Three DeFi Bridge Hacks Drain $35.6 Million in a Single Day
Key Takeaways
- •More than $35.6 million was stolen from three decentralized finance protocols—AFX Trade, BSquared Network, and VerusCoin—during a series of simultaneous cross-chain bridge exploits.
- •The AFX Trade bridge on Arbitrum suffered the largest loss of approximately $24.2 million, potentially due to compromised validator keys authorizing a fraudulent withdrawal.
- •Hackers stole roughly $3.86 million from BSquared Network and immediately laundered the proceeds through various platforms to obscure tracking.
- •The VerusCoin bridge lost $7.54 million after an attacker reused a previously known contract vulnerability that allowed unbacked payouts.

Three separate crypto bridge exploits wiped out more than $35.6 million from major DeFi protocols in a single day, hitting AFX Trade, BSquared Network, and VerusCoin. The attacks exposed persistent security vulnerabilities across cross-chain bridge infrastructure, and the attackers have already moved most of the stolen funds.
Blockchain investigators noted that each exploit followed a distinct attack vector, intensifying concerns over bridge security throughout the decentralized finance ecosystem. Cross-chain bridges have been among the most targeted categories of DeFi infrastructure since 2022, with cumulative losses from bridge exploits measured in the billions of dollars, because they lock up large pools of assets on one chain to mint representations on another — creating a concentrated honeypot that attackers repeatedly probe for signature logic, validator key management, and contract verification flaws.
AFX Bridge Loses $24.2 Million
The largest of the three hacks targeted AFX's bridge on Arbitrum, where attackers stole 24.15 million USDC, worth approximately $24.2 million.
According to blockchain security firm Blockaid, the bridge approved the fraudulent withdrawal using five of the seven signatures in its validator system, suggesting the attackers may have compromised validator keys or gained access to the bridge's backend infrastructure.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol. Our team has been working with the incredible folks on…
— Blockaid (@blockaid_) July 22, 2026
After stealing the funds, the attacker quickly moved the USDC from Arbitrum to Ethereum. The AFX team stated it is working with the Arbitrum team and security firms to investigate the exploit and trace the stolen funds.
BSquared Network Loses Nearly $3.9 Million in B2 Token Hack
The second attack targeted the BSquared Network, where hackers stole 8.59 million B2 tokens, valued at approximately $3.86 million.
The attacker immediately sold the stolen B2 tokens for 5,409 BNB, worth roughly $3.01 million. The funds were then bridged to Ethereum, converted into ETH and USDT, and subsequently routed through NEAR Intents and HOT Protocol in an effort to obscure tracking.
Security teams continue to monitor the wallet as the investigation remains active.
VerusCoin Hit Again as Old Bridge Bug Resurfaces
The VerusCoin Ethereum bridge suffered the third attack, losing $7.54 million worth of assets, including Ether (ETH), tokenized Bitcoin (tBTC), USDC, USDT, DAI, and several other tokens.
According to SlowMist, the attack reused the same import path contract bug that hackers exploited during a separate $11.5 million hack in May 2026. The vulnerability allowed the attacker to trigger unbacked payouts, meaning the bridge released assets without verifying whether sufficient funds backed the transactions.
After draining the bridge, the attacker converted the stolen assets into 3,916 ETH, worth approximately $7.5 million, before sending the funds to Tornado Cash, an Ethereum-based mixing service sanctioned by the U.S. Treasury's Office of Foreign Assets Control since August 2022, significantly complicating recovery efforts.