Skip to main content
AVOID.NET

Fact-check findings

What an automated fact-checker found when it re-read H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

4 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #4[disputed][awaiting moderator]in section: Attack 2: Across Protocol (Solana Relayer) — $3.35–$4.5M (July 17, 2026)
    Attacker funding sources included Tornado Cash on Ethereum and FixedFloat on Solana.
    reviewerAcross attacker's funding sources included Tornado Cash on Ethereum and FixedFloat on Solana.This appears to be a misattribution: the Tornado Cash/FixedFloat funding detail traces to the unrelated June 2026 Raydium exploit, not the Across attacker. None of the four cited Across sources contain this claim, and the one uncited source that discusses laundering explicitly separates it from Across.
    Proposed correction (not yet applied)
    The attacker's funding and laundering sources were not disclosed in public reporting on the Across Protocol exploit.
  2. #10[disputed][awaiting moderator]in section: Attack 6: B² Network Bridge — $3.86M (July 23, 2026)
    B² Network, a modular Bitcoin scaling solution, lost approximately 8.59 million B2 tokens valued at $3.86 million on July 23, 2026.
    reviewerB² Network lost 8.59M B2 tokens ($3.86M) on July 23, 2026, via unauthorized upgrade-authority takeover of its staking contract, converting ~5,409 WBNB (~$3.11M).Token/dollar amounts and mechanism are correct, but the date is off by one day across the heading, body, and timeline.
    Proposed correction (not yet applied)
    B² Network, a modular Bitcoin scaling solution, lost approximately 8.59 million B2 tokens valued at $3.86 million on July 22, 2026.
  3. #11[disputed][awaiting moderator]in section: Attack 6: B² Network Bridge — $3.86M (July 23, 2026)
    The project subsequently offered the attacker legal immunity in exchange for return of 90% of stolen funds, a structure mirroring Wanchain's response to its own exploit two days prior.
    reviewerB² Network offered the attacker legal immunity in exchange for return of 90% of stolen funds, mirroring Wanchain's structure.The page reverses the actual figure and mischaracterizes it as mirroring Wanchain's deal (which required 90% returned for a 10% bounty); B²'s ask (10% returned) is structurally the opposite.
    Proposed correction (not yet applied)
    The project subsequently offered the attacker legal immunity in exchange for return of at least 10% of the stolen funds within 24 hours, a much lower return threshold than Wanchain's response to its own exploit two days prior.
  4. #12[disputed][awaiting moderator]in the timeline
    2026-07-23
    reviewerB² Network timeline entry date for the exploit.Same date error as the section heading/content; grouped under the same defect.
    Proposed correction (not yet applied)
    2026-07-22

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #14[unverifiable][awaiting moderator]in section: Attack 7: Verus–Ethereum Bridge — $7.54M (July 23, 2026)
    Notably, user funds from the May 2026 hack had been redeposited into the bridge on July 8, and those same funds were among the assets drained a second time on July 23.
    reviewerUser funds from the May 2026 Verus hack were redeposited into the bridge on July 8, and those same funds were drained again on July 23.Could not independently confirm the specific July 8 redeposit date or that the exact same recovered funds were drained again; not contradicted, just unconfirmed in the sources checked.
  2. #20[unverifiable][awaiting moderator]in section: Broader July 2026 Context and Total Losses
    Bridges accounted for approximately 21% of total July protocol losses by the PANews methodology.
    reviewerBridges accounted for approximately 21% of total July protocol losses by the PANews methodology.The arithmetic implied by the page's own cited figures does not obviously produce 21%, but the original article text could not be directly retrieved to confirm or refute an explicit PANews percentage statement.

stale

2 claims

The claim was accurate when written but events since have overtaken it.

  1. #21[stale][awaiting moderator]in section: Overview of the July 2026 Bridge Hack Wave
    Year-to-date through July, bridge exploits had accounted for at least $328.6 million across eight or more major incidents, according to reporting from Bitcoin Foundation and CryptoTimes.
    reviewerYear-to-date through July, bridge exploits had accounted for at least $328.6 million across eight or more major incidents, according to Bitcoin Foundation and CryptoTimes.The $328.6M/eight-incident figure is a PeckShield tally as of May 18, 2026, not a July year-to-date figure. Presenting it as 'through July' understates the true 2026 bridge-loss total, since it excludes Taiko, TeleSwap, Across, Allbridge, Wanchain, AFX Trade, B² Network, Verus (second hit), and Garden Finance — several of which are the subject of this very page.
    Proposed correction (not yet applied)
    Year-to-date through mid-May 2026, bridge exploits had accounted for at least $328.6 million across eight major incidents, according to reporting from Bitcoin Foundation and CryptoTimes; that tally predates, and does not include, the June and July incidents detailed in this report.
  2. #22[stale][awaiting moderator]in section: Broader July 2026 Context and Total Losses
    Year-to-date 2026 bridge hack losses had exceeded $328.6 million by month-end across at least eight major incidents, with projections from DeFi analysts suggesting the full-year total could exceed $1 billion.
    reviewerYear-to-date 2026 bridge hack losses had exceeded $328.6 million by month-end (July) across at least eight major incidents.Same underlying error as the Overview section; the figure is stale and should not be characterized as a July month-end total.
    Proposed correction (not yet applied)
    Bridge hack losses had exceeded $328.6 million through mid-May 2026 across at least eight major incidents, a tally that predates the June and July wave detailed in this report; projections from DeFi analysts suggest the full-year total could exceed $1 billion.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #3[partially supported][awaiting moderator]in section: Attack 2: Across Protocol (Solana Relayer) — $3.35–$4.5M (July 17, 2026)
    The attacker deployed 1,627 single-use Solana wallets to submit fictitious deposit events with an aggregate face value of approximately $41.7 million, routing payment requests across 18 destination chains.
    reviewerThe Across attacker deployed 1,627 single-use Solana wallets submitting fictitious deposit events with an aggregate face value of approximately $41.7 million across 18 destination chains.The figures are accurate and independently verifiable, but none of the four sources actually cited in this section contain them; the real source (crypto.news) is not in the page's source list for this section.
  2. #17[partially supported][awaiting moderator]in section: Systemic Attack Vector Analysis
    The Decripto analysis alleged that AI-assisted tooling was being used by attackers to accelerate discovery and exploitation of these non-code attack surfaces.
    reviewerThe Decripto analysis alleged that AI-assisted tooling was being used by attackers to accelerate discovery and exploitation of non-code attack surfaces across the July wave.The page overstates a hedged, general claim about LLMs making vulnerability discovery easier into an assertion that AI tooling was actually used in these specific attacks; the source disclaims this.
  3. #18[partially supported][awaiting moderator]in section: Systemic Attack Vector Analysis
    The 1inch blog on 2026 bridge hacks documented that bridge infrastructure had produced the majority of the year's largest DeFi exploits, with failure modes unchanged from 2022.
    reviewerThe 1inch blog documented that bridge infrastructure had produced the majority of the year's largest DeFi exploits, with failure modes unchanged from 2022.The underlying comparison to 2022 failure modes is roughly supported; the 'majority of the year's largest DeFi exploits' quantifier is not something the cited post actually states.

confirmed

13 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Attack 1: TeleSwap — $735,000 (July 15, 2026)
    TeleSwap, a DeFi platform billing itself as a Bitcoin-native bridge hub, experienced suspicious outflows from its Bitcoin hot wallet on approximately July 15, 2026. The exploit was not disclosed publicly by the project; instead, on-chain researcher ZachXBT reported the incident on July 21, noting that over $735,000 had drained from the hot wallet and that transaction processing had silently halted.
    reviewerTeleSwap's Bitcoin hot wallet showed suspicious outflows around July 15, 2026, totaling over $735,000, with a 5-day silent gap before ZachXBT's July 21 disclosure.Cited source directly supports the amount, date, disclosure mechanism, and timeline.
  2. #2[confirmed][no action needed]in section: Attack 2: Across Protocol (Solana Relayer) — $3.35–$4.5M (July 17, 2026)
    The stolen funds belonged to Risk Labs, the foundation operating the relayer, rather than end users; all user bridge transfers were completed or refunded on the same day. The attack vector involved a missing verification of the 8-byte Anchor event discriminator in the off-chain Solana relayer code, which allowed an attacker to forge deposit events that the relayer treated as legitimate.
    reviewerThe Across Protocol Solana relayer exploit ($3.35-4.5M) resulted from a missing verification of the 8-byte Anchor event discriminator; user funds were unaffected and losses fell on Risk Labs.Core mechanism and loss allocation independently confirmed.
  3. #5[confirmed][no action needed]in section: Attack 3: Allbridge Core — $1.65–1.66M (July 20, 2026)
    The attacker used a roughly $1.12 million USDC flash loan from the Kamino lending protocol to rapidly manipulate the price ratio between USDC and USDT in Allbridge's liquidity pools.
    reviewerAllbridge Core lost $1.65-1.66M on July 20, 2026 via a ~$1.12M USDC Kamino flash loan manipulating the USDC/USDT pool ratio, a repeat of an unpatched single-pool pricing flaw.Loss amount, flash loan source/amount, and repeat-vulnerability characterization are independently corroborated; the exact incident date (July 19 vs. July 20 across sources) is ambiguous by a day but not disputed here given the cited TechTimes source uses July 20.
  4. #6[confirmed][no action needed]in section: Attack 4: Wanchain Cardano–BNB Chain Bridge — $10–13M (July 21, 2026)
    The root cause was identified by blockchain security firm BlockSec Phalcon as a non-injective signed-message encoding flaw in the bridge's TreasuryCheck validator. The bridge constructed signed messages by concatenating 14 variable-length redeemer fields without separators or length identifiers, allowing an attacker to reuse a legitimate signature for a materially larger transaction through field-boundary ambiguity.
    reviewerThe Wanchain Cardano-BNB bridge was drained of ~515M NIGHT tokens ($10-13M) via a non-injective signed-message encoding flaw in the TreasuryCheck validator concatenating 14 fields without separators.Technical detail matches cited source closely, including the 14-field concatenation and field-boundary ambiguity mechanism.
  5. #7[confirmed][no action needed]in section: Attack 4: Wanchain Cardano–BNB Chain Bridge — $10–13M (July 21, 2026)
    Wanchain took the bridge offline and subsequently offered the attacker a 10% white-hat bounty if 90% of funds were returned, setting an August 6, 2026 deadline.
    reviewerNIGHT token price crashed more than 30% to an all-time low near $0.016 following the Wanchain exploit; Wanchain offered a 10% white-hat bounty for 90% return with an August 6, 2026 deadline.Price crash and bounty terms both independently confirmed.
  6. #8[confirmed][no action needed]in section: Attack 5: AFX Trade Bridge — $24.15M (July 22, 2026)
    An attacker compromised the private signing keys of five of the bridge's seven validators, obtaining 7,142 of the 10,000 total voting units distributed across the validator set — exceeding the 6,667 required for quorum.
    reviewerAFX Trade's attacker compromised 5 of 7 validators controlling 7,142 of 10,000 voting units, exceeding the 6,667 quorum threshold, to drain $24.15M USDC within the 200-second challenge window, later converted to ~12,467.5 ETH.Precise numeric match across independent search corroboration.
  7. #9[confirmed][no action needed]in section: Attack 5: AFX Trade Bridge — $24.15M (July 22, 2026)
    In response, AFX head of growth Ken C offered the attacker a white-hat bounty deal allowing retention of 30% ($7.2 million) in exchange for returning the remaining 70%.
    reviewerAFX head of growth Ken C offered the attacker a white-hat deal allowing retention of 30% (~$7.2M) in exchange for returning 70%.Directly confirmed by cited source.
  8. #13[confirmed][no action needed]in section: Attack 7: Verus–Ethereum Bridge — $7.54M (July 23, 2026)
    The attack exploited a flaw in the VerusProof.checkExportAndTransfers function that failed to verify that cross-chain asset transfers were backed by matching assets on the source chain before executing payouts.
    reviewerThe Verus-Ethereum bridge exploit ($7.54M, July 23, 03:45 UTC) stemmed from a flaw in VerusProof.checkExportAndTransfers that failed to verify matching source-chain backing, replaying the same bug class as the May 2026 $11.6M exploit.Asset list, function name, and 'same bug class as May' framing are corroborated by multiple independent sources.
  9. #15[confirmed][no action needed]in section: Supplementary Attack: Taiko Bridge — $1.7M (June 22, 2026 / Recovered July 2026)
    The exploit abused Taiko's permissionless prover registration system: an SGX (Secure Enclave) signing key had been mistakenly exposed on GitHub, enabling a rogue SGX instance to register, submit invalid proofs, and unlock approximately $1.7 million in ERC20 assets from the vault.
    reviewerThe Taiko bridge exploit ($1.7M, June 22, 2026) resulted from a leaked SGX signing key on GitHub enabling forged message proofs; bridge reopened ~July 2, 2026 after a 10-day pause and full reimbursement.Mechanism, amount, and reopening timeline (July 2, 10 days after June 22) are consistent with the cited CoinDesk headline and independent reporting.
  10. #16[confirmed][no action needed]in section: Supplementary Attack: Garden Finance — $450K (July 26–27, 2026)
    Analysts noted this was alleged to be Garden Finance's second exploit in nine months, with both incidents traced to solver-layer infrastructure, underscoring that the security perimeter of atomic-swap systems extends beyond audited contracts.
    reviewerGarden Finance paused operations after a $450,000 USDT exploit (July 26-27, 2026) traced to a third-party solver's off-chain database, its second such incident in nine months.All key details independently confirmed.
  11. #19[confirmed][no action needed]in section: Broader July 2026 Context and Total Losses
    The month saw an 18.7% increase in losses over June 2026.
    reviewerPANews reported total July 2026 security losses of approximately $97 million, an 18.7% increase over June.Confirmed via search-accessible content of the primary source (direct fetch was blocked by 403/429, but indexed text matches exactly).
  12. #23[confirmed][no action needed]in section: Broader July 2026 Context and Total Losses
    CryptoAdventure and NullTX reported $210 million when including a Coldcard hardware wallet bug that alone accounted for approximately $110 million
    reviewerCryptoAdventure and NullTX reported $210 million in July losses when including a Coldcard hardware wallet bug that alone accounted for approximately $110 million.Reconciled: the $70M vs $110M discrepancy across sources reflects the escalating, multi-wave nature of the Coldcard incident rather than an error.
  13. #24[confirmed][no action needed]in section: Broader July 2026 Context and Total Losses
    the Medium Coinmonks tally reached $242 million using similar all-inclusive methodology
    reviewerThe Medium Coinmonks tally reached $242 million using an all-inclusive methodology similar to CryptoAdventure/NullTX.Confirmed via search-indexed content; direct fetch was blocked (403).
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.