Why DeFi Bridges Keep Getting Hacked While Blockchains Stay Safe
DeFi bridges are designed to move crypto between blockchains, but they've become the easiest target for attackers. Between July 19 and July 25, 2026, four separate protocols lost a combined $47 million or more to exploits that never touched the underlying blockchains themselves. The pattern reveals a troubling reality: the infrastructure that connects crypto networks is far more vulnerable than the networks it connects.
What Actually Happened During the July 2026 Hack Wave?
The week of July 19-25 saw four distinct incidents, though they're often lumped together in headlines. Understanding what happened to each one shows why bridges remain such concentrated targets for attackers.
- Wanchain (July 21): A signature-reuse flaw in the Cardano-to-BNB Chain bridge allowed attackers to reuse a legitimately signed message to authorize a withdrawal far larger than what had actually been approved, resulting in roughly 515 million NIGHT tokens stolen, valued between $10 million and $13 million depending on the token's price at the time.
- AFX Trade (July 22): The Arbitrum-based perpetuals exchange lost $24.15 million in USDC after its bridge's validator signing keys were compromised, giving attackers enough signatures to fake the bridge's quorum and approve an unauthorized withdrawal.
- Verus (July 22-23): The Ethereum bridge approved eight withdrawals without verifying that matching reserves actually backed them, losing $7.54 million across ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, repeating the same class of bug from an earlier Verus exploit in May 2026.
- B² Network (July 22): A Bitcoin scaling network discovered unauthorized access to its staking contract's upgrade authority, draining roughly 8.59 million B2 tokens worth about $3.86 million, though this was a staking-infrastructure breach rather than a bridge exploit.
The AFX Trade and Verus incidents combined account for the widely reported $31.7 million figure, but they represent two separate hacks that happened to occur within hours of each other, not a single coordinated attack. Add smaller incidents like an Allbridge Core flash-loan exploit on Solana (about $1.65 million on July 19) and a Lien Finance bond-pricing exploit (about $542,000 on July 24), and verified losses across the week exceed $47 million.
Why Do Bridges Get Targeted More Than Blockchains?
None of the four incidents touched the underlying blockchain each protocol ran on. The Midnight Foundation confirmed that the Cardano-linked Midnight blockchain "remains unaffected" throughout the Wanchain incident, with the core network continuing to operate as intended. Reporting on the AFX Trade exploit was consistent on the same point: the breach stayed contained to the bridge's custody layer and never reached Arbitrum's underlying network.
A bridge is separate infrastructure that a protocol operates on top of a blockchain, usually a set of smart contracts and signing keys that lock tokens on one chain and mint or release them on another. DeFi protocols rely on bridges precisely because no single blockchain can natively talk to another. That same design, a smaller set of contracts and keys with outsized control over funds, is what makes bridges a concentrated target. Signature-reuse bugs, compromised validator keys, and unchecked withdrawal approvals are three different technical failures, but all three exploited the same category of weak point: the bridge's authorization logic, not the base chain's consensus mechanism.
How to Document Losses From Bridge Hacks for Tax Purposes
If your funds were caught in one of these exploits, the immediate question isn't just about recovery; it's about what you actually owe the IRS. The tax treatment of stolen or hacked crypto depends on several factors, and proper documentation now can protect you from being taxed on money you no longer have access to.
- Theft Loss Deduction: Crypto held for investment or trading may qualify for a theft-loss deduction with no disaster requirement, unlike personal-use losses which follow a disaster-only casualty-loss rule, making the distinction between how you held the crypto critical to your tax outcome.
- Income Already Earned: If you earned staking rewards, airdrops, or trading gains before the exploit happened, that income was already taxable when you received it, regardless of what happened to it afterward, so you cannot retroactively erase that tax obligation.
- Proof of Holdings: Documentation proving what you held and when you lost access to it protects you from being taxed on money you no longer have, making timestamped records of your wallet balances before the exploit essential for any IRS inquiry or dispute.
You don't owe tax on the theft itself. Having crypto stolen from you isn't a taxable event the way a sale or trade is. You didn't dispose of the asset by choice, so there's nothing to recognize as a gain. The IRS's own digital asset reporting guidance centers on selling, exchanging, or receiving digital assets, not on assets that were simply taken from you without your involvement. If your funds never moved on your instruction, you have no reporting obligation for that specific loss event.
However, two situations can still create a real tax obligation even after a hack. First, if you earned income, staking rewards, airdrops, or trading gains before the exploit happened, that income was already taxable when you received it, regardless of what happened to it afterward. Second, if a protocol later compensates affected users, that compensation may itself be treated as income or a recovery event with its own tax implications.
What the Pattern Reveals About DeFi Security
The concentration of attacks on bridges rather than blockchains points to a structural vulnerability in how decentralized finance currently operates. Bridges are necessary infrastructure, but their design creates a single point of failure. When validator keys are compromised or authorization logic contains flaws, attackers gain access to custody of funds across multiple chains simultaneously. The fact that three of the four incidents involved authorization-layer failures, not consensus-mechanism breaches, suggests that bridge operators may be underinvesting in the security of their signing infrastructure relative to the value flowing through it.
The Verus bridge's repeat vulnerability is particularly telling. The same class of bug, unchecked withdrawal approvals, appeared in both the May 2026 exploit and the July 2026 incident, suggesting that fixes from the first incident may not have been comprehensive or that the protocol's security review process didn't catch the underlying architectural issue. For users holding assets in bridges or staking contracts, the lesson is clear: the underlying blockchain may be secure, but the infrastructure sitting on top of it carries concentrated risk.