July 23, 2026 . The attack vector was a forged cross-chain proof: the attacker exploited the bridge's "import path" to trigger payouts on the Ethereum side that were not backed by corresponding locked assets on the Verus chain .
Crucially, this was the same contract entry path and vulnerability used in an $11.58 million exploit in May 2026 — a flaw that had not been fully remediated . After the May attack, Verus had recovered most funds via a bounty, then redeposited them into the same bridge on July 8, 2026 — just two weeks before the repeat exploit .
The attacker drained approximately $7.54 million in a mix of assets including approximately 1,137 ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD . The stolen assets were converted into roughly 3,916.1 ETH and then sent to Tornado Cash for mixing . Security firms Blockaid and PeckShield investigated the incident, which drew sharp criticism for the unresolved vulnerability .
The B² Network, a Bitcoin L2 project on BNB Chain, lost approximately $3.86 million in an attack detected by chain analyst Specter on July 23 (UTC+8) . Unlike the other two incidents, this was not a cryptographic bridge break but an administrative key compromise: the attacker gained unauthorized access to a contract upgrade authority, allowing them to drain B2 tokens .
The attacker drained approximately 8.591 million B2 tokens, swapped them into 5,409 WBNB (~$3.11 million), bridged the funds to Ethereum, and reportedly routed them toward Zcash via NEAR Intents . The sell pressure from the dump sent B2's price down sharply . B² Network responded by suspending token staking after the unauthorized access was detected .
On July 25, 2026 — about three days after the initial exploit — the AFX Trade hacker began actively laundering the stolen funds . The attacker used THORChain, a decentralized cross-chain liquidity protocol, to swap ETH for BTC . This method bypasses centralized exchange KYC requirements and is commonly used for obfuscation.
As of reports published on July 25, approximately 655 ETH (out of the ~12,467.5 ETH total) had been converted into roughly 18.86 BTC . On-chain analysts Ash and EmberCN reported that the hacker started the swaps about one hour before the reports were published . The bulk of the approximately 12,467 ETH remained in the hacker's wallet at the time, with the conversion to BTC via THORChain still in progress .