Between July 22 and 23, 2026, three cross chain protocols (AFX Trade, Verus Ethereum, and B² Network) lost a combined $35.55 million to exploits that targeted off chain validator keys, a recurring import path vulnerab... The AFX attacker began moving stolen ETH to BTC through THORChain on July 25, and all three prot...

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What were the key details of the AFX Trade, Verus-Ethereum, and B² Network exploits on July 22-23. Article summary: Between July 22–23, 2026, three cross-chain protocols — AFX Trade, Verus-Ethereum, and B² Network — were exploited in rapid succession, resulting in combined losses exceeding $35 million. Each attack targeted a different. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Between July 22–23, 2026, three cross-chain protocols — AFX Trade, Verus-Ethereum, and B² Network — were exploited in rapid succession, resulting in combined losses exceeding $35 million. Each attack targeted a different architectural weakness: compromised off-chain validator keys, a recurring import-path bug, and unauthorized contract upgrade authority. The AFX attacker has already begun moving funds through THORChain, while the protocols responded with bounties and legal-immunity offers.
The largest of the three incidents targeted AFX Trade, a decentralized perpetuals exchange on Arbitrum. The attacker compromised five hot-validator signing keys on the AFX cross-chain bridge. Those five keys carried 7,142 of 10,000 validator power, exceeding the two-thirds quorum required to authorize withdrawals. Security firm Blockaid confirmed that no on-chain smart contract logic was bypassed — the bridge's code performed exactly as designed .
Approximately 24.15 million USDC was stolen, which the attacker immediately swapped into roughly 12,467.4 ETH . On July 25, the attacker began converting ETH to BTC via THORChain. In the first known transaction, 655.4 ETH was swapped for 18.86 BTC. On-chain analyst EmberCN flagged this as continued laundering activity, noting the majority of stolen coins remained in the hacker's wallet at the time of reporting
.
AFX Trade offered a $7.2 million bounty — the attacker could keep 30% of the stolen funds if 70% (about $16.9M) was returned . Offchain Labs co-founder Steven Goldfeder confirmed the attack targeted a third-party bridge, not Arbitrum's native infrastructure
.
The Verus-Ethereum bridge was drained on July 23 through a forged cross-chain import — the same contract and entry path exploited in a May 2026 attack that cost $11.58 million. Blockaid confirmed the attack reused the bridge's import path to trigger unbacked Ethereum-side payouts .
Approximately $7.54 million was stolen in ether (ETH), tokenized bitcoin (tBTC), and a spread of stablecoins including USDC, USDT, EURC, MKR, and scrvUSD. The attacker converted the haul into about 3,916.1 ETH, and some funds were subsequently routed toward Tornado Cash .
This was the second major Verus bridge breach in roughly two months, raising serious questions about whether the root cause was ever fully patched. Blockaid noted that the July transaction came from a different attacker and wallet than the May exploit, meaning the vulnerability was independently exploitable .
B² Network, a Bitcoin scaling solution, lost approximately 8.591 million B2 tokens (worth ~$3.86 million) when an attacker obtained unauthorized access to the upgrade authority for its token staking contract on BNB Chain. This was an administrative-privilege exploit, not a traditional on-chain vulnerability .
The attacker sold the B2 tokens for 5,409 WBNB (~$3.11 million), bridged to Ethereum, and the funds were reportedly being routed toward Zcash via NEAR Intents . On-chain analysts noted that the wallet responsible for the theft had been granted the necessary privileged role since 2025 — a role only revoked after the unauthorized transfer occurred, suggesting a possible insider credential leak
.
B² Network paused staking and offered legal immunity to the attacker in exchange for a partial refund, with a 10% return reportedly discussed. The protocol said it would fully compensate affected users .
Off-chain key management remains the weakest link. The AFX exploit was not a protocol bug but a failure of key custody — five hot-validator signatures were compromised and used to meet the bridge quorum. Security firm Blockaid noted that the on-chain logic functioned exactly as designed .
Repeat vulnerabilities are not being fully resolved. Verus's bridge was exploited via the same import-path vector twice within two months, suggesting the May 2026 fix was incomplete or the underlying architecture was fundamentally flawed .
Administrative upgrade authority is a single point of failure. B² Network's exploit shows that privileged roles (contract upgrade keys) can be as dangerous as private keys, and their compromise allows attackers to drain entire token supplies without exploiting any smart contract logic bug .
Laundering infrastructure is mature. The AFX attacker moved stolen USDC to ETH within minutes, then began converting ETH to BTC via THORChain on July 25, demonstrating that cross-chain atomic swaps and decentralized exchangers are now the standard path for obfuscating bridge-exploit proceeds . The B² Network attacker similarly routed funds through NEAR Intents toward Zcash
.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Between July 22 and 23, 2026, three cross chain protocols (AFX Trade, Verus Ethereum, and B² Network) lost a combined $35.55 million to exploits that targeted off chain validator keys, a recurring import path vulnerab...
Between July 22 and 23, 2026, three cross chain protocols (AFX Trade, Verus Ethereum, and B² Network) lost a combined $35.55 million to exploits that targeted off chain validator keys, a recurring import path vulnerab... The AFX attacker began moving stolen ETH to BTC through THORChain on July 25, and all three protocols attempted negotiations (bounties or legal immunity) with their attackers.