Approximately 24.15 million USDC was stolen, which the attacker immediately swapped into roughly 12,467.4 ETH . On July 25, the attacker began converting ETH to BTC via THORChain. In the first known transaction, 655.4 ETH was swapped for 18.86 BTC. On-chain analyst EmberCN flagged this as continued laundering activity, noting the majority of stolen coins remained in the hacker's wallet at the time of reporting .
AFX Trade offered a $7.2 million bounty — the attacker could keep 30% of the stolen funds if 70% (about $16.9M) was returned . Offchain Labs co-founder Steven Goldfeder confirmed the attack targeted a third-party bridge, not Arbitrum's native infrastructure .
The Verus-Ethereum bridge was drained on July 23 through a forged cross-chain import — the same contract and entry path exploited in a May 2026 attack that cost $11.58 million. Blockaid confirmed the attack reused the bridge's import path to trigger unbacked Ethereum-side payouts .
Approximately $7.54 million was stolen in ether (ETH), tokenized bitcoin (tBTC), and a spread of stablecoins including USDC, USDT, EURC, MKR, and scrvUSD. The attacker converted the haul into about 3,916.1 ETH, and some funds were subsequently routed toward Tornado Cash .
This was the second major Verus bridge breach in roughly two months, raising serious questions about whether the root cause was ever fully patched. Blockaid noted that the July transaction came from a different attacker and wallet than the May exploit, meaning the vulnerability was independently exploitable .
B² Network, a Bitcoin scaling solution, lost approximately 8.591 million B2 tokens (worth ~$3.86 million) when an attacker obtained unauthorized access to the upgrade authority for its token staking contract on BNB Chain. This was an administrative-privilege exploit, not a traditional on-chain vulnerability .
The attacker sold the B2 tokens for 5,409 WBNB (~$3.11 million), bridged to Ethereum, and the funds were reportedly being routed toward Zcash via NEAR Intents . On-chain analysts noted that the wallet responsible for the theft had been granted the necessary privileged role since 2025 — a role only revoked after the unauthorized transfer occurred, suggesting a possible insider credential leak .
B² Network paused staking and offered legal immunity to the attacker in exchange for a partial refund, with a 10% return reportedly discussed. The protocol said it would fully compensate affected users .
| Protocol | Date | Amount | Entry Vector |
|---|---|---|---|
| AFX Trade | July 22 | $24.15M | Compromised off-chain validator signing keys |
| Verus-Ethereum | July 23 | $7.54M | Reused import-path vulnerability from May 2026 |
| B² Network | July 23 | $3.86M | Unauthorized upgrade authority on staking contract |
| Total | ~$35.55M |
Off-chain key management remains the weakest link. The AFX exploit was not a protocol bug but a failure of key custody — five hot-validator signatures were compromised and used to meet the bridge quorum. Security firm Blockaid noted that the on-chain logic functioned exactly as designed .
Repeat vulnerabilities are not being fully resolved. Verus's bridge was exploited via the same import-path vector twice within two months, suggesting the May 2026 fix was incomplete or the underlying architecture was fundamentally flawed .
Administrative upgrade authority is a single point of failure. B² Network's exploit shows that privileged roles (contract upgrade keys) can be as dangerous as private keys, and their compromise allows attackers to drain entire token supplies without exploiting any smart contract logic bug .
Laundering infrastructure is mature. The AFX attacker moved stolen USDC to ETH within minutes, then began converting ETH to BTC via THORChain on July 25, demonstrating that cross-chain atomic swaps and decentralized exchangers are now the standard path for obfuscating bridge-exploit proceeds . The B² Network attacker similarly routed funds through NEAR Intents toward Zcash .