Crypto infrastructure took another hit this week. Three separate security incidents across different protocols resulted in more than $35.5 million drained in combined losses. The attacks hit a cross-chain bridge, a custody bridge, and token permissions. They show once again that the real danger zones sit in how projects handle asset movement and control, not in the underlying blockchains themselves.
The biggest loss came from AFX Trade on Arbitrum, followed quickly by a troubling repeat breach at the Verus Ethereum Bridge. A third incident at B² Network rounded out a rough 24 hours for the space.
Verus Ethereum Bridge Falls Victim to Near-Identical Exploit Again
Just months after its May breach, the Verus Ethereum Bridge lost roughly $7.54 million. According to Blockaid, an attacker used a tiny amount of VRSC on the Verus side to trigger massive unbacked payouts on Ethereum, draining ETH, tBTC, USDC, USDT, and other reserves. The funds were quickly swapped to ETH and routed through privacy services. Full on-chain details here.
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
More details in 🧵— Blockaid (@blockaid_) July 23, 2026
This one stings because it looks painfully similar to the May attack that drained $11.58 million. Security researchers noted back then that the bridge checked signatures and proofs properly but missed verifying that the value sent on one side matched what was released on the other. The fact that a similar vector worked again raises real questions about how thorough the fixes were after the first incident.
AFX Trade Loses $24.15M USDC from Arbitrum Bridge
The largest single hit landed on July 22. Attackers drained approximately $24.15 million in USDC from a bridge operated directly by perpetuals protocol AFX Trade on Arbitrum. Blockaid spotted it early, and the stolen funds were swiftly bridged to Ethereum and converted into roughly 12,467 ETH.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol.
— Blockaid (@blockaid_) July 22, 2026
Important clarification: Arbitrum’s native bridge was not touched. Offchain Labs co-founder Steven Goldfeder confirmed the core L2 infrastructure stayed secure. The breach was isolated to AFX’s own custody setup. Full root cause details are still pending, but it appears tied to the protocol’s bridge authorization logic rather than the chain itself.
B² Network Hit by Privileged Permission Drain
In the third incident, B² Network lost around 8.59 million B2 tokens worth approximately $3.86 million. Analysts noted that a wallet holding elevated permissions moved the tokens before access was revoked. The attacker swapped them for WBNB, bridged onward, and continued routing through services like NEAR Intents toward privacy paths.
There may have been an exploit involving @BSquaredNetwork on BNB Chain.
The attacker drained 8.591M $B2 tokens worth $3.86M, swapped them for 5,409 WBNB ($3.11M), bridged the funds to Ethereum, and is currently moving them to Zcash via NEAR Intents.
— Specter (@SpecterAnalyst) July 22, 2026
The move triggered an immediate ~15% price drop in B2. The team publicly urged the attacker to return some funds or face legal consequences. This case stands out because it appears more operational a permissions issue than a classic smart contract bug.
What These Attacks Reveal
Three different protocols. Three different attack paths. Yet a clear pattern emerges: attackers are laser-focused on the layers where assets are actually held or transferred. Verus exposed weaknesses in economic validation across chains. AFX highlighted custody bridge risks. B² showed how dangerous lingering privileged access can be.
None of these touched core Ethereum or Arbitrum consensus. Instead, they targeted application-level trust assumptions. Notably, stolen funds in multiple cases flowed toward Ethereum before further laundering a recurring tactic we’ve seen in past large drains.
This week’s events add to a growing list of 2026 bridge and custody incidents. They serve as a reminder that smart contract audits alone aren’t enough. Projects need equally strong operational security, permission management, and business-logic checks that actually match real economic value across chains.
For users and builders, the takeaway is straightforward: bridges and large token treasuries remain high-value targets. Expect continued volatility and caution around cross-chain activity until teams demonstrate stronger post-incident fixes and transparency.














