Cross-chain bridges had one of their worst weeks of the year between July 19 and July 25, 2026, and the pattern behind the losses is more useful than any single dollar figure. Five separate protocols got hit — a perpetuals exchange, two bridge operators for the second time each, a flash-loan repeat offender, and a staking contract — pushing confirmed weekly damage past $47 million. None of it involved a genuinely new class of smart contract bug. Almost all of it came down to who controls the keys and whether anyone actually fixed the last exploit.
The largest single hit landed on AFX Trade, a decentralized perpetuals exchange running on Arbitrum that settles trades in USDC. Security firm Blockaid flagged the exploit at 21:30 UTC on July 22: attackers had compromised the private signing keys of five of the validators responsible for approving withdrawals from AFX’s bridge, clearing the two-thirds quorum the contract required to treat a transfer as legitimate. The system did exactly what it was designed to do — it just trusted keys that had already been stolen. Roughly $24.15 million in USDC moved out, was bridged to Ethereum, and converted into about 12,467 ETH, consolidated in a single wallet. Offchain Labs confirmed Arbitrum’s own native bridge was never touched; this was AFX’s own validator infrastructure, not the underlying chain.
AFX wasn’t an isolated incident so much as the biggest entry in a week that kept repeating the same lesson. Days earlier, Wanchain’s Cardano-BNB bridge lost roughly $9 million — 515 million NIGHT tokens — to a cryptographic flaw in its TreasuryCheck validator: a non-injective signed-message encoding bug that let an attacker generate multiple withdrawal requests mapping to the same signed message, then reuse one legitimate signature to authorize fraudulent transfers. Cardano founder Charles Hoskinson publicly called for an industry-wide overhaul of how bridges handle zero-knowledge signature schemes in the exploit’s aftermath. The Verus Ethereum bridge was drained a second time in just over two months on July 23, losing $7.54 million — through the same import path attackers had already weaponized against it in May. And Allbridge Core lost $1.65 million to a Solana flash-loan attack that succeeded specifically because its Solana deployment still pooled USDC and USDT together in the same architecture the protocol claimed to have already patched back in 2023.
Lay those four incidents side by side and a real pattern shows up: this wasn’t a week of novel cryptographic breakthroughs by sophisticated attackers finding zero-days nobody had ever seen. It was compromised operational key management (AFX), an unpatched signature-scheme flaw (Wanchain), a bridge getting hit twice through the identical vulnerability (Verus), and a fix that was announced but never actually shipped to every deployment (Allbridge). Add a staking-contract seizure at B² Network and an OTC pool manipulation at Lien Finance, and the week’s total losses reflect an industry that keeps building new bridges faster than it audits and re-audits the ones already live. July’s cumulative hack losses across the sector had already reached close to $97 million before some of this week’s damage was even fully tallied, on top of PeckShield’s estimate that hackers drained roughly $750 million from crypto protocols in the first half of 2026 alone — putting the current quarter among the worst on record for the sector.
The uncomfortable part for the industry is that bridges remain both the most necessary and the most fragile piece of multi-chain crypto infrastructure. Every protocol that wants users to move assets between Arbitrum, Ethereum, Solana, Cardano, and BNB Chain needs some mechanism to lock value on one chain and mint or release it on another — and every one of those mechanisms is, structurally, a single point of failure sitting on top of whatever validator set, multisig, or oracle a given team chose to trust. Repeat attacks on Verus and Allbridge in particular suggest that “we patched it” claims from smaller protocols deserve real skepticism until a fix is independently verified across every deployment, not just the one that got hit first.
What This Means for Philippine Founders
Philippine crypto platforms and Web3 builders rarely operate their own bridges, but almost everyone touching multi-chain assets — a local exchange offering cross-chain deposits, a remittance startup settling in stablecoins across networks, a GameFi or Web3 project bridging in-game tokens — depends on someone else’s bridge infrastructure being sound. The practical lesson from this week for any Filipino founder integrating a bridge is to treat “audited” as a starting point, not a guarantee, and to specifically ask whether a security fix was verified across every chain deployment a bridge supports, since Allbridge’s repeat failure happened precisely because a 2023 fix never made it to the Solana side. For platforms handling OFW remittances or cross-border settlement in particular, custodying user funds through a bridge with validator-key concentration risk — exactly what took down AFX — is a real, quantifiable liability that BSP-regulated Virtual Asset Service Providers in the Philippines should be actively pressure-testing rather than assuming away.
Share this article