Mark RadarMARK RADAR
EN

Hackers Drain Over $35 Million From Bitcoin- and Ethereum-Linked Protocols

3 reports · First detected 2026-07-23 · Last active 2026-07-23

Cross-chain bridges lock assets on one blockchain and issue claims on another, allowing capital to move between otherwise incompatible networks such as Bitcoin and Ethereum. Their security depends not only on smart-contract code but also on validation logic, private keys and administrative upgrade controls. The cluster of breaches matters because none required attackers to break underlying cryptography; instead, recurring governance and permission failures allowed trusted components to release or redirect funds.

During a six-hour span ending July 23, 2026, at least three systems lost more than $35 million. AFX Trade’s Arbitrum bridge was drained of about $24.15 million, the Verus-Ethereum Bridge lost $7.54 million, and B² Network lost $3.86 million after an attacker seized the upgrade authority for its staking contract. Blockaid said the Verus incident reused the contract path and vulnerability class exploited on May 18; Verus had redeposited recovered funds into the bridge on July 8. B² suspended staking and said affected users would be fully compensated.

All Coverage

3 original reports

The Backstory

The history behind this event
Allbridge Halts Protocol After $1.65 Million Flash-Loan Exploit2026-07-20 · 4 reports · similarity 0.81

Allbridge Core is a cross-chain bridge designed to move stablecoins between blockchains including Solana and Ethereum. Such protocols pool liquidity and coordinate transfers across otherwise separate networks, making them important infrastructure for decentralized finance. Their concentration of assets and reliance on smart-contract pricing also make them frequent targets, with any failure potentially exposing liquidity providers and disrupting users’ ability to move funds between chains.

On July 19, an attacker borrowed $1.12 million through a flash loan from Solana-based lending protocol Kamino and rapidly swapped USDC for USDT to distort Allbridge Core’s pool ratios, according to Onchain Lens. The maneuver enabled withdrawals at favorable rates and drained about $1.65 million. Allbridge paused the protocol and urged users to remove liquidity from affected pools. PeckShield and CertiK said the stolen assets were later bridged from Solana to Ethereum and deposited into privacy pools.

Gravity Bridge Suffers Key-Exposure Exploit, Losing About $5.4 Million2026-05-31 · 2 reports · similarity 0.80

Gravity Bridge is a cross-chain protocol connecting the Ethereum and Cosmos ecosystems, with validators jointly authorizing asset transfers. Cross-chain bridges hold large concentrations of tokens, and stolen keys can allow attackers to bypass security controls. The incident again highlights key-management risks in DeFi infrastructure.

On-chain analyst Specter raised the alarm on May 30, 2026, saying an apparent contract-key exposure had allowed about $5.4 million to be removed from Gravity Bridge. The assets included 4.3 million USDC, 274 WETH, 434,000 USDT and 14.164 PAXG, leaving only about $85,000 in the contract. The team confirmed the following day that the bridge had been paused.

Verus–Ethereum Bridge Hacked for More Than $11.58 Million2026-05-25 · 6 reports · similarity 0.85

Verus is a privacy-focused blockchain launched in 2018. Its Verus–Ethereum bridge, which went live in October 2023, transfers and swaps assets between the two networks. Because bridges hold liquidity in centralized pools, a failure in their verification mechanisms can put multiple tokens at risk. The incident again highlights vulnerabilities in DeFi infrastructure.

On May 18, 2026, Blockaid and PeckShield reported the theft of 1,625 ETH, 103.6 tBTC and about 147,000 USDC from the bridge, for losses of roughly $11.58 million. On May 22, the attacker returned 4,052.4 ETH, worth about $8.5 million, while retaining 1,350 ETH as a bounty. Verus agreed to end its investigation and not pursue legal action.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)