An exploit drained roughly $24.15 million in USDC from a bridge operated by AFX, according to onchain security firm Blockaid, which said it detected the incident as funds moved out. The report, circulated by WuBlockchain early on July 23, 2026, adds another cross-chain bridge to a list of eight- and nine-figure losses that has grown steadily through the year.
Details on the exact mechanism were thin at the time of writing. Blockaid described detecting the drain in progress, and the figure quoted was $24.15 million in USDC. No attacker attribution, patched vulnerability, or recovery plan had been confirmed publicly. Treat everything beyond the headline number and the affected contract as unsettled until AFX or the security firm publishes a post-mortem.
The pattern behind the number
Bridges keep getting hit because of where they sit. To move a token from one chain to another, a bridge locks or holds the asset on the source side and issues or releases a representation on the destination side. That means a bridge contract sits on top of a pool of real, withdrawable value at all times. The bigger the bridge, the bigger the pool, and the bigger the payday for anyone who finds a flaw in the locking, minting, or message-verification logic.
The failure points are well documented. Some bridges have been drained through forged deposit proofs, where the attacker convinces the destination chain that a deposit happened when it did not. Others fall to signature or validator compromise, where the set of keys authorizing withdrawals is smaller or weaker than the value it guards. A third class comes from ordinary smart-contract bugs: a reentrancy path, a missing access check, an arithmetic error. Without a confirmed root cause for the AFX incident, it fits somewhere in this map, but the specific box is not yet known.
Stablecoins make the target cleaner. USDC does not need to be sold on a thin order book before it becomes useful to an attacker, and it does not swing 20% while the theft is laundered. A drained bridge holding volatile tokens forces the thief to offload into weak liquidity; a bridge holding USDC hands them $24 million that is already close to cash. That is part of why stablecoin-heavy bridges draw the sharpest attention.
Who actually absorbs the loss
Most people never interact with a bridge contract directly and assume it is not their problem. It often is. Anyone using stablecoin spending rails that route USDC across chains, anyone funding a multi-chain wallet, and anyone chasing yield across ecosystems is trusting one or more bridges to hold value in transit. When a bridge is drained, the loss usually falls on liquidity providers and on users whose funds were mid-transfer or pooled at the moment of the exploit, not on the protocol's treasury.
This is the same counterparty question that runs through the rest of the market. A self-custody wallet protects the keys to your own funds, but the second those funds enter a bridge, a lending pool, or a custodial platform, you inherit that system's security assumptions. The AFX incident, the Allbridge Core flash-loan exploit, and the Wanchain Cardano-BNB bridge hack all point the same direction: the smart-contract layer between chains is where value concentrates and where it leaks.
Market conditions did not amplify the damage this time. As of July 23, 2026, Bitcoin traded near $66,155, down 0.7% on the day, Ethereum sat around $1,934, and the Fear and Greed Index read 40, a neutral setting. A $24 million bridge loss during a calm tape is a security story, not a macro one. It does not move prices; it moves trust.
Practical takeaways while the details firm up
Users routing assets across chains can lower exposure without waiting for the full report. Move value in smaller tranches rather than parking a large balance inside a bridge or its associated pools. Favor bridges and providers that publish audits, run active monitoring, and have a track record of disclosure. Where a direct route exists, such as a native issuer's own cross-chain transfer for USDC, that path avoids a third-party lock-and-mint contract entirely.
For liquidity providers, the calculus is starker. Supplying to a bridge pool means underwriting the contract's security in exchange for yield. The AFX loss is a reminder that the return has to compensate for a real tail risk of a total, sudden drain, not a theoretical one.
Overview
Blockaid reported a roughly $24.15 million USDC exploit on the AFX-operated bridge, detected as the funds were moving. The root cause, attacker, and any recovery path remained unconfirmed as of July 23, 2026. The incident continues a run of cross-chain bridge failures in 2026, driven by the same structural fact: bridges concentrate withdrawable value and complex code in one place. Users and liquidity providers exposed to multi-chain routing carry that risk directly. Until AFX publishes a post-mortem, treat the $24.15 million figure as the one firm data point and everything else as pending.



