0x7bcd388f7bcd…7bcd388c
Three Bridge Exploits Drain $35.6M From DeFi in Single Day
AFX, BSquared and VerusCoin bridges lost a combined $35.6 million in one day to three distinct exploits, with attackers already laundering funds through Ethereum, NEAR Intents and Tornado Cash.

Outputs
Three bridge exploits on July 22, 2026 drained over $35.6 million: AFX ($24.2M USDC on Arbitrum), BSquared ($3.86M in B2 tokens) and VerusCoin ($7.54M).
Blockaid found the AFX withdrawal was approved by five of seven validator signatures, indicating a validator key or backend compromise.
SlowMist linked the VerusCoin attack to the same unremediated import path contract bug exploited in a $11.5M May 2026 hack; the attacker routed 3,916 ETH to Tornado Cash.
Three separate cross-chain bridge exploits removed more than $35.6 million from decentralized finance protocols in a single day, according to on-chain records and analyses from blockchain security firms Blockaid and SlowMist. The attacks hit AFX Trade, BSquared Network and VerusCoin, and the attackers have already moved most of the stolen funds through laundering pipelines that complicate recovery.
The three incidents followed distinctly different attack vectors, reinforcing long-standing concerns that bridge infrastructure remains the weakest structural layer in DeFi.
AFX loses $24.2 million on Arbitrum
The largest loss hit AFX's bridge on Arbitrum, where an attacker drained 24.15 million USDC, roughly $24.2 million. Blockaid detected the exploit at 21:30 UTC on July 22, 2026, and confirmed in an on-chain alert that the withdrawal was approved with five signatures from the bridge's seven-validator multisig.
That signature pattern points to a compromise of validator keys or the bridge's backend rather than a smart contract flaw. An attacker holding five of seven validator keys can authorize any withdrawal without breaking consensus rules. After the drain, the hacker bridged the USDC from Arbitrum to Ethereum mainnet.
The AFX team said it is working with the Arbitrum team and security firms to investigate the exploit and trace the stolen funds.
BSquared loses $3.86 million in B2 token theft
The second attack targeted BSquared Network, where the attacker stole 8.59 million B2 tokens worth approximately $3.86 million. The attacker immediately sold the tokens for 5,409 BNB, about $3.01 million, then bridged the proceeds to Ethereum, converted them into ETH and USDT, and routed the funds through NEAR Intents and HOT Protocol to obscure the trail.
Security teams continue to monitor the wallet as the investigation remains active. The rapid token dump compressed the realized proceeds by roughly $850,000 relative to the notional theft size, illustrating the liquidity discount attackers typically accept for speed.
VerusCoin bridge hit by repeat vulnerability
The VerusCoin Ethereum bridge suffered the third and most methodologically significant attack, losing $7.54 million in assets including ETH, tokenized Bitcoin (tBTC), USDC, USDT, DAI and several other tokens.
According to SlowMist, the attacker reused the same import path contract bug exploited in a separate $11.5 million hack of the bridge in May 2026. The flaw lets an attacker trigger unbacked payouts, meaning the bridge releases assets without verifying that sufficient collateral backs the transaction. The recurrence indicates the vulnerability was never fully remediated after the first incident, bringing the bridge's cumulative losses from this single bug class to roughly $19 million.
After draining the bridge, the attacker converted the stolen assets into 3,916 ETH, worth about $7.5 million, and sent the funds to Tornado Cash, the sanctioned Ethereum mixer that remains the default laundering endpoint for large exploits.
Operational consequences
The trio of incidents illustrates three distinct failure modes now dominant in bridge security: key compromise of validator sets, direct token theft with rapid DEX disposal, and unremediated contract bugs inviting repeat exploitation. For AFX, a five-of-seven validator compromise means the incident is fundamentally an operational security failure, not a code audit issue, and rebuilding signer infrastructure is a prerequisite for any relaunch. For VerusCoin, a second successful exploit of the same import path within two months will intensify scrutiny of the project's remediation process and its residual solvency against unbacked payouts.
Recovery prospects are slim in all three cases given the speed of cross-chain movement, mixer routing and chain-hopping through NEAR Intents. Investigations with Arbitrum, Blockaid, SlowMist and other security teams remain active, and further wallet-tracking disclosures are expected as on-chain forensics progress.
via s3.tradingview.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles