
Four crypto losses in three weeks show how bridge security depends on decisions made years earlier, in layers no depositor ever sees.
Four separate crypto losses hit within three weeks in July and August 2026. Each had one thing in common: the failure was set up long before the month it happened, in decisions no depositor was ever shown.
An audit tells you the contract logic works. It doesn't tell you who holds the keys, how many people have to agree before funds move, or what an old fix actually covered. Every question retail knows to ask is present tense: is it audited, is it big, has it been hacked before? Yet every one of these losses was set up in the past, by someone else.
AFX Trade runs its own bridge on a validator quorum – a set of signers who must clear a threshold before a withdrawal executes. On July 22, an attacker gained control of roughly two-thirds of the total keys. The withdrawal executed exactly as the system was built to allow. A deposit screen shows a token symbol and a network name. The validator count, who holds the keys, and whether they're hardware-secured across separate custodians never appear on it. AFX's bridge doesn't publish them anywhere else either.
Five days earlier, a different bridge failed through a decision made three years ago. A user checking Allbridge's history in June 2026 would have found a 2023 incident marked resolved – a fact both true and useless. What they needed to see was the scope of the fix, which nobody publishes, because a patch closes the hole it names and leaves the class of attack behind it open. Allbridge said it will return affected funds and move away from pools. Nearly three weeks on, it hasn't reported either as finished.
Seven chains, one breach, because one operator held every key. Spreading funds across chains only helps when a different party controls each chain's keys, and that architecture was set long before the attacker arrived. Nothing visible to a client would distinguish the arrangement that lost $11.8 million from the one that lost nothing. Both were choices made years earlier, in the same invisible layer. Two weeks after the event, Triple-A has yet to disclose how the wallets were accessed.
Anyone who set up a wallet on that firmware received a seed that an attacker could rebuild without ever touching the device. The theft happened in 2026. The compromise happened in 2021, in a code path no owner could inspect, on hardware bought specifically to avoid trusting anyone. Nobody caught it for five years. Starting July 30, attackers swept roughly 1,816 BTC from more than 5,200 addresses across four waves. The first drained 594 BTC in 25 minutes. By Aug. 7, a linked wallet moved about $1.94 million, with roughly 90% still sitting untouched.
Most people think a bigger bridge is a safer bridge. That assumption is incorrect. You can't check any of this the way you can check code with an audit. What you can check is simpler: does the operator tell you any of this at all? How many validators or verifiers does the bridge use, and how many of them must agree before money moves? How much of an old exploit did the last fix actually cover? Are customer funds kept separate from the company's own money, or mixed together in one pot?
Answering those questions doesn't make a bridge safe. It's still the only part of this hidden decision layer that an outsider ever gets to see. When a bridge won't answer them, that silence is the clearest warning sign you can have.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.