Three Crypto Exploits Drain Over $35 Million in a Single Day
- Three crypto protocols lost over $35 million in a single day due to exploits targeting bridges and blockchain infrastructure.
- Investors should remain cautious as bridge security vulnerabilities continue to be a significant risk in decentralized finance.
- Ongoing investigations into these attacks emphasize the importance of enhanced security measures for crypto protocols.
The crypto industry suffered another wave of exploits on July 23, with three protocols collectively losing approximately $35.55 million in attacks affecting bridges and blockchain infrastructure.
The largest incident involved AFX Trade, an Arbitrum-based protocol, which lost around $24.15 million after attackers exploited one of its bridge contracts. According to blockchain security firms Blockaid and PeckShield, the stolen USDC was bridged to Ethereum and swapped into roughly 12,467 ETH shortly after the attack. Offchain Labs CEO Steven Goldfeder clarified that Arbitrum’s native bridge was not compromised, stressing that the exploit was isolated to AFX’s own bridge implementation.
The second-largest incident targeted the Verus Ethereum Bridge, with approximately $7.55 million reportedly drained. The exploit comes just months after Verus suffered a larger bridge compromise in May, which prompted extensive recovery efforts, mandatory software upgrades, and protocol changes aimed at restoring the network.
The third exploit affected B² Network, resulting in losses of roughly $3.86 million, according to on-chain security trackers. At the time of writing, limited technical details about the attack have been disclosed publicly.
Is today Hackers’ Day?
Three exploits have already happened today, with total losses of $35.55M.
AFX Trade(@AFX_XYZ) was exploited for $24.15M.
Verus(@VerusCoin) Ethereum bridge was exploited for $7.55M.
B² Network(@BSquaredNetwork) was exploited for $3.86M. pic.twitter.com/9v1KxWtaHV
— Lookonchain (@lookonchain) July 23, 2026
Bridge Infrastructure Remains a Prime Target
All three incidents underscore a familiar pattern in decentralized finance: attackers continue to focus on bridges and cross-chain infrastructure, where complex smart contract logic and large pools of locked liquidity create attractive targets.
The AFX exploit appears to have originated from the protocol’s proprietary bridge rather than the underlying Arbitrum network. Investigators from Blockaid, PeckShield, and the AFX team are continuing to analyze the attack vector, while efforts are underway to trace the stolen assets across Ethereum.
Meanwhile, Verus has already experienced one of this year’s most technically sophisticated bridge attacks, making today’s reported losses another setback for the ecosystem despite its recent recovery efforts.
July’s Security Losses Continue to Climb
The latest exploits add to an already costly month for the crypto industry. July has seen a steady stream of high-profile incidents, with cumulative losses now significantly exceeding June’s total. You can check out our hack and scam index for a more detailed breakdown of many of the exploits.
While investigations into all three attacks remain ongoing, the incidents once again highlight that bridge security continues to be one of the most significant risks facing decentralized finance, despite increased auditing, monitoring, and real-time detection efforts across the industry.
