AFX and Verus suffer separate exploits within hours on July 22

Two Ethereum bridges lost a combined $31.69 million on July 22, 2026, as a third staking protocol suspended operations following unauthorized access to its upgrade authority.

AFX, a decentralized trading protocol on Arbitrum, lost 24.15 million USDC through its third-party USDC custody bridge after attackers used social engineering to gain initial access to a development environment. The compromise escalated into internal build infrastructure and validator systems, according to preliminary findings AFX published on July 24. Blockaid, a security detection firm, identified the exploit at 21:30 UTC on July 22.

AFX said the incident was isolated from its trading infrastructure, mainnet, and the Arbitrum network itself. The company suspended its USDC custody bridge while security reviews continued.

Hours after the AFX incident, Verus, an Ethereum bridge operator, released 1,137.4528 ETH and seven tokens valued at $7.54 million without proof of matching reserves. Eight withdrawals were approved by Verus in total. SlowMist, a blockchain analysis firm, linked the Verus failure to the same broad cross-chain import-validation class as a May exploit, though the two attacks used different mechanics.

B² Network, a staking protocol, suspended normal staking operations after unauthorized access to its upgrade authority. The company said the issue was contained and committed to full compensation for affected users. B² offered manual exit through official Discord, processing ownership-verified unstaking requests within one business day. As of July 24, B² had not announced a completed fund return or a formal compensation plan.

Neither AFX nor Verus disclosed whether any funds had been recovered or returned as of publication.