Bridge Exploits Surge as Wanchain and AFX Hacks Expose Persistent Cross-Chain Risks

3 hour ago 1 sources negative

Key takeaways:

  • Off-chain attacks are now the main DeFi vulnerability, threatening bridge-dependent token value.
  • Recovery outcomes for NIGHT and AFX may set precedent for investor confidence in cross-chain bridges.
  • Investors should watch for ETH sell pressure if attacker liquidates 12,467 stolen ETH.

Two major cross-chain bridge exploits within the same month have again highlighted the cryptocurrency industry's persistent infrastructure vulnerabilities. Wanchain issued an ultimatum to the attacker behind last week’s theft of approximately 515 million NIGHT tokens, while decentralized derivatives protocol AFX revealed that a $24.15 million heist was traced to a North Korean social engineering campaign rather than a smart contract flaw.

Wanchain Gives Hacker Deadline
Wanchain set a deadline of 12:00 UTC on August 6 for the exploiter to voluntarily return the stolen assets. The attack drained roughly $13 million in bridged NIGHT tokens from the Cardano–BNB Chain bridge, representing about 97% of the bridge’s reserves. If the funds are not returned, the company intends to escalate recovery through law enforcement and public bounty programs. The forced sell-off pushed NIGHT to an all-time low, though the Midnight Foundation clarified that its own blockchain was not compromised.

AFX Exploit: From Fake Recruiter to $24M Loss
AFX’s post‑mortem detailed an elaborate supply‑chain attack that began on July 9, when a developer was contacted by an individual posing as a recruiter from “Oddium Lab.” Cloning a malicious repository led to a compromised workstation, which the attacker then used to infiltrate internal systems. By July 22, a malicious Groovy plugin had been planted in AFX’s artifact repository, granting the attacker control over validator nodes. At 21:27 UTC, the validators signed a bridge transaction that drained 24.15 million USDC from the custody bridge. The USDC was quickly swapped for 12,467 ETH on Ethereum. AFX attributed the attack to UNC4899, a DPRK‑linked group also tracked as TraderTraitor.

The AFX incident marks one of several recent exploits where intrusions bypass on‑chain code entirely, instead compromising off‑chain developer infrastructure. One day earlier, Ostium reported a similar 23.75 million USDC breach tied to compromised off‑chain systems. Both incidents reinforce PeckShield data showing cross‑chain bridges remain a leading source of crypto losses in 2026.

As protocols tighten security, the Wanchain deadline and AFX’s upcoming recovery plan on August 3 will test whether negotiated settlements or legal enforcement can stem the tide of bridge‑related thefts.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.