News·2 minutes read

DeFi Bounties: Inviting Hacks or Strengthening Audits? Verus and AFX Spotlight

Alphid Team·

Hero: A digital visualization of blockchain bridges connecting multiple networks with data flowing between them, highlighting security breaches in DeFi protocols

Summary

  • AFX Trade lost roughly $24 million on July 22, 2026, after bridge keys were compromised on Arbitrum.
  • The Verus-Ethereum Bridge lost about $7.5 million in a separate exploit the following day.
  • AFX Trade offered the exploiter a $7.2 million bounty in exchange for 70 percent of the stolen funds.

Attackers compromised AFX Trade's bridge keys on July 22, 2026. They drained roughly $24.15 million from the Arbitrum perpetual DEX. DefiLlama data already listed 13 prior hacks that month for $72.6 million in losses.

This pushed July totals near $97 million based on Blockaid and PeckShield figures. The breach exposed cross-chain bridge weaknesses that still hit DeFi users and operators. AFX Trade responded by offering the exploiter a bounty deal to return most of the funds.

Context

Cross-chain bridges faced repeated attacks in 2026. July alone brought multiple incidents that drained tens of millions from protocols. AFX Trade and Verus bridges were hit within 24 hours of each other. Combined losses exceeded $31.5 million.

Steven Goldfeder, co-founder of Offchain Labs, stated the network's native bridge had not been hacked or exploited in the AFX case. The compromise instead centered on the protocol's own bridge keys.

Details

The AFX Trade exploit involved compromised bridge keys that allowed unauthorized transfers of assets. The protocol then opened negotiations and offered the exploiter $7.2 million to return 70 percent of the stolen funds.

One day later, on July 23, 2026, the Verus-Ethereum Bridge suffered its second exploit. Attackers took approximately $7.5 million in crypto assets, according to reports from Wu Blockchain and other trackers.

"On July 22, 2026, AFX Trade lost roughly $24.15 million."

, CryptoTicker (https://cryptoticker.io/en/afx-trade-hack-bridge-exploit-arbitrum/)

These incidents show how bounty programs now serve as a primary recovery tool after bridge attacks. The frequency of exploits still raises questions about whether current audit practices fully address key management and cross-chain risks.

Outlook

Protocols will likely continue testing bounty offers as a recovery tool in the coming months. Observers will watch whether these deals reduce net losses or encourage further attempts on vulnerable bridges.