AFX and Verus Bridge Lose $31.69M in Coordinated Same-Day Failures

AFX lost $24.15M via validator compromise and Verus lost $7.54M through unbacked withdrawals on July 22, as B² Network also halted staking after a breach.

Fractured digital bridge with three glowing breach points in black and orange, representing crypto security failures

AFX and the Verus-Ethereum bridge lost a combined $31.69 million within hours of each other on July 22, according to reporting by CryptoSlate – while B² Network separately suspended staking after unauthorized access to a contract upgrade authority, adding a third concurrent security failure across the Ethereum ecosystem.

AFX: $24.15M USDC Drained via Social Engineering and Validator Compromise

Security firm Blockaid detected the AFX exploit at approximately 21:30 UTC on July 22, flagging an Arbitrum transaction that moved 24.15 million USDC out of the bridge operated by AFX, a decentralized trading protocol on Arbitrum. The affected component was a third-party custody bridge – not Arbitrum’s native bridge – and AFX said the incident was isolated from its trading infrastructure and the broader Arbitrum network.

In preliminary findings published July 24, AFX attributed the exploit to coordinated social engineering and infrastructure compromise. According to the protocol, access originated in a development environment before escalating through internal build infrastructure and into validator systems – a supply-chain-style attack path that bypassed the on-chain mechanism by corrupting the operational layer that feeds it.

AFX said it was verifying balances, pursuing fund recovery, and preparing remediation steps. As of July 24, no completed return of funds or finalized compensation plan had been announced.

Verus Bridge: $7.54M in Unbacked Assets Approved Without Reserve Proof

Hours after the AFX incident, an Ethereum transaction showed the Verus-Ethereum bridge releasing 1,137.4528 ETH and seven additional token transfers. Blockaid valued the unbacked payouts at approximately $7.54 million.

Analysis from SlowMist identified the failure mechanism: the bridge approved eight withdrawals without verifying that matching assets backed them. SlowMist linked the vulnerability to the same broad cross-chain import-validation class exploited in a separate May 2026 attack on the same bridge, but noted the two incidents used different mechanics – meaning the May patch did not close the door on this variant.

That pattern of repeated exploitation on the same infrastructure is a critical data point for anyone assessing cross-chain bridge risk. The Verus bridge has now been successfully attacked twice in roughly two months via related but distinct flaws in how it validates cross-chain imports.

B² Network: Staking Suspended After Upgrade Authority Breach

B² Network‘s incident differs structurally from the two bridge exploits. The network reported unauthorized access to the upgrade authority of its staking contract – a governance-level control point rather than a bridge accounting mechanism. B² suspended normal staking operations during security reviews, said the issue was contained, and committed to full compensation for affected users.

Promotional graphic for B2 Network featuring a golden $B2 cryptocurrency coin on a lit stage.
The official launch timeline for the B2 Network token, scheduled for April 30, 2025.

B² did not disclose a loss amount, and its incident is therefore excluded from the $31.69 million combined figure. The network offered a manual exit path: users can request unstaking through its official Discord, with ownership-verified requests to be processed within one business day, while normal staking remains offline pending review completion.

The upgrade authority access vector – distinct from bridge import-validation failures and validator key compromise – illustrates that protocol-level admin controls carry their own attack surface, separate from the mechanisms most commonly associated with bridge exploits.

Three Different Failure Points, One Structural Pattern

What the three incidents share is not a common exploit technique but a common location: each attack succeeded at a control layer sitting outside base-chain consensus. AFX’s validator infrastructure, Verus’s bridge accounting logic, and B²’s staking contract upgrade authority each became the point where normal access failed – none of the failures required breaking Ethereum itself or manipulating Arbitrum’s sequencer.

That framing matters for risk assessment. Bridge and staking security debates often focus on smart contract audits, but the AFX incident specifically traces back to a compromised development environment – an upstream operational failure that no amount of on-chain code review would have caught. SlowMist’s finding that Verus’s July mechanics differed from its May exploit suggests the protocol’s remediation after the first attack was either incomplete or addressed only a subset of the underlying validation class.

The broader context reinforces the systemic reading. Cross-chain bridge exploits have accounted for substantial cumulative losses across the Ethereum ecosystem in 2026, with validator-based and import-validation-based designs consistently identified as high-risk components. The July incidents are consistent with that trend rather than anomalous within it – and Ethereum’s own price trajectory and ecosystem health remain tied to whether bridge security standards can keep pace with exploit sophistication, a tension directly relevant to ETH’s near-term market structure.

Digital padlock icon inside a glowing blue network sphere with connecting nodes on a dark starry background

What Comes Next for AFX, Verus, and B²

For AFX, the immediate question is whether fund recovery efforts produce any restitution, and what the remediation plan looks like for the validator infrastructure that was compromised. The protocol’s July 24 preliminary findings acknowledged the scope of the infrastructure breach but stopped short of any recovery timeline or compensation framework – both of which remain outstanding as of the reporting date.

For Verus, the more pointed concern is architectural. A second successful exploit via a related but distinct import-validation flaw suggests that patching individual attack vectors without restructuring the underlying validation model carries meaningful residual risk. Whether the protocol moves toward stricter reserve-proof requirements or a more fundamental redesign of its cross-chain accounting will determine the credibility of any post-incident bridge restart.

B² users seeking to exit staked positions remain dependent on the manual Discord process until normal staking resumes – a dependency on manual intervention that the primary source identified as a structural risk in its own right. Protocols that respond to upgrade authority breaches by routing users through off-chain coordination channels introduce operational fragility that is difficult to audit and slow to scale. The broader push across the Ethereum ecosystem toward more trust-minimized bridge designs – including light-client and ZK-based proof architectures – is directly motivated by the class of failures these three protocols encountered in a single day.

The next test across all three protocols is straightforward in principle and difficult in practice: whether recovery plans return funds at scale, whether cross-chain validation is restructured to verify economic backing before approving withdrawals, and whether upgrade authority is protected through mechanisms that do not make emergency exits contingent on manual review. None of those outcomes is guaranteed, and the market will be forced to price the difference between protocols that deliver on their post-exploit commitments and those that do not.

Follow CoinNews on X and Telegram for ongoing coverage of Ethereum ecosystem security events and market structure updates.

Source: CryptoSlate

About Author

Ifeanyi Egede

About Author

Ifeanyi Egede

Ifeanyi Egede

Ifeanyi Egede is a seasoned crypto journalist with six years of experience covering the dynamic world of cryptocurrencies and blockchain technology. Specializing in coin news, market analysis, crypto reviews, and comprehensive guides, Ifeanyi delivers insightful and accurate content that empowers readers to navigate the complexities of the crypto space. With a keen eye for market trends and a deep understanding of blockchain innovations, his work combines technical expertise with clear, engaging storytelling. Ifeanyi's contributions have been featured in leading crypto publications, establishing him as a trusted voice in the industry.
ABOUT COINNEWS
100k+
Active Monthly Users Around the World
50+
Guides and Reviews Articles
3
Years on the Market
8+
In-house Authors
At Coinnews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2022, Coinnews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.