DeFi Bounties: Inviting Hacks or Strengthening Audits? Verus and AFX Spotlight

Summary
- On July 22-23 2026 two cross-chain bridge exploits at AFX Trade and Verus drained over $31.5M combined and triggered immediate bounty talks.
- AFX Trade lost $24.15M after an attacker compromised validator signing keys on its Arbitrum USDC custody bridge, while Verus suffered unbacked payouts through its import mechanism for the second time since May.
- The events position bounty offers as a practical recovery mechanism even as they underscore recurring weaknesses in cross-chain bridge design.
The control room at AFX Trade went quiet around midnight on July 22 2026. Monitors showed validator signatures firing in rapid succession on the Arbitrum bridge, each transaction pulling USDC out of the custody pool without the usual multi-check confirmations. Within hours the team realized more than $24 million had moved to addresses they did not control.
That same night a similar alert reached the Verus operators. Their Ethereum bridge was issuing tokens that had never been deposited on the other side. Those hours set the tone for the next forty-eight. Instead of waiting for law-enforcement processes that have historically recovered little, both teams moved straight to public bounty negotiations.
The speed of those offers, and the partial fund returns that followed in similar incidents, now shape how the wider DeFi market thinks about breach response.
Background
AFX Trade began as a perpetuals DEX focused on low-latency trading on Arbitrum. Its bridge was designed to let users move USDC between networks so traders could fund positions without leaving the ecosystem. The architecture relied on a set of validator signing keys, a common pattern that concentrates power in a small group of signers.
When those keys were obtained, the entire custody layer became exposed. Verus entered the bridge space with a different technical emphasis, allowing users to import assets through a mechanism that was intended to verify deposits on the source chain before minting on Ethereum. Yet the same import flow had already been abused once in May 2026, when an attacker triggered payouts without matching collateral.
The July incident therefore marked a second demonstration of the same failure mode.
"The AFX-operated USDC custody bridge on Arbitrum was exploited, forcing the team to suspend bridge operations."
, Coin Bureau (X post)
The pattern is straightforward. Cross-chain bridges must trust either keys or proofs. When either assumption breaks, the economic damage scales with the liquidity sitting in the contract. Both AFX and Verus learned this the hard way within the same twenty-four-hour window.
Current
By July 23 the AFX operators had publicly offered a 30 percent bounty for the return of the $24.15 million. The proposal was not framed as a reward for white-hat discovery but as a direct negotiation with the unknown party holding the funds. Verus, meanwhile, traced the unbacked mints and began similar outreach while pausing all bridge activity.
These negotiations sit against a broader backdrop. In 2026 alone more than $750 million has already left DeFi protocols through comparable routes. The July 22-23 incidents added another $31.5 million, yet the rapid bounty conversations represent a tactical shift.
Teams now treat the attacker as a counterparty capable of returning the majority of assets if the split is attractive enough.
"The Arbitrum-based perpetuals DEX lost $24.15 million in USDC after an attacker compromised validator signing keys for its bridge."
, Crypto Briefing (Source)
The approach carries obvious risks. A public bounty can be read as an admission that on-chain tracing alone will not suffice. Yet the alternative, waiting months for fragmented law-enforcement cooperation, has produced even lower recovery rates in earlier cases. For now, the market appears willing to accept the trade-off. And honestly, that's a big deal when every day of delay risks the funds vanishing deeper into mixer services.
Impact
The dual exploits arrive at a moment when cross-chain infrastructure still accounts for the largest single category of DeFi losses. Each new bridge adds another surface that must be hardened against key theft, proof forgery, or import abuse. The AFX and Verus cases show that even audited systems remain vulnerable once the economic incentive aligns for an attacker.
Bounty programs have therefore moved from optional community gesture to core incident-response playbook. When $24 million can be partially clawed back within days rather than lost forever, the calculation changes for both projects and their users.
At the same time the visibility of these offers raises a separate question the industry has not yet answered: whether the existence of a standing bounty itself lowers the threshold for the next exploit.
"Three major security incidents hit DeFi. An AFX-operated USDC custody bridge on Arbitrum was exploited."
, BingX (Source)
Which, if you've been watching this space, shouldn't be surprising. The same bridges that enable seamless liquidity also concentrate risk in ways that traditional finance never had to manage.
The monitors at AFX Trade eventually went dark again once operations were suspended. The same quiet returned to the Verus dashboard after the import function was disabled. Those screens will light up once more only after the teams decide whether the next bridge iteration can survive the same assumptions that failed on July 22.
Until then, the bounty remains the most reliable on-ramp back to the funds that left.


