The week of July 19 to July 25 delivered one other punishing stretch for crypto safety, with bridge exploits at AFX Commerce, Wanchain, and Verus, a Solana flash mortgage drain at Allbridge Core, a staking contract seizure at B² Community, an OTC pool manipulation at Lien Finance, and a social hit on Robinhood CEO Vlad Tenev’s X account pushing weekly confirmed injury previous $47 million.
The stretch lands straight on high of the earlier week’s $20M loss throughout Ostium, Throughout, Cascade, and DeFiTuna. It extends the shift specified by CertiK’s H1 2026 report, which discovered Web3 misplaced greater than $1.31 billion throughout 344 incidents within the first half, with pockets compromises and infrastructure breaches now the most expensive assault floor.
Crypto safety breaches value over $47 million in every week, extending $1.31 billion in losses throughout 344 incidents in H1 2026.
Exploits goal third-party bridges and infrastructure, with AFX Commerce and Wanchain dropping $24.15 million and $10 million, respectively.
Repeated assaults on Verus Ethereum Bridge and B² Community spotlight vulnerabilities in key administration and permission scoping, sparking requires improved safety.
AFX Commerce Drained of $24.15M in Arbitrum Bridge Exploit
The largest incident of the week hit AFX Commerce, an Arbitrum-based decentralized perpetual alternate, on July 22 at 21:30 UTC. Blockchain safety agency PeckShield was the primary to flag the breach, reporting on X that the protocol had been drained of roughly $24.15 million in USDC.
The exploiter bridged the stolen funds from Arbitrum to Ethereum and swapped them for 12,467.5 ETH, sitting in pockets 0x6276…ebAC on the time of disclosure. In accordance with the PeckShield alert, the pockets has been positioned underneath lively on-chain surveillance.
Responding to issues that Arbitrum’s core infrastructure had been compromised, Steven Goldfeder, Co-Founding father of Offchain Labs, issued a public clarification on X. Goldfeder stated that the transaction in query originated from a third-party protocol, and that the Arbitrum native bridge had not been hacked or exploited in any means. The excellence contained the compromise to AFX Commerce’s personal third-party bridge setup and restricted the systemic danger to the broader Layer 2 ecosystem.
The Scale of the Drain
On-chain analytics platform Lookonchain later grouped the AFX Commerce breach with two same-day incidents underneath the tag “Hackers’ Day,” pegging mixed losses at $35.55 million. The breakdown coated AFX Commerce at $24.15 million, the Verus Ethereum Bridge at $7.55 million, and B² Community at $3.86 million.
Newest replace: AFX Commerce has not revealed a autopsy or a compensation plan on the time of writing. Blockchain safety companies proceed to trace pockets 0x6276…ebAC for any onward motion of the swapped ETH, and no extra transactions have been reported for the reason that preliminary swap. The complete breakdown of Crypto’s ‘Hackers’ Day’ covers the broader context.
Wanchain Cardano Bridge Loses $10M in NIGHT Token Theft
Two days earlier, safety agency BlockSec’s Phalcon monitor reported on July 21 that Wanchain’s bridge connecting Cardano to BNB Chain had been exploited, ensuing within the theft of roughly 515.2 million NIGHT tokens value roughly $10 million.
The incident unfolded in simply 4 speedy transactions over an eight-minute window. In accordance with preliminary evaluation shared by BlockSec, the foundation trigger was a non-injective signed-message encoding flaw within the TreasuryCheck validator.
The signed message was constructed by concatenating 14 variable-length redeemer fields with out correct delimiters or size prefixes, permitting completely different field-value mixtures to supply equivalent byte strings and hashes, and subsequently legitimate signature reuses.
BlockSec traced the redeemer’s uniqueId discipline again to a reliable BSC transaction that licensed solely 3,110 NIGHT. The identical signature was reused on Cardano to extract 203,001,692 NIGHT, a roughly 65,000x inflation through field-boundary ambiguity within the raw-concatenated hash.
The attacker funneled the stolen tokens right into a main pockets on Cardano earlier than aggressively liquidating roughly 90% of the haul by way of DEX swaps and DeFi protocols. At prevailing costs round $0.01950 per token, the drained quantity equated to roughly $10 million in realized worth.
Midnight Distances Itself From the Breach
NIGHT, the native token of the privacy-focused Midnight blockchain incubated by Enter Output, plunged greater than 30% to 40% intraday, hitting a brand new all-time low. Midnight Community shortly issued an announcement clarifying that the core Midnight protocol and its Layer 1 stay uncompromised, with the breach confined to Wanchain’s third-party bridging infrastructure.
Newest replace: Wanchain paused its bridge and said in an official assertion that the incident has its full consideration, promising full transparency as soon as the investigation is full. The occasion provides to a operating checklist of bridge exploits which have already value the business billions since 2017, together with Ronin at $624 million and Wormhole at $326 million.
Verus Ethereum Bridge Drained of $7.54M in Repeat Assault
The Verus Ethereum Bridge has been drained for the second time in simply over two months, with an attacker siphoning roughly $7.54 million in belongings on July 23, 2026, by abusing the identical import path weaponized in opposition to the protocol in Could.
Onchain safety agency Blockaid flagged the incident in actual time, and unbiased researcher exvulsec confirmed the exploit signature inside minutes of the drain. The stolen basket spans seven belongings held within the bridge’s Ethereum-side reserves, together with ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
The exploit was executed in a single main transaction at roughly 03:45 UTC on July 23. Etherscan data present the drain occurred by way of goal bridge contract 0x715…D7F63, with the attacker EOA at 0xBda…855c and the loot pockets at 0xCF…42D54. The only largest motion was a switch of 1,137 ETH from the bridge to the attacker-controlled pockets, alongside proportionate withdrawals of the tokenised BTC, stablecoin, and MKR reserves.
Identical Bug Class because the Could Breach
Blockaid described the July exploit as belonging to the identical bug class because the Could 18 breach, with the attacker utilizing the bridge’s submitImports operate to set off payouts that weren’t backed by matching belongings on the supply aspect.
The Ethereum-side contract launched actual reserves in response to an import declare that didn’t carry corresponding worth locked on the Verus aspect, the identical architectural hole recognized within the Could autopsy.
As beforehand reported by The Crypto Instances, the Could attacker later returned 4,052.4 ETH value round $8.5 million after Verus provided settlement phrases, holding 1,350 ETH as an agreed bounty.
Newest replace: VerusCoin has not issued a public assertion on the July 23 exploit on the time of writing. In accordance with onchain information compiled after the drain, the attacker consolidated the stolen basket into 3,916 ETH by way of decentralised alternate routes after which started routing parts of it by way of Twister Money. Blockaid and exvulsec have requested exchanges, stablecoin issuers, and analytics suppliers to flag each the attacker EOA and the loot pockets for any downstream motion.
B² Community Loses $3.86M through Staking Contract Seizure
Alongside the AFX Commerce and Verus incidents on July 23, Bitcoin Layer 2 resolution B² Community reported a lack of roughly $3.86 million after an attacker seized improve authority over the community’s staking contract.
In accordance with Lookonchain, which grouped the three same-day incidents underneath the “Hackers’ Day” tag, the B² Community breach was a permissions-based failure fairly than a cryptographic one. The attacker obtained management of the contract’s improve rights and used them to change the protocol’s logic, siphoning staker funds within the course of.
B² Community is constructed on zero-knowledge proof verification and had not beforehand reported a safety incident of this scale. Blockaid framed the day’s clustered incidents as a continued shift in attacker focus towards off-chain infrastructure, the place key administration, permission scoping, and validation logic stay softer targets than the underlying good contracts themselves.
Newest replace: B² Community has not but launched an in depth autopsy or a compensation plan. Blockchain safety companies proceed to trace pockets exercise linked to the exploit, and no confirmed root-cause disclosure has been revealed.
Allbridge Core Loses $1.65M to Second Flash Mortgage Assault Since 2023
Cross-chain protocol Allbridge paused its Core bridge on July 19 after an attacker drained roughly $1.65 million from its Solana liquidity swimming pools by way of flash mortgage manipulation.
In accordance with blockchain safety companies PeckShield and CertiK, the attacker borrowed $1.12 million in USDC by way of a flash mortgage from Solana lending protocol Kamino, then quickly swapped USDC and USDT to distort the swimming pools’ inner ratios earlier than withdrawing belongings at favorable charges. Onchain Lens confirmed the approach and stated the stolen funds had been bridged to Ethereum handle 0x651…ffDe earlier than additional dispersion.
Allbridge posted on X that the protocol had been paused as a precaution, urging liquidity suppliers in affected swimming pools to withdraw instantly. The staff additionally stated the manipulation left its swimming pools imbalanced, creating a short lived arbitrage window, and requested merchants who profited from the distortion to return funds to compensate affected liquidity suppliers.
An Echo of 2023
The incident echoes a flash mortgage assault in April 2023 that drained roughly $573,000 from Allbridge’s BNB Chain swimming pools. In its autopsy on the time, Allbridge dedicated to deploying a single liquidity pool per chain, an structure meant to make same-transaction flash mortgage manipulation structurally unimaginable. The July exploit focused a USDC and USDT pool working aspect by aspect on Solana, the multi-stablecoin configuration the sooner repair was meant to remove.
Newest replace: Allbridge has not revealed a ultimate accounting of how a lot of the $1.65 million has been recovered. The protocol recovered round $465,000 in a white-hat association after the 2023 incident, and the staff has a template for renegotiation ought to the July attacker be receptive.
Lien Finance Loses $542K in USDC Bond Pricing Exploit
Ethereum-based structured merchandise protocol Lien Finance was exploited on July 24 for about 542,144 USDC after an attacker manipulated pricing contained in the protocol’s GeneralizedDotc bond-to-ERC20 OTC swimming pools.
The incident, first flagged by DefimonAlerts and independently amplified by exvulsec, is being labeled as a public protocol logic hole. The attacker deployed an orchestration contract at 0xe74…8062e and registered a brand new bond group on BondMakerCollateralizedEth utilizing a maliciously crafted payoff operate.
As a result of the registration course of is open and doesn’t require governance approval, the attacker was in a position to introduce a bond group whose financial traits didn’t mirror any actual underlying collateral worth.
As soon as the bond group was reside, the newly minted bond tokens had been routed by way of Lien’s GeneralizedDotc OTC swimming pools. The pricing logic within the inner _calcRateBondToErc20 operate priced the crafted bonds at a stage that dramatically overvalued them relative to the precise collateral backing.
Roughly 542,144 USDC was extracted from pool liquidity that had originated from allowances granted by the liquidity supplier at 0xA961…14d80, with the attacker pockets 0x0D7d…1808a receiving the total sum within the main exploit transaction.
Safety researchers are categorising the incident as an oracle and worth manipulation exploit fairly than a classical good contract reentrancy or entry management failure. The sample is a well-known one for 2026, with structural parallels to the $285 million Drift Protocol exploit in April, the place an attacker whitelisted a fabricated token as collateral and drained actual belongings in opposition to it.
Newest replace: Lien Finance has not issued a public assertion on the July 24 incident on the time of writing. The exploit transaction, attacker EOA, and orchestration contract have been circulated for downstream monitoring by exchanges, stablecoin issuers, and analytics suppliers.
Robinhood CEO’s X Account Compromised in Memecoin Push
Whereas many of the week’s injury sat inside DeFi contracts, a social engineering hit rounded out the image. On July 23, Robinhood confirmed that CEO Vlad Tenev’s X account had been compromised and used to advertise a fraudulent memecoin to the platform’s tens of millions of followers.
Robinhood stated in an X post that the unauthorized submit had been eliminated and that the corporate was working with X to revive entry. The staff has not disclosed how the compromise occurred or whether or not another programs had been affected.
The Robinhood incident is the most recent instance of verified social media accounts linked to main crypto corporations and executives being compromised. Earlier this yr, Arbitrum DAO’s official governance X account was breached underneath related circumstances. Safety researchers have famous that such assaults sometimes exploit the credibility of verified accounts fairly than vulnerabilities in blockchain networks themselves.
The Greater Image
Each main loss this week traced again to infrastructure or off-chain programs fairly than good contract code executing as designed. AFX Commerce fell to a third-party bridge with compromised scorching validator signing keys. Wanchain fell to a signed-message encoding flaw in a validator script. Verus fell to a repeated unbacked payout path. B² Community fell to a stolen improve authority.
Allbridge fell to a pool manipulation approach it had promised to structurally remove three years in the past. Lien Finance fell to permissionless bond registration paired with a price calculation operate that trusted its inputs. Robinhood fell to a compromised social media account.
That matches neatly into the shift documented in CertiK’s H1 2026 findings, the place pockets compromise was the most expensive class of the half at greater than $444 million. It additionally stacks on high of a $328 million operating tab for bridge-specific exploits earlier within the yr, a determine that has since crossed materially increased after the July drains. The assault floor retains climbing up the stack, away from the code that will get audited and towards the foundations, keys, and off-chain infrastructure that largely don’t.
Additionally Learn: BitMart to Shut Down as BMX Token Crashes 70%, Just Days After BitMEX Exit
Disclaimer: The knowledge researched and reported by The Crypto Instances is for informational functions solely and isn’t an alternative choice to skilled monetary recommendation. Investing in crypto belongings includes important danger attributable to market volatility. All the time Do Your Personal Analysis (DYOR) and seek the advice of with a professional Monetary Advisor earlier than making any funding selections.





