Logo
My Crypto News AI

Over $47 Million Lost in a Week: How Off-Chain Infrastructure Became Crypto's Biggest Vulnerability

The crypto industry lost more than $47 million in confirmed damages between July 19 and July 25, marking another brutal week for decentralized finance (DeFi) security. Rather than targeting the blockchain code itself, attackers exploited vulnerabilities in the infrastructure that bridges assets between chains and manages validator permissions. This shift represents a fundamental change in how hackers approach crypto theft, moving away from smart contract exploits toward the less-audited systems that support them.

What Happened During Crypto's "Hackers' Day"?

The week's largest incident struck AFX Trade, an Arbitrum-based perpetual exchange, on July 22 when attackers drained approximately $24.15 million in USDC (United States Dollar Coin, a stablecoin pegged to the US dollar). The attacker bridged the stolen funds from Arbitrum to Ethereum and converted them into 12,467.5 ETH (Ethereum's native token), which was placed under active on-chain surveillance by security firm PeckShield.

Two other major exploits occurred on the same day, prompting blockchain analytics platform Lookonchain to tag the incidents as "Hackers' Day." The Verus Ethereum Bridge was drained of $7.54 million, and B² Network, a Bitcoin Layer 2 solution, lost $3.86 million through a permissions-based attack. Combined with AFX Trade's loss, the three same-day incidents totaled $35.55 million.

Earlier in the week, on July 21, Wanchain's bridge connecting Cardano to BNB Chain was exploited for approximately $10 million worth of NIGHT tokens, the native token of the privacy-focused Midnight blockchain. The attacker executed the theft in just four rapid transactions over an eight-minute window by exploiting a flaw in how the bridge's validator encoded signed messages.

Why Are Off-Chain Systems Becoming the Weakest Link?

The pattern emerging from this week's attacks reveals a critical blind spot in DeFi security: the infrastructure that connects blockchains and manages validator permissions is far less scrutinized than the smart contracts themselves. In the Across Protocol exploit on July 17, attackers stole $4.5 million by exploiting a bug in the relay software responsible for reading off-chain events on Solana. The attacker forged deposit events that never actually occurred, tricking the relayer into paying out its own funds. Across's core smart contracts and Solana programs remained completely secure, yet the off-chain relay software vulnerability cost the protocol millions.

Similarly, the Wanchain incident stemmed from a non-injective signed-message encoding flaw in the TreasuryCheck validator. The signed message was constructed by concatenating 14 variable-length fields without proper delimiters or length prefixes, allowing different field-value combinations to produce identical byte strings. This allowed an attacker to reuse a signature authorized for only 3,110 NIGHT tokens to extract 203 million NIGHT, a roughly 65,000-fold inflation through field-boundary ambiguity.

The B² Network breach exemplified a permissions-based failure rather than a cryptographic one. An attacker obtained control of the staking contract's upgrade rights and used them to alter the protocol's logic and siphon staker funds. This type of attack targets governance and access control rather than the underlying cryptography.

How Does This Week Compare to Broader 2026 Trends?

This week's $47 million in losses lands directly on top of the previous week's $20 million in damages across Ostium, Across, Cascade, and DeFiTuna. The pattern aligns with findings from CertiK's first-half 2026 report, which documented that Web3 lost more than $1.31 billion across 344 incidents, with wallet compromises and infrastructure breaches now representing the costliest attack surface.

The shift away from smart contract exploits toward infrastructure vulnerabilities reflects a maturation of the attack landscape. As developers improve smart contract auditing and testing, attackers have adapted by targeting the less-scrutinized layers of the ecosystem. Bridges, relay software, and validator systems have become attractive targets precisely because they operate outside the main blockchain and often receive less rigorous security review.

What Steps Can Users Take to Protect Their Assets?

  • Minimize Bridge Exposure: Cross-chain bridges are useful tools, but they should not be treated as long-term storage. Bridge only the amount you need and transfer your assets to a secure wallet immediately after the transaction is complete.
  • Use Self-Custody Wallets: Whenever possible, keep the majority of your assets in wallets where you control the private keys, such as Trust Wallet, MetaMask, Rabby Wallet, or hardware wallets that support self-custody.
  • Consider Cold Storage: If you are holding crypto for months or years, consider using a hardware wallet such as Ledger or Trezor. Cold storage keeps your private keys offline, making them significantly harder for attackers to access remotely.
  • Research Before Connecting: Before connecting your wallet to any bridge or DeFi application, investigate whether the protocol has been audited, whether it has suffered previous exploits, whether the development team is transparent, and whether the community trusts it.
  • Enable Account Security: Use two-factor authentication (2FA), strong and unique passwords, secure backup methods, and withdrawal protection where available on any platform holding your funds.
  • Verify URLs and Avoid Phishing: Many successful crypto thefts do not involve sophisticated blockchain exploits at all. Instead, attackers trick users into signing malicious transactions or revealing wallet credentials through fake websites, emails, Telegram groups, Discord servers, or social media messages. Always verify URLs, bookmark official websites, and avoid clicking links shared by unknown sources.

The incidents this week underscore a critical lesson: no legitimate platform or support agent will ever ask for your private keys or seed phrases. Protecting your funds should always come before chasing the next opportunity.

What Are the Immediate Implications for the Industry?

The repeated targeting of bridges and off-chain infrastructure highlights the growing complexity of cross-chain bridge security, particularly when integrating with networks like Solana that rely on off-chain event processing. While core smart contracts may remain secure, vulnerabilities in the relay software and validator systems underscore the importance of auditing all layers of a bridge's infrastructure, not just on-chain components.

Across Protocol's rapid response to its $4.5 million exploit demonstrates how quick detection and patching can limit damage. The team deployed a fix within five hours of discovery and confirmed that no user funds were at risk at any point during the exploit. The team also stated that its scheduled ACX buyback plan would proceed as planned, unaffected by the incident.

However, not all protocols have responded with the same transparency. AFX Trade has not published a post-mortem or compensation plan at the time of writing, and VerusCoin has not issued a public statement on its July 23 exploit. The Verus Ethereum Bridge was drained for the second time in just over two months, with the July attack using the same import path weaponized against the protocol in May, suggesting that previous remediation efforts may have been incomplete.

As the industry matures, stronger security standards, better auditing practices, and improved user education will be essential. Until then, users should approach every third-party platform with caution and make security a core part of their crypto journey. The events of this week reinforce an important lesson: whether you are sending remittances, trading digital assets, or simply holding crypto for the long term, protecting your funds should always come before chasing the next opportunity.