Crypto Bridge Attack Spree: $31M Stolen From AFX and VerusCoin
Crypto Scams

Crypto Bridge Attack Spree: $31M Stolen From AFX and VerusCoin

By Samuel

Hackers drained $31M from AFX Trade and VerusCoin bridges in July 2026. Full breakdown of both exploits and fund movements.

Two separate bridge exploits drained more than $31 million from crypto protocols within days of each other. Arbitrum-based AFX Trade lost $24.15 million in USDC on July 22. 

VerusCoin’s Ethereum Bridge lost roughly $7.54 million in a related but distinct attack.

Security firm Blockaid flagged both incidents as they unfolded. The two hacks push 2026’s bridge exploit total higher, adding fresh pressure on cross-chain infrastructure.

AFX Trade’s Arbitrum Bridge Drained of $24 Million

Blockaid detected the AFX exploit at 21:30 UTC on July 22. 

The attacker compromised five hot-validator signatures on the AFX-operated custody bridge. This let them bypass the quorum requirement and authorize an unauthorized withdrawal. 

Stolen USDC moved to an Ethereum wallet before the attacker swapped it for 12,467.5 ETH, according to PeckShieldAlert. The funds currently sit in wallet 0x6276…ebAC.

AFX suspended bridge operations immediately after detecting the breach. The company said its trading infrastructure, mainnet, and the wider Arbitrum network remain unaffected. 

Arbitrum Foundation’s Steven Goldfeder confirmed the native Arbitrum bridge was not involved. He said the exploited transaction originated from a third-party protocol.

AFX later confirmed the stolen funds remain in the attacker’s address. 

Security firm SlowMist reported the wallet to the Crypto Defense Alliance, a network of exchanges and ecosystem partners tracking illicit funds. Zellic, the firm that audited AFX’s bridge code, joined the investigation. 

AFX said it will continue sharing verified updates as the case develops.

VerusCoin Bridge Hit Again With $7.5 Million Loss

Blockaid also flagged a second exploit targeting the VerusCoin Ethereum Bridge. 

The attacker used the bridge’s import path to trigger payouts not backed by real reserves. This drained roughly $7.54 million across ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Funds moved from the bridge contract to a wallet ending in C142D54.

Blockaid noted the exploit shares key traits with a May 2026 incident on the same bridge. Both attacks used the same contract and the same entry path. 

Blockaid described the pair as sharing an identical bug class. A different attacker carried out the July exploit using a separate wallet.

PeckShieldAlert reported the attacker began laundering the stolen funds through Tornado Cash shortly after the exploit. VerusCoin had not issued a public statement on the July incident at the time of writing. 

The May attack, by contrast, drained $11.58 million after an attacker manipulated the bridge’s cross-chain export process using a transaction that cost roughly $10 in fees.

Read also

Wanchain Cardano Bridge Exploited, 515M NIGHT Drained From Treasury

Security Firms Respond as Bridge Exploits Rise

Both incidents highlight recurring weaknesses in how bridges verify cross-chain transfers. 

The May VerusCoin exploit stemmed from a missing validation check on source-chain export amounts. Blockaid said the bug class resembles issues seen in the Wormhole and Nomad exploits from 2022.

Security teams across both cases moved quickly to trace stolen assets. SlowMist, Zellic, and PeckShieldAlert all played roles in monitoring wallet activity and confirming attack details. 

Neither AFX nor VerusCoin has disclosed a timeline for restoring full bridge functionality. Both cases remain open as investigators continue tracking the flow of stolen funds across chains.

Samuel

About the Author

Samuel

Leave a Reply