AFX Bridge Exploit Drains $24.15 Million, Pushing July Crypto Losses Near $100 Million

An exploit of an AFX-operated bridge on Arbitrum drained about $24.15 million in USDC on 22 July 2026, converted into roughly 12,467 ETH. Arbitrum's native brid...

The AFX bridge exploit on 22 July 2026 drained approximately $24.15 million in USDC from a third-party bridge contract built on the Arbitrum network. Security firm Blockaid detected the attack at 21:30 UTC. Stolen funds were converted into roughly 12,467.5 ETH. The incident pushed July 2026 crypto hack losses to approximately $97 million across 14 incidents.

Key Takeaways: AFX Bridge Exploit at a Glance

  • Attack detected: 21:30 UTC, 22 July 2026, by Blockaid’s on-chain threat monitoring system
  • Amount drained: ~$24.15 million in USDC (roughly Rs 201 crore at current rates)
  • Conversion: Stolen USDC swapped into approximately 12,467.5 ETH, moved to one wallet
  • Arbitrum native bridge: Confirmed safe by Offchain Labs; only the AFX-operated third-party bridge was hit
  • July 2026 running total: This was the 14th hack of the month, pushing cumulative losses to roughly $97 million
  • June 2026 comparison: Total losses in June stood at $75.32 million, per DefiLlama hack data

What Happened in the AFX Bridge Exploit?

How the Attack Unfolded

Blockaid’s automated alert system flagged suspicious on-chain activity at exactly 21:30 UTC on 22 July 2026. The attacker targeted a bridge contract operated by AFX, a protocol built on top of Arbitrum’s Ethereum layer-2 network. The AFX bridge exploit drained USDC liquidity that users had deposited into the AFX bridge to move assets between chains.

Within minutes of the drain, the attacker converted all stolen USDC into approximately 12,467.5 ETH. Moving funds into ETH is a classic post-exploit tactic: it makes tracing harder and allows the attacker to route funds through mixers or decentralised exchanges without touching centralised stablecoins that can be frozen by issuers like Circle.

Was Arbitrum’s Native Bridge Exploited?

No. This is a critical distinction. Offchain Labs, the company behind Arbitrum, publicly confirmed that Arbitrum’s native bridge was not compromised. The exploited contract belonged entirely to AFX, a separate third-party protocol that built its own bridging layer on top of Arbitrum’s network.

If you hold ARB tokens or use the official Arbitrum bridge, your funds were not at risk from this specific incident. The confusion arose because AFX operates on the Arbitrum chain, leading early social media posts to incorrectly label this an “Arbitrum hack.”

Cross-Chain Bridge Security: Why Bridges Keep Getting Hit

Web3 bridges are among the most targeted infrastructure in crypto. They hold large pools of locked assets, often run complex smart contract logic, and sometimes combine multiple signing schemes that create attack surfaces. According to Chainalysis, cross-chain bridges accounted for $2.66 billion in stolen crypto in 2022 alone, making them the single largest attack category that year.

The AFX bridge exploit follows a pattern seen in incidents like the Ronin bridge hack ($625 million, 2022), the Wormhole hack ($320 million, 2022), and more recently the Ostium exploit post-mortem. Each case highlighted how third-party bridge contracts, not base-layer blockchains, are the weak link.

July 2026 Crypto Hack Tracker: Monthly Losses Near $100 Million

Where the AFX Bridge Exploit Fits in the Monthly Picture

The AFX bridge exploit was the 14th reported hack in July 2026, according to DefiLlama’s hack tracking dashboard. Before this event, the month’s total stood at around $72.85 million. The $24.15 million drain pushed the running figure to approximately $97 million, closing in on the $100 million mark with days still left in the month.

June 2026 recorded $75.32 million in total losses across all incidents, per DefiLlama data. July is on track to be materially worse, driven largely by this single AFX bridge exploit.

July 2026 vs. June 2026: Crypto Hack Loss Comparison

Metric June 2026 July 2026 (as of 22 July)
Total losses (USD) $75.32 million ~$97 million
Number of incidents Data unavailable (DefiLlama) 14 (confirmed)
Largest single hack Data unavailable (DefiLlama) AFX bridge exploit ($24.15M)
Primary asset drained Mixed USDC (converted to ETH)
Data source DefiLlama DefiLlama / Blockaid

What Indian Crypto Investors Should Know

Indian retail investors who use cross-chain bridges to move assets between networks carry a specific risk that goes beyond price volatility. If you bridge USDC or any other asset through a third-party protocol and it gets exploited, there is no insurance, no RBI guarantee, and no SEBI redressal mechanism. You could lose everything held in that contract.

Platforms like WazirX, CoinDCX, ZebPay, and Mudrex operate as centralised Indian exchanges and do not expose users to bridge smart contract risk directly. But if you use a DeFi wallet and interact with protocols like AFX yourself, the risk sits entirely with you. India’s 30% VDA tax and 1% TDS rules apply to gains, but they offer no protection against losses from hacks. The government taxes your profits; it does not cover your losses.

The broader blockchain security landscape in India is still maturing. SEBI has been cautious about DeFi oversight, and the RBI has repeatedly flagged crypto risks. Neither body has issued guidance specifically on DeFi bridge risks as of July 2026.

Frequently Asked Questions

What happened in the AFX bridge exploit?

On 22 July 2026 at 21:30 UTC, Blockaid detected the AFX bridge exploit targeting a bridge contract operated by AFX on the Arbitrum network. Attackers drained approximately $24.15 million in USDC and converted it into roughly 12,467.5 ETH, consolidating the funds in a single wallet. The AFX team had not issued a full post-mortem at the time of writing.

Was Arbitrum’s native bridge exploited?

No. Offchain Labs confirmed that Arbitrum’s official native bridge was completely unaffected. The vulnerability was in a bridge contract built and operated by AFX, a third-party protocol that runs on Arbitrum. ARB token holders and users of the official Arbitrum bridge were not at risk from this specific incident.

How much crypto was stolen in July 2026?

As of 22 July 2026, total crypto hack losses for the month reached approximately $97 million across 14 separate incidents, according to DefiLlama data. The AFX bridge exploit, at $24.15 million, was the largest single event of the month. June 2026 saw $75.32 million in total losses, making July significantly worse month-over-month.

Why do cross-chain bridges keep getting hacked?

Bridges hold large pools of locked assets and run complex smart contract code that often combines multiple validation layers. Any flaw in that logic can be exploited for massive gains. Unlike base-layer blockchains, bridges are built by smaller teams with tighter timelines and do not always receive thorough third-party audits. That makes them a consistent target for sophisticated attackers.

Is it safe for Indian investors to use DeFi bridges?

DeFi bridges carry significant smart contract risk. There is no regulatory protection from SEBI or the RBI if a bridge is exploited. Indian investors should only use well-audited protocols, keep amounts small relative to their portfolio, and understand that losses from hacks are not tax-deductible under current VDA tax rules. Always research a bridge before depositing any funds.

Sources: Blockaid official alert (22 July 2026); Offchain Labs public statement; DefiLlama Hacks Dashboard (defillama.com/hacks); Chainalysis Crypto Crime Report 2025.

This article is for news and informational purposes only. It is not investment advice. Crypto assets are highly volatile and unregulated in India. Please consult a qualified financial advisor before making any investment decisions.

Last updated: July 2026. Reviewed by the CryptoWire editorial team.

Related News

Scroll to Top