Cryptoslate Ethereum Bridges Suffer $31.7M Losses from Hack Attacks
Article Content
- •Hackers stole over $31.6 million from two Ethereum bridges within hours.
- •The AFX bridge loss was attributed to social engineering and infrastructure compromise.
- •Verus bridge payouts were unbacked, similar to a previous exploit in May.
On July 22, 2026, hackers exploited vulnerabilities in two Ethereum bridges, AFX and Verus, resulting in a combined loss of $31.69 million. AFX reported a loss of $24.15 million due to unauthorized access to its bridge, attributed to social engineering and infrastructure compromise. The Verus bridge was exploited shortly after, leading to $7.54 million in unbacked payouts. A third protocol, B² Network, suspended staking following unauthorized access to its staking contract's upgrade authority, although it did not report a specific loss amount. The incidents highlight ongoing security risks in cross-chain bridges, which are critical for asset transfers between blockchains. Recovery plans and compensation for affected users are still pending. The attacks utilized compromised keys rather than exploiting smart contract vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AFX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…