2026-07-25, 11:25 AM

Two Ethereum bridges lose $31.7M within hours as third protocol halts staking

AFX and the Verus-Ethereum bridge suffered about $31.69 million in combined losses within hours of each other, while B² Network separately suspended token staking after unauthorized access to a contract upgrade authority.

Blockaid said it detected the AFX exploit at about 21:30 UTC on July 22. An Arbitrum transaction recorded 24.15 million USDC leaving the bridge operated by AFX, a decentralized trading protocol on Arbitrum.

AFX suspended its USDC custody bridge and said the incident was isolated from its trading infrastructure, mainnet, and the Arbitrum network. The affected component was a third-party bridge, not Arbitrum’s native bridge.

In preliminary findings published July 24, AFX attributed the incident to coordinated social engineering and infrastructure compromise. The protocol said access appeared to begin in a development environment before escalating into internal build infrastructure and validator systems.

The next big DeFi exploit will start before the code is deployed
Related Reading

The next big DeFi exploit will start before the code is deployed

A new malware campaign targeting crypto developers shows how attackers can move upstream, stealing GitHub tokens, SSH keys, cloud credentials, wallets, and environment variables before a protocol ever ships vulnerable code.
May 26, 2026
·
Gino Matos

AFX said it was verifying balances, pursuing fund recovery and preparing remediation. As of July 24, it had not announced a completed return of funds or a finalized compensation plan.

Hours after the AFX incident, an Ethereum transaction showed the Verus bridge releasing 1,137.4528 ETH and seven token transfers. Blockaid valued the unbacked payouts at about $7.54 million.

SlowMist’s analysis said the bridge approved eight withdrawals without proving that matching assets backed them. The firm linked the failure to the same broad cross-chain import-validation class as a May exploit, but said the two attacks used different mechanics.

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk
Related Reading

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk

The incident forced users to confront the part of rollup security that usually stays invisible: whether they can still withdraw when the bridge layer breaks.
Jun 23, 2026
·
Liam 'Akiba' Wright

B²’s incident was not disclosed as a bridge exploit. The network said there was unauthorized access to its staking contract’s upgrade authority. B² suspended normal staking during security reviews, said the issue was contained, and promised full compensation to affected users. It had not documented completed restitution as of July 24.

B² also offered a manual exit: users could request unstaking through its official Discord, with ownership-verified requests to be processed within one business day. The network did not state a loss amount, so its incident is excluded from the $31.69 million bridge-loss total. Until normal staking resumes, that manual review is the route B² offered users seeking to withdraw staked tokens.

DeFi’s automated yield protocols were built for retail, now they just add another layer of risk
Related Reading

DeFi’s automated yield protocols were built for retail, now they just add another layer of risk

Stake DAO’s vsdCRV exploit shows how automated yield products can turn DeFi complexity into a black box for retail users.
May 28, 2026
·
Gino Matos

The three episodes exposed different controls outside base-chain consensus. AFX’s custody and validator infrastructure, Verus’s bridge-accounting checks, and B²’s staking-contract upgrade authority each became the point where normal access failed.

For users, the next test is whether recovery plans return funds, whether cross-chain validation verifies economic backing and whether upgrade authority is protected without making emergency exits depend on manual intervention.

com”>CryptoSlate.