Hackers drained $31M from AFX Commerce and VerusCoin bridges in July 2026. Full breakdown of each exploits and fund actions.
Two separate bridge exploits drained greater than $31 million from crypto protocols inside days of one another. Arbitrum-based AFX Commerce misplaced $24.15 million in USDC on July 22.
VerusCoin’s Ethereum Bridge misplaced roughly $7.54 million in a associated however distinct assault.
Safety agency Blockaid flagged each incidents as they unfolded. The 2 hacks push 2026’s bridge exploit whole greater, including contemporary strain on cross-chain infrastructure.
AFX Commerce’s Arbitrum Bridge Drained of $24 Million
Blockaid detected the AFX exploit at 21:30 UTC on July 22.
The attacker compromised 5 hot-validator signatures on the AFX-operated custody bridge. This allow them to bypass the quorum requirement and authorize an unauthorized withdrawal.
Blockaid detected an exploit at 2026-07-22 21:30 UTC concentrating on @AFX_XYZ, a protocol on @arbitrum. The exploit was particular to a bridge that AFX operates. Roughly 24.15M USDC has been drained thus removed from the protocol.
Our group has been working with the unbelievable people on… https://t.co/0Qd9ve5gPB
— Blockaid (@blockaid_) July 22, 2026
Stolen USDC moved to an Ethereum pockets earlier than the attacker swapped it for 12,467.5 ETH, in accordance to PeckShieldAlert. The funds at the moment sit in pockets 0x6276…ebAC.
AFX suspended bridge operations instantly after detecting the breach. The corporate stated its buying and selling infrastructure, mainnet, and the broader Arbitrum community stay unaffected.
Arbitrum Basis’s Steven Goldfeder confirmed the native Arbitrum bridge was not concerned. He stated the exploited transaction originated from a third-party protocol.
AFX later confirmed the stolen funds stay within the attacker’s tackle.
Safety agency SlowMist reported the pockets to the Crypto Protection Alliance, a community of exchanges and ecosystem companions monitoring illicit funds. Zellic, the agency that audited AFX’s bridge code, joined the investigation.
AFX stated it is going to proceed sharing verified updates because the case develops.
VerusCoin Bridge Hit Once more With $7.5 Million Loss
Blockaid additionally flagged a second exploit concentrating on the VerusCoin Ethereum Bridge.
The attacker used the bridge’s import path to set off payouts not backed by actual reserves. This drained roughly $7.54 million throughout ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Funds moved from the bridge contract to a pockets ending in C142D54.
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
An attacker used the bridge import path to set off unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
Extra particulars in 🧵— Blockaid (@blockaid_) July 23, 2026
Blockaid famous the exploit shares key traits with a Could 2026 incident on the identical bridge. Each assaults used the identical contract and the identical entry path.
Blockaid described the pair as sharing an an identical bug class. A distinct attacker carried out the July exploit utilizing a separate pockets.
PeckShieldAlert reported the attacker started laundering the stolen funds by Twister Money shortly after the exploit. VerusCoin had not issued a public assertion on the July incident on the time of writing.
The Could assault, against this, drained $11.58 million after an attacker manipulated the bridge’s cross-chain export course of utilizing a transaction that price roughly $10 in charges.
Learn additionally:
Wanchain Cardano Bridge Exploited, 515M NIGHT Drained From Treasury
Safety Corporations Reply as Bridge Exploits Rise
Each incidents spotlight recurring weaknesses in how bridges confirm cross-chain transfers.
The Could VerusCoin exploit stemmed from a lacking validation test on source-chain export quantities. Blockaid stated the bug class resembles points seen within the Wormhole and Nomad exploits from 2022.
Safety groups throughout each circumstances moved rapidly to hint stolen belongings. SlowMist, Zellic, and PeckShieldAlert all performed roles in monitoring pockets exercise and confirming assault particulars.
Neither AFX nor VerusCoin has disclosed a timeline for restoring full bridge performance. Each circumstances stay open as investigators proceed monitoring the circulation of stolen funds throughout chains.
