Hackers steal $31.6M with 2 crypto bridge attacks within 7 hours

Published on July 23, 2026 • Expert Analysis
Hackers steal $31.6M with 2 crypto bridge attacks within 7 hours

The cryptocurrency landscape has once again been shaken by a series of rapid-fire security breaches. In a staggering display of precision and timing, hackers managed to siphon a combined $31.6 million from two separate cross-chain bridges in a window of just seven hours. The attacks targeted AFX, a decentralized perpetual exchange on Arbitrum, and the Verus Ethereum bridge, underscoring the persistent vulnerabilities inherent in the infrastructure that connects different blockchain networks.

The AFX Heist: $24.15 Million Vanishes from Arbitrum

The first blow landed on Wednesday, when AFX, a decentralized perpetual exchange (Perp DEX) operating on the Arbitrum network, suffered a catastrophic loss of approximately $24.15 million. According to on-chain data and security reports, the attacker managed to exploit a vulnerability within the platform's smart contracts to drain assets from its liquidity pools.

The attack on AFX was characterized by its speed. The exploiter gained unauthorized access to the exchange's funds and rapidly transferred them to external wallets to avoid detection. While AFX serves as a critical hub for traders looking to leverage positions on Arbitrum, the breach has highlighted a recurring theme in the DeFi space: the "flash-attack" capability where attackers leverage complex smart contract loopholes to execute drains in a single transaction block.

The Arbitrum community and security auditors are currently dissecting the incident to determine whether the breach was the result of a logic error in the contract or a compromised administrative key. For AFX, the immediate priority is damage control and the attempt to track the stolen funds via blockchain forensics.

Verus Ethereum Bridge: The Second Strike

Just hours after the AFX exploit, the onslaught continued with a targeted attack on the Verus Ethereum bridge. While the financial magnitude was smaller than the AFX heist, the timing suggests a coordinated effort or, at the very least, a period of heightened vulnerability across cross-chain protocols.

Cross-chain bridges are designed to allow users to transfer assets between disparate blockchains—in this case, between the Verus network and Ethereum. However, these bridges are often the "weakest link" in the crypto ecosystem because they act as centralized honeypots of locked collateral. The attacker exploited a flaw in the bridge's validation mechanism, allowing them to mint or withdraw assets without providing the corresponding collateral on the opposite chain.

Combined with the AFX loss, the Verus attack brings the total stolen amount to $31.6 million. The speed with which these attacks occurred—within a seven-hour window—indicates that the attackers were likely monitoring multiple protocols simultaneously, waiting for the optimal moment to strike.

Why Crypto Bridges Remain Prime Targets

To understand why bridges continue to be the primary target for hackers, one must look at their architectural complexity. A bridge requires a set of smart contracts on two different chains to communicate. This "interoperability layer" creates a massive attack surface.

Most bridge attacks fall into three categories:

In the recent cases of AFX and Verus, the vulnerabilities likely resided in the contract logic, allowing the attackers to bypass the security checks intended to verify the legitimacy of the fund transfers.

The Ripple Effect on DeFi Confidence

These incidents occur at a time when the Decentralized Finance (DeFi) sector is striving to regain institutional trust. High-profile losses of over $30 million in a single afternoon serve as a grim reminder that "code is law," and if the code is flawed, the consequences are immediate and irreversible.

Investors are increasingly wary of "bridge risk." The industry is now seeing a shift toward more secure alternatives, such as atomic swaps and more rigorous formal verification of smart contracts. However, as long as the demand for cross-chain liquidity grows, the incentive for hackers to find these "holes" remains incredibly high.

Conclusion: The Path Toward Greater Security

The theft of $31.6 million from AFX and Verus is a wake-up call for the Arbitrum and Ethereum ecosystems. It emphasizes the need for real-time monitoring tools and "circuit breakers" that can pause bridge activity when anomalous transactions are detected.

For the average user, the lesson is clear: diversification is key. Storing significant assets in a single bridge or protocol carries inherent risks. As the industry evolves, the move toward decentralized validators and more transparent auditing processes will be essential to stop the bleeding and secure the future of the decentralized web.

Read Also:

Trade on BybitGet up to $30,000 in rewards
Register →
Join BinanceEarn up to $100 USD in rewards
Register →