Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked

Bridge exploits dominated the week, accounting for the majority of the nearly $48 million stolen across six separate crypto attacks.

Written By Dishita Malvania
Published 2026-07-26·Updated 1 month ago
Make The Crypto Times preferred on GoogleGoogle
Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked

The week of July 19 to July 25 delivered another punishing stretch for crypto security, with bridge exploits at AFX Trade, Wanchain, and Verus, a Solana flash loan drain at Allbridge Core, a staking contract seizure at B² Network, an OTC pool manipulation at Lien Finance, and a social hit on Robinhood CEO Vlad Tenev’s X account pushing weekly confirmed damage past $47 million.

The stretch lands directly on top of the previous week’s $20M loss across Ostium, Across, Cascade, and DeFiTuna. It extends the shift laid out in CertiK’s H1 2026 report, which found Web3 lost more than $1.31 billion across 344 incidents in the first half, with wallet compromises and infrastructure breaches now the costliest attack surface.

AI Summary
Show
Crypto security breaches cost over $47 million in a week, extending $1.31 billion in losses across 344 incidents in H1 2026.
Exploits target third-party bridges and infrastructure, with AFX Trade and Wanchain losing $24.15 million and $10 million, respectively.
Repeated attacks on Verus Ethereum Bridge and B² Network highlight vulnerabilities in key management and permission scoping, sparking calls for improved security.

AFX Trade Drained of $24.15M in Arbitrum Bridge Exploit

The biggest incident of the week hit AFX Trade, an Arbitrum-based decentralized perpetual exchange, on July 22 at 21:30 UTC. Blockchain security firm PeckShield was the first to flag the breach, reporting on X that the protocol had been drained of roughly $24.15 million in USDC.

The exploiter bridged the stolen funds from Arbitrum to Ethereum and swapped them for 12,467.5 ETH, sitting in wallet 0x6276…ebAC at the time of disclosure. According to the PeckShield alert, the wallet has been placed under active on-chain surveillance.

Responding to concerns that Arbitrum’s core infrastructure had been compromised, Steven Goldfeder, Co-Founder of Offchain Labs, issued a public clarification on X. Goldfeder stated that the transaction in question originated from a third-party protocol, and that the Arbitrum native bridge had not been hacked or exploited in any way. The distinction contained the compromise to AFX Trade’s own third-party bridge setup and limited the systemic risk to the broader Layer 2 ecosystem.

The Scale of the Drain

On-chain analytics platform Lookonchain later grouped the AFX Trade breach with two same-day incidents under the tag “Hackers’ Day,” pegging combined losses at $35.55 million. The breakdown covered AFX Trade at $24.15 million, the Verus Ethereum Bridge at $7.55 million, and B² Network at $3.86 million.

Latest update: AFX Trade has not published a post-mortem or a compensation plan at the time of writing. Blockchain security firms continue to track wallet 0x6276…ebAC for any onward movement of the swapped ETH, and no additional transactions have been reported since the initial swap. The full breakdown of Crypto’s ‘Hackers’ Day’ covers the wider context.

Wanchain Cardano Bridge Loses $10M in NIGHT Token Theft

Two days earlier, security firm BlockSec’s Phalcon monitor reported on July 21 that Wanchain’s bridge connecting Cardano to BNB Chain had been exploited, resulting in the theft of approximately 515.2 million NIGHT tokens worth roughly $10 million.

The incident unfolded in just four rapid transactions over an eight-minute window. According to initial analysis shared by BlockSec, the root cause was a non-injective signed-message encoding flaw in the TreasuryCheck validator. 

The signed message was constructed by concatenating 14 variable-length redeemer fields without proper delimiters or length prefixes, allowing different field-value combinations to produce identical byte strings and hashes, and therefore valid signature reuses.

BlockSec traced the redeemer’s uniqueId field back to a legitimate BSC transaction that authorized only 3,110 NIGHT. The same signature was reused on Cardano to extract 203,001,692 NIGHT, a roughly 65,000x inflation via field-boundary ambiguity in the raw-concatenated hash.

The attacker funneled the stolen tokens into a primary wallet on Cardano before aggressively liquidating roughly 90% of the haul through DEX swaps and DeFi protocols. At prevailing prices around $0.01950 per token, the drained amount equated to roughly $10 million in realized value.

Midnight Distances Itself From the Breach

NIGHT, the native token of the privacy-focused Midnight blockchain incubated by Input Output, plunged more than 30% to 40% intraday, hitting a new all-time low. Midnight Network quickly issued a statement clarifying that the core Midnight protocol and its Layer 1 remain uncompromised, with the breach confined to Wanchain’s third-party bridging infrastructure.

Latest update: Wanchain paused its bridge and said in an official statement that the incident has its full attention, promising full transparency once the investigation is complete. The event adds to a running list of bridge exploits that have already cost the industry billions since 2017, including Ronin at $624 million and Wormhole at $326 million.

Verus Ethereum Bridge Drained of $7.54M in Repeat Attack

The Verus Ethereum Bridge has been drained for the second time in just over two months, with an attacker siphoning roughly $7.54 million in assets on July 23, 2026, by abusing the same import path weaponized against the protocol in May.

Onchain security firm Blockaid flagged the incident in real time, and independent researcher exvulsec confirmed the exploit signature within minutes of the drain. The stolen basket spans seven assets held in the bridge’s Ethereum-side reserves, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

The exploit was executed in a single primary transaction at approximately 03:45 UTC on July 23. Etherscan records show the drain occurred through target bridge contract 0x715…D7F63, with the attacker EOA at 0xBda…855c and the loot wallet at 0xCF…42D54. The single largest movement was a transfer of 1,137 ETH from the bridge to the attacker-controlled wallet, alongside proportionate withdrawals of the tokenised BTC, stablecoin, and MKR reserves.

Same Bug Class as the May Breach

Blockaid described the July exploit as belonging to the same bug class as the May 18 breach, with the attacker using the bridge’s submitImports function to trigger payouts that were not backed by matching assets on the source side. 

The Ethereum-side contract released real reserves in response to an import claim that did not carry corresponding value locked on the Verus side, the same architectural gap identified in the May post-mortem.

As previously reported by The Crypto Times, the May attacker later returned 4,052.4 ETH worth around $8.5 million after Verus offered settlement terms, keeping 1,350 ETH as an agreed bounty.

Latest update: VerusCoin has not issued a public statement on the July 23 exploit at the time of writing. According to onchain data compiled after the drain, the attacker consolidated the stolen basket into 3,916 ETH through decentralised exchange routes and then began routing portions of it through Tornado Cash. Blockaid and exvulsec have asked exchanges, stablecoin issuers, and analytics providers to flag both the attacker EOA and the loot wallet for any downstream movement.

B² Network Loses $3.86M via Staking Contract Seizure

Alongside the AFX Trade and Verus incidents on July 23, Bitcoin Layer 2 solution B² Network reported a loss of roughly $3.86 million after an attacker seized upgrade authority over the network’s staking contract.

According to Lookonchain, which grouped the three same-day incidents under the “Hackers’ Day” tag, the B² Network breach was a permissions-based failure rather than a cryptographic one. The attacker obtained control of the contract’s upgrade rights and used them to alter the protocol’s logic, siphoning staker funds in the process.

B² Network is built on zero-knowledge proof verification and had not previously reported a security incident of this scale. Blockaid framed the day’s clustered incidents as a continued shift in attacker focus toward off-chain infrastructure, where key management, permission scoping, and validation logic remain softer targets than the underlying smart contracts themselves.

Latest update: B² Network has not yet released a detailed post-mortem or a compensation plan. Blockchain security firms continue to track wallet activity linked to the exploit, and no confirmed root-cause disclosure has been published.

Allbridge Core Loses $1.65M to Second Flash Loan Attack Since 2023

Cross-chain protocol Allbridge paused its Core bridge on July 19 after an attacker drained roughly $1.65 million from its Solana liquidity pools through flash loan manipulation.

According to blockchain security firms PeckShield and CertiK, the attacker borrowed $1.12 million in USDC through a flash loan from Solana lending protocol Kamino, then rapidly swapped USDC and USDT to distort the pools’ internal ratios before withdrawing assets at favorable rates. Onchain Lens confirmed the technique and said the stolen funds were bridged to Ethereum address 0x651…ffDe before further dispersion.

Allbridge posted on X that the protocol had been paused as a precaution, urging liquidity providers in affected pools to withdraw immediately. The team also said the manipulation left its pools imbalanced, creating a temporary arbitrage window, and asked traders who profited from the distortion to return funds to compensate affected liquidity providers.

An Echo of 2023

The incident echoes a flash loan attack in April 2023 that drained roughly $573,000 from Allbridge’s BNB Chain pools. In its post-mortem at the time, Allbridge committed to deploying a single liquidity pool per chain, an architecture intended to make same-transaction flash loan manipulation structurally impossible. The July exploit targeted a USDC and USDT pool operating side by side on Solana, the multi-stablecoin configuration the earlier fix was meant to eliminate.

Latest update: Allbridge has not published a final accounting of how much of the $1.65 million has been recovered. The protocol recovered around $465,000 in a white-hat arrangement after the 2023 incident, and the team has a template for renegotiation should the July attacker be receptive.

Lien Finance Loses $542K in USDC Bond Pricing Exploit

Ethereum-based structured products protocol Lien Finance was exploited on July 24 for approximately 542,144 USDC after an attacker manipulated pricing inside the protocol’s GeneralizedDotc bond-to-ERC20 OTC pools.

The incident, first flagged by DefimonAlerts and independently amplified by exvulsec, is being classified as a public protocol logic gap. The attacker deployed an orchestration contract at 0xe74…8062e and registered a new bond group on BondMakerCollateralizedEth using a maliciously crafted payoff function. 

Because the registration process is open and does not require governance approval, the attacker was able to introduce a bond group whose economic characteristics did not reflect any real underlying collateral value.

Once the bond group was live, the newly minted bond tokens were routed through Lien’s GeneralizedDotc OTC pools. The pricing logic in the internal _calcRateBondToErc20 function priced the crafted bonds at a level that dramatically overvalued them relative to the actual collateral backing. 

Roughly 542,144 USDC was extracted from pool liquidity that had originated from allowances granted by the liquidity provider at 0xA961…14d80, with the attacker wallet 0x0D7d…1808a receiving the full sum in the primary exploit transaction.

Security researchers are categorising the incident as an oracle and price manipulation exploit rather than a classical smart contract reentrancy or access control failure. The pattern is a familiar one for 2026, with structural parallels to the $285 million Drift Protocol exploit in April, where an attacker whitelisted a fabricated token as collateral and drained real assets against it.

Latest update: Lien Finance has not issued a public statement on the July 24 incident at the time of writing. The exploit transaction, attacker EOA, and orchestration contract have been circulated for downstream monitoring by exchanges, stablecoin issuers, and analytics providers.

Robinhood CEO’s X Account Compromised in Memecoin Push

While most of the week’s damage sat inside DeFi contracts, a social engineering hit rounded out the picture. On July 23, Robinhood confirmed that CEO Vlad Tenev’s X account had been compromised and used to promote a fraudulent memecoin to the platform’s millions of followers.

Robinhood said in an X post that the unauthorized post had been removed and that the company was working with X to restore access. The team has not disclosed how the compromise occurred or whether any other systems were affected.

The Robinhood incident is the latest example of verified social media accounts linked to major crypto companies and executives being compromised. Earlier this year, Arbitrum DAO’s official governance X account was breached under similar circumstances. Security researchers have noted that such attacks typically exploit the credibility of verified accounts rather than vulnerabilities in blockchain networks themselves.

The Bigger Picture

Every major loss this week traced back to infrastructure or off-chain systems rather than smart contract code executing as designed. AFX Trade fell to a third-party bridge with compromised hot validator signing keys. Wanchain fell to a signed-message encoding flaw in a validator script. Verus fell to a repeated unbacked payout path. B² Network fell to a stolen upgrade authority. 

Allbridge fell to a pool manipulation technique it had promised to structurally eliminate three years ago. Lien Finance fell to permissionless bond registration paired with a rate calculation function that trusted its inputs. Robinhood fell to a compromised social media account.

That fits neatly into the shift documented in CertiK’s H1 2026 findings, where wallet compromise was the costliest category of the half at more than $444 million. It also stacks on top of a $328 million running tab for bridge-specific exploits earlier in the year, a figure that has since crossed materially higher after the July drains. The attack surface keeps climbing up the stack, away from the code that gets audited and toward the rules, keys, and off-chain infrastructure that mostly do not.

Also Read: BitMart to Shut Down as BMX Token Crashes 70%, Just Days After BitMEX Exit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

trade[XYZ] Launches Event Contracts on Hyperliquid Using HIP-4 
trade[XYZ] Launches Event Contracts on Hyperliquid Using HIP-4 
Base App Returns to Coinbase Wallet A Year After Rebranding 
Base App Returns to Coinbase Wallet A Year After Rebranding 
Smartphone displaying IREN Ltd stock performance chart against an IREN logo background.
IREN Stock Price Prediction for September 2026: Is $50 Next?
USDC coin standing in front of Circle and Noble logos.
Circle to End USDC and CCTP V1 Support on Noble by January 2027
Glowing Trezor logo and padlock icon on a red binary code background.
Trezor Details Brevo Breach Behind Fake Security Alert

Find Us on Socials

You may also like

HTX Faces Unverified Data Breach Claim Over 6.5M User Records

HTX Faces Unverified Data Breach Claim Over 6.5M User Records

Aave logo alongside a retro computer icon and an "MCP" badge set against a light purple gradient background

Aave Launches Official MCP Server for AI Assistants to Read Data and Build Transactions

Hooded figure working on a laptop displaying the Nomic logo in front of a wall featuring the Osmosis logo

Osmosis Freezes 22.65 BTC After Nomic Exploit Hits Alloyed BTC Backing

Smartphone displaying Tectonic crypto app in front of glowing Cronos logo

Cronos Rewound 10,961 Blocks to Reverse Tectonic Hack, $9.19M Still Missing

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information