Crypto Bridge Attack: $31M Stolen From AFX Trade and VerusCoin Bridges

A crypto bridge attack spree drained over $31M from two cross-chain protocols in two days, raising concerns about bridge security and validation logic. On July 22, Blockaid flagged a compromise of the Arbitrum-based AFX Trade bridge. The attacker obtained access to five hot-validator signatures tied to AFX’s custody bridge, bypassing quorum checks and authorizing an unauthorized withdrawal. About 24.15M USDC was drained and moved to an Ethereum wallet, where it was reportedly swapped into 12,467.5 ETH. AFX suspended bridge operations immediately, stating its trading infrastructure and mainnet (and the wider Arbitrum network) were unaffected. Arbitrum Foundation’s Steven Goldfeder said the native Arbitrum bridge was not involved and the source transaction came from a third-party protocol. AFX confirmed the stolen funds remain in the attacker’s address; investigations included SlowMist and Zellic (who audited the bridge code), while SlowMist reported the wallet activity to the Crypto Defense Alliance. On July 23, Blockaid detected a second crypto bridge attack on the VerusCoin Ethereum Bridge. Using the bridge import path, the attacker triggered payouts not backed by real reserves. The loss was about 7.54M across ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Funds were transferred from the bridge contract to a wallet ending in C142D54. PeckShieldAlert said laundering began via Tornado Cash shortly after the exploit. Blockaid noted the July exploit resembled an earlier May incident on the same bridge. With multiple crypto bridge attacks tied to shared bug classes and delayed public responses from both teams, traders may see near-term risk sentiment pressure around cross-chain infrastructure and stablecoin-linked flows.
Bearish
Bridge exploits typically pressure risk sentiment because they threaten user funds, disrupt liquidity routing, and can trigger broader concerns about cross-chain verification. Here, two crypto bridge attack incidents (AFX Trade on Arbitrum and VerusCoin on Ethereum) combined for $31M+, with funds moving quickly to swap and laundering venues (e.g., Tornado Cash). Traders often respond to similar bridge-hack headlines by reducing exposure to cross-chain-related tokens, widening spreads, and front-running de-risking flows from affected bridges. In the short term, market impact may be concentrated around stablecoin corridors (USDC/USDT) and bridges’ operational halts, which can create temporary imbalances in liquidity and on-chain activity. Longer term, repeated bug-class similarities to earlier incidents (e.g., 2022 bridge failures) can increase regulatory and risk-premium for bridge infrastructure and may accelerate migration toward more robust designs (audited, formally verified, or alternative transfer mechanisms). Even though AFX claimed its broader Arbitrum infrastructure is unaffected, the recurrence supports a continued negative backdrop for cross-chain security narratives.