Hackers Steal $31.6M in Bridge Attacks Within Seven Hours
Hackers drained more than $31.6 million from two unrelated crypto bridges within seven hours, targeting infrastructure operated by AFX Trade and Verus Protocol.
AFX lost about $24.15 million in USDC, while the Verus-Ethereum Bridge suffered a separate $7.5 million attack. Neither protocol had announced completed recovery of the stolen assets when the incidents were reported.
Five Validator Signatures Approved AFX’s $24.15M Withdrawal
Blockchain security firm Blockaid detected the AFX attack at 9:30 p.m. UTC on July 22. The attacker withdrew 24.15 million USDC from a cross-chain bridge operated by the Arbitrum-based perpetual futures protocol.
Blockaid CEO Ido Ben-Natan said the evidence was consistent with five hot validator keys being compromised. Blockaid said the valid signatures satisfied the bridge’s required quorum, allowing its smart contracts to approve the withdrawal as designed rather than through an on-chain logic flaw.
AFX Attacker Converted Stolen USDC Into 12,467 ETH
The attacker moved the USDC from Arbitrum to Ethereum and exchanged it for about 12,467 ETH. Offchain Labs CEO Steven Goldfeder said Arbitrum’s native bridge was not affected because the transaction originated from a third-party protocol.
That distinction leaves the AFX incident tied to its own bridge infrastructure rather than Arbitrum’s core bridge. AFX had not published a technical explanation or compensation plan when the incident was reported.
Verus Bridge Loses $7.5M After Earlier $11.58M Breach
Hours later, an attacker drained about $7.5 million from the Verus-Ethereum Bridge. The stolen reserves included Ether, tBTC, USDC, USDT, EURC, MKR and scrvUSD.
Blockaid said the attacker used the bridge’s import path to trigger unbacked payouts on Ethereum.
The method appeared similar to a May attack that removed about $11.58 million from the same bridge, although the latest transaction came from a different wallet.
Version 1.2.17 Failed to Prevent Second Verus Attack
Verus had recently completed a network upgrade and phased restoration following the May breach.
Version 1.2.17 introduced stricter transaction proofs and prepared upgraded Ethereum contracts intended to verify that submitted imports matched valid exports from the Verus network.
The second reported breach leaves unresolved how the upgraded bridge remained vulnerable. Verus had not released a post-mortem for the July attack when the incident was reported.
No Stolen Funds Have Been Confirmed Recovered
Blockaid said it was working with the Arbitrum team and contacting AFX to contain the first incident. The next confirmed steps are identifying how both attacks occurred, tracing the stolen funds, and determining whether either protocol can restore the missing reserves.
Until post-mortems are published, AFX’s suspected validator-key compromise and Verus’s import-path exploit remain separate investigations with no confirmed completed recovery.