Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    The Robinhood Chain Paradox Built for Tokenized Stocks, Dominated by Memecoins
    The Robinhood Chain Paradox: Built for Tokenized Stocks, Dominated by Memecoins
  • Opinion
    OpinionShow More
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked

Bridge exploits dominated the week, accounting for the majority of the nearly $48 million stolen across six separate crypto attacks.

Written By Dishita Malvania
Published 2 hours ago
Make The Crypto Times preferred on GoogleGoogle
Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked

The week of July 19 to July 25 delivered another punishing stretch for crypto security, with bridge exploits at AFX Trade, Wanchain, and Verus, a Solana flash loan drain at Allbridge Core, a staking contract seizure at B² Network, an OTC pool manipulation at Lien Finance, and a social hit on Robinhood CEO Vlad Tenev’s X account pushing weekly confirmed damage past $47 million.

The stretch lands directly on top of the previous week’s $20M loss across Ostium, Across, Cascade, and DeFiTuna. It extends the shift laid out in CertiK’s H1 2026 report, which found Web3 lost more than $1.31 billion across 344 incidents in the first half, with wallet compromises and infrastructure breaches now the costliest attack surface.

AI Summary
Show
Crypto security breaches cost over $47 million in a week, extending $1.31 billion in losses across 344 incidents in H1 2026.
Exploits target third-party bridges and infrastructure, with AFX Trade and Wanchain losing $24.15 million and $10 million, respectively.
Repeated attacks on Verus Ethereum Bridge and B² Network highlight vulnerabilities in key management and permission scoping, sparking calls for improved security.

AFX Trade Drained of $24.15M in Arbitrum Bridge Exploit

The biggest incident of the week hit AFX Trade, an Arbitrum-based decentralized perpetual exchange, on July 22 at 21:30 UTC. Blockchain security firm PeckShield was the first to flag the breach, reporting on X that the protocol had been drained of roughly $24.15 million in USDC.

The exploiter bridged the stolen funds from Arbitrum to Ethereum and swapped them for 12,467.5 ETH, sitting in wallet 0x6276…ebAC at the time of disclosure. According to the PeckShield alert, the wallet has been placed under active on-chain surveillance.

Responding to concerns that Arbitrum’s core infrastructure had been compromised, Steven Goldfeder, Co-Founder of Offchain Labs, issued a public clarification on X. Goldfeder stated that the transaction in question originated from a third-party protocol, and that the Arbitrum native bridge had not been hacked or exploited in any way. The distinction contained the compromise to AFX Trade’s own third-party bridge setup and limited the systemic risk to the broader Layer 2 ecosystem.

The Scale of the Drain

On-chain analytics platform Lookonchain later grouped the AFX Trade breach with two same-day incidents under the tag “Hackers’ Day,” pegging combined losses at $35.55 million. The breakdown covered AFX Trade at $24.15 million, the Verus Ethereum Bridge at $7.55 million, and B² Network at $3.86 million.

Latest update: AFX Trade has not published a post-mortem or a compensation plan at the time of writing. Blockchain security firms continue to track wallet 0x6276…ebAC for any onward movement of the swapped ETH, and no additional transactions have been reported since the initial swap. The full breakdown of Crypto’s ‘Hackers’ Day’ covers the wider context.

Wanchain Cardano Bridge Loses $10M in NIGHT Token Theft

Two days earlier, security firm BlockSec’s Phalcon monitor reported on July 21 that Wanchain’s bridge connecting Cardano to BNB Chain had been exploited, resulting in the theft of approximately 515.2 million NIGHT tokens worth roughly $10 million.

The incident unfolded in just four rapid transactions over an eight-minute window. According to initial analysis shared by BlockSec, the root cause was a non-injective signed-message encoding flaw in the TreasuryCheck validator. 

The signed message was constructed by concatenating 14 variable-length redeemer fields without proper delimiters or length prefixes, allowing different field-value combinations to produce identical byte strings and hashes, and therefore valid signature reuses.

BlockSec traced the redeemer’s uniqueId field back to a legitimate BSC transaction that authorized only 3,110 NIGHT. The same signature was reused on Cardano to extract 203,001,692 NIGHT, a roughly 65,000x inflation via field-boundary ambiguity in the raw-concatenated hash.

The attacker funneled the stolen tokens into a primary wallet on Cardano before aggressively liquidating roughly 90% of the haul through DEX swaps and DeFi protocols. At prevailing prices around $0.01950 per token, the drained amount equated to roughly $10 million in realized value.

Midnight Distances Itself From the Breach

NIGHT, the native token of the privacy-focused Midnight blockchain incubated by Input Output, plunged more than 30% to 40% intraday, hitting a new all-time low. Midnight Network quickly issued a statement clarifying that the core Midnight protocol and its Layer 1 remain uncompromised, with the breach confined to Wanchain’s third-party bridging infrastructure.

Latest update: Wanchain paused its bridge and said in an official statement that the incident has its full attention, promising full transparency once the investigation is complete. The event adds to a running list of bridge exploits that have already cost the industry billions since 2017, including Ronin at $624 million and Wormhole at $326 million.

Verus Ethereum Bridge Drained of $7.54M in Repeat Attack

The Verus Ethereum Bridge has been drained for the second time in just over two months, with an attacker siphoning roughly $7.54 million in assets on July 23, 2026, by abusing the same import path weaponized against the protocol in May.

Onchain security firm Blockaid flagged the incident in real time, and independent researcher exvulsec confirmed the exploit signature within minutes of the drain. The stolen basket spans seven assets held in the bridge’s Ethereum-side reserves, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

The exploit was executed in a single primary transaction at approximately 03:45 UTC on July 23. Etherscan records show the drain occurred through target bridge contract 0x715…D7F63, with the attacker EOA at 0xBda…855c and the loot wallet at 0xCF…42D54. The single largest movement was a transfer of 1,137 ETH from the bridge to the attacker-controlled wallet, alongside proportionate withdrawals of the tokenised BTC, stablecoin, and MKR reserves.

Same Bug Class as the May Breach

Blockaid described the July exploit as belonging to the same bug class as the May 18 breach, with the attacker using the bridge’s submitImports function to trigger payouts that were not backed by matching assets on the source side. 

The Ethereum-side contract released real reserves in response to an import claim that did not carry corresponding value locked on the Verus side, the same architectural gap identified in the May post-mortem.

As previously reported by The Crypto Times, the May attacker later returned 4,052.4 ETH worth around $8.5 million after Verus offered settlement terms, keeping 1,350 ETH as an agreed bounty.

Latest update: VerusCoin has not issued a public statement on the July 23 exploit at the time of writing. According to onchain data compiled after the drain, the attacker consolidated the stolen basket into 3,916 ETH through decentralised exchange routes and then began routing portions of it through Tornado Cash. Blockaid and exvulsec have asked exchanges, stablecoin issuers, and analytics providers to flag both the attacker EOA and the loot wallet for any downstream movement.

B² Network Loses $3.86M via Staking Contract Seizure

Alongside the AFX Trade and Verus incidents on July 23, Bitcoin Layer 2 solution B² Network reported a loss of roughly $3.86 million after an attacker seized upgrade authority over the network’s staking contract.

According to Lookonchain, which grouped the three same-day incidents under the “Hackers’ Day” tag, the B² Network breach was a permissions-based failure rather than a cryptographic one. The attacker obtained control of the contract’s upgrade rights and used them to alter the protocol’s logic, siphoning staker funds in the process.

B² Network is built on zero-knowledge proof verification and had not previously reported a security incident of this scale. Blockaid framed the day’s clustered incidents as a continued shift in attacker focus toward off-chain infrastructure, where key management, permission scoping, and validation logic remain softer targets than the underlying smart contracts themselves.

Latest update: B² Network has not yet released a detailed post-mortem or a compensation plan. Blockchain security firms continue to track wallet activity linked to the exploit, and no confirmed root-cause disclosure has been published.

Allbridge Core Loses $1.65M to Second Flash Loan Attack Since 2023

Cross-chain protocol Allbridge paused its Core bridge on July 19 after an attacker drained roughly $1.65 million from its Solana liquidity pools through flash loan manipulation.

According to blockchain security firms PeckShield and CertiK, the attacker borrowed $1.12 million in USDC through a flash loan from Solana lending protocol Kamino, then rapidly swapped USDC and USDT to distort the pools’ internal ratios before withdrawing assets at favorable rates. Onchain Lens confirmed the technique and said the stolen funds were bridged to Ethereum address 0x651…ffDe before further dispersion.

Allbridge posted on X that the protocol had been paused as a precaution, urging liquidity providers in affected pools to withdraw immediately. The team also said the manipulation left its pools imbalanced, creating a temporary arbitrage window, and asked traders who profited from the distortion to return funds to compensate affected liquidity providers.

An Echo of 2023

The incident echoes a flash loan attack in April 2023 that drained roughly $573,000 from Allbridge’s BNB Chain pools. In its post-mortem at the time, Allbridge committed to deploying a single liquidity pool per chain, an architecture intended to make same-transaction flash loan manipulation structurally impossible. The July exploit targeted a USDC and USDT pool operating side by side on Solana, the multi-stablecoin configuration the earlier fix was meant to eliminate.

Latest update: Allbridge has not published a final accounting of how much of the $1.65 million has been recovered. The protocol recovered around $465,000 in a white-hat arrangement after the 2023 incident, and the team has a template for renegotiation should the July attacker be receptive.

Lien Finance Loses $542K in USDC Bond Pricing Exploit

Ethereum-based structured products protocol Lien Finance was exploited on July 24 for approximately 542,144 USDC after an attacker manipulated pricing inside the protocol’s GeneralizedDotc bond-to-ERC20 OTC pools.

The incident, first flagged by DefimonAlerts and independently amplified by exvulsec, is being classified as a public protocol logic gap. The attacker deployed an orchestration contract at 0xe74…8062e and registered a new bond group on BondMakerCollateralizedEth using a maliciously crafted payoff function. 

Because the registration process is open and does not require governance approval, the attacker was able to introduce a bond group whose economic characteristics did not reflect any real underlying collateral value.

Once the bond group was live, the newly minted bond tokens were routed through Lien’s GeneralizedDotc OTC pools. The pricing logic in the internal _calcRateBondToErc20 function priced the crafted bonds at a level that dramatically overvalued them relative to the actual collateral backing. 

Roughly 542,144 USDC was extracted from pool liquidity that had originated from allowances granted by the liquidity provider at 0xA961…14d80, with the attacker wallet 0x0D7d…1808a receiving the full sum in the primary exploit transaction.

Security researchers are categorising the incident as an oracle and price manipulation exploit rather than a classical smart contract reentrancy or access control failure. The pattern is a familiar one for 2026, with structural parallels to the $285 million Drift Protocol exploit in April, where an attacker whitelisted a fabricated token as collateral and drained real assets against it.

Latest update: Lien Finance has not issued a public statement on the July 24 incident at the time of writing. The exploit transaction, attacker EOA, and orchestration contract have been circulated for downstream monitoring by exchanges, stablecoin issuers, and analytics providers.

Robinhood CEO’s X Account Compromised in Memecoin Push

While most of the week’s damage sat inside DeFi contracts, a social engineering hit rounded out the picture. On July 23, Robinhood confirmed that CEO Vlad Tenev’s X account had been compromised and used to promote a fraudulent memecoin to the platform’s millions of followers.

Robinhood said in an X post that the unauthorized post had been removed and that the company was working with X to restore access. The team has not disclosed how the compromise occurred or whether any other systems were affected.

The Robinhood incident is the latest example of verified social media accounts linked to major crypto companies and executives being compromised. Earlier this year, Arbitrum DAO’s official governance X account was breached under similar circumstances. Security researchers have noted that such attacks typically exploit the credibility of verified accounts rather than vulnerabilities in blockchain networks themselves.

The Bigger Picture

Every major loss this week traced back to infrastructure or off-chain systems rather than smart contract code executing as designed. AFX Trade fell to a third-party bridge with compromised hot validator signing keys. Wanchain fell to a signed-message encoding flaw in a validator script. Verus fell to a repeated unbacked payout path. B² Network fell to a stolen upgrade authority. 

Allbridge fell to a pool manipulation technique it had promised to structurally eliminate three years ago. Lien Finance fell to permissionless bond registration paired with a rate calculation function that trusted its inputs. Robinhood fell to a compromised social media account.

That fits neatly into the shift documented in CertiK’s H1 2026 findings, where wallet compromise was the costliest category of the half at more than $444 million. It also stacks on top of a $328 million running tab for bridge-specific exploits earlier in the year, a figure that has since crossed materially higher after the July drains. The attack surface keeps climbing up the stack, away from the code that gets audited and toward the rules, keys, and off-chain infrastructure that mostly do not.

Also Read: BitMart to Shut Down as BMX Token Crashes 70%, Just Days After BitMEX Exit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Aave CEO Ramps Up DC Lobbying to Pass CLARITY for GENIUS-Level Growth
Aave CEO Ramps Up DC Lobbying to Pass CLARITY Act for GENIUS-Level Growth
BitMart Shuts Down as BMX Crashes 70% in Second Crypto Exchange Exit This Week
BMX Token Crashes 70% as BitMart Announces Shutdown Days After BitMEX Exit
What Happens If the CLARITY Act Does Not Pass?
What Happens If the CLARITY Act Does Not Pass?
Crypto ETFs End the Week With Strong Inflows Despite Bitcoin $225M Outflow
Crypto ETFs End Week Positive Despite $465M Bitcoin Outflows
Tokenized SpaceX Overtakes GameStop on Robinhood Chain as RWAs Explode 5x to $70M
Tokenized SpaceX Overtakes GameStop on Robinhood Chain as RWAs Explode 5x to $70M

Find Us on Socials

You may also like

Phantom Pulls the Plug on Monad Less Than a Year After Launch

Phantom Pulls the Plug on Monad Less Than a Year After Launch

Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana

Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana

Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit

Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit

$44.4M ETH Moved Drift Protocol Exploiter Breaks 3-Month Silence

$44.4M ETH Moved: Drift Protocol Exploiter Breaks 3-Month Silence

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information