Need help? Support
BITCOIN
Tether Dominance USDT.D

DeFi bridges lose $35M to exploits

Published 546 words 3 min read

TLDR

Several DeFi bridges and cross-chain protocols were hit in coordinated exploits, losing roughly $35 million in under a day.

  1. AFX Trade, Verus Ethereum Bridge, and B Network were drained in separate attacks that together exceeded $35 million in losses.
  2. The exploits stemmed from compromised keys and flawed bridge logic, not broken cryptography, reinforcing bridges as a structural weak point in DeFi.
  3. Users should watch how these teams handle compensation, audits, and key management, and treat smaller, lightly-audited bridges with extra caution.

Deep Dive

1. What Was Exploited And For How Much

In a roughly six-hour window on 23 Jul 2026, at least three cross-chain systems were exploited for over $35 million in total losses, according to blockchain data analyzed in multiple attacks hours apart.

  1. Arbitrum-based AFX Trade lost about $24.15 million in USDC via an AFX-operated bridge, after an attacker used validator signing keys to authorize withdrawals, as detailed in AFX Trade drained of $24 million.
  2. The Verus Ethereum Bridge was hit again, losing around $7.54 million by abusing its import path to trigger unbacked payouts, in a repeat of a May bug class described in Verus Ethereum bridge hacked again.
  3. B Network, a Bitcoin scaling protocol, lost roughly $3.86 million when an attacker seized upgrade authority over its staking contract, letting them change logic and drain funds.
What this means

The headline figure comes from multiple independent incidents that all targeted cross-chain infrastructure rather than base-layer chains like Bitcoin or Ethereum.

2. Why Bridges Keep Failing

These incidents did not break cryptography; they abused governance and design weaknesses such as key control, upgrade powers, and validation gaps, as highlighted in CoinDesks protocols lose $35 million.

Bridges and staking contracts often hold large pooled reserves while relying on a small set of validator keys or admin roles; if those keys are compromised or if logic allows unbacked payouts, attackers can move funds without invalidating the underlying chain. Verus redeposited returned funds into the same vulnerable bridge, and AFXs bridge reportedly had weak test coverage and unresolved issues, a culture critique captured in the Hackers Day coverage from three protocols drained of $35 million.

What this means

The main risk is operational and governance design; users are exposed when teams underestimate key management, testing, and fail-safe controls on contracts that custody large TVL.

3. What To Watch Next As A DeFi User

Short term, watch for:

  1. Official post-mortems, compensation plans, and any freezes or blacklists on stolen funds from AFX, Verus, and B Network.
  2. Concrete changes in bridge design, such as multi-sig or threshold keys, time-locked upgrades, and stronger validation for cross-chain messages.
  3. Movement of funds from these exploits and whether similar attack patterns appear on other bridges, which could signal broader systemic risk.

For your own usage, it is safer to favor battle-tested, well-audited bridges with transparent governance and to limit exposure sitting on smaller, experimental bridges, especially when TVL is high relative to the projects maturity.

Confidence: high multiple reputable security firms and news outlets report consistent loss figures and attack mechanisms.

Conclusion

The reported $35 million in losses reflects a cluster of bridge and cross-chain exploits that hit several protocols in quick succession, not a single failure. The common thread is weak key and upgrade governance on infrastructure that controls large asset pools. How affected teams redesign their bridges and contracts now will shape both user trust and the next wave of DeFi security standards.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top