Attackers hit three cross-chain systems in a six-hour window. AFX Trade lost $24 million from a compromised USDC custody bridge; Verus and B² Network gave up another $11.4 million between them.
AFX Trade lost $24.15 million on Wednesday after an attacker compromised the validator signing keys on its USDC custody bridge and drained the reserves.
The exchange, a perpetual DEX built on Arbitrum, said the compromise was contained to its own third-party bridge infrastructure. Offchain Labs co-founder Steven Goldfeder confirmed that Arbitrum's native bridge was not touched. The attacker moved the stolen USDC to Ethereum and, according to blockchain security firm PeckShield, swapped it into 12,467.5 ETH now sitting in a single wallet. The taken amount was substantially all of AFX Trade's total value locked at the time.
Ken C, AFX's head of growth, made a public overture within hours: return 70% of the stolen funds and keep 30% as a "white hat bounty," with no legal action. The engineering team is investigating the attack vector, and PeckShield and Blockaid are helping trace the assets. As of Wednesday evening, the attacker had not responded.
The AFX loss was the largest in a six-hour spree that drained more than $35 million across three separate cross-chain systems. Each attack exploited a different weakness.
The Verus Ethereum bridge was drained of $7.55 million a few hours before AFX went down. The attacker used the bridge import path to trigger unbacked Ethereum-side payouts, walking away with ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD from the reserves. The technique is virtually identical to a May attack on the same infrastructure that cost the protocol $11.58 million. Forensics indicates a different wallet address this time. Two exploits, two months apart, on the same import path.
B² Network was the third target. An attacker gained unauthorised control of the upgrade authority on the network's token staking contract, the administrative permission that governs how the contract behaves. Once inside, they moved 8.59 million B2 tokens and dumped them for 5,409 BNB, netting roughly $3.01 million after slippage. Total loss: $3.86 million. B² has offered the attacker legal immunity in exchange for a partial refund.
Three attacks, three architectures, one common surface. AFX's bridge was compromised at the signing-key layer. Verus was compromised in the bridge-logic layer. B² was compromised at the governance layer. Every element that centralises trust in a cross-chain system was in play, and each mechanism has a long record of catastrophic failure.
Bridges have been the worst-performing category of crypto infrastructure for the entire life of the industry. The Wormhole bridge lost $320 million in 2022. The Ronin bridge lost $625 million the same year. Nomad lost $190 million. Poly Network lost $611 million in 2021. The architecture is the same each time: reserves held on one chain, wrapped tokens issued on another, and a validator set or admin key that becomes the single point of failure the entire structure depends on. Compromise that key, and the reserves walk.
For AFX Trade specifically, the loss is close to existential. A perpetual DEX's competitive edge is deep on-chain liquidity, and $24 million was substantially all of it. The 70/30 bounty offer is the standard opening move, but recovery is not guaranteed. AFX will have to explain to its liquidity providers how third-party bridge software with unaudited or under-audited signing infrastructure ended up custodying essentially all user deposits.
July has now seen roughly $100 million in crypto hack losses, most of it from bridge and cross-chain exploits. Perpetual DEXs on Arbitrum continue to expand as an alternative to centralised venues, and Wednesday's incident will feed the argument that their custody-in-bridge design is structurally weaker than the in-house books run by Hyperliquid or the departing BitMEX. Attackers keep finding the seams. The engineers keep writing them in.