Two Ethereum-related cross-chain bridges ran into trouble within hours of each other. According to Tokenpost, citing a CryptoSlate report, security firm Blockaid detected an exploit against AFX around 21:30 UTC on July 22 — the decentralized trading protocol, which runs on Arbitrum, saw $24.15M USDC drained from its USDC custody bridge, with the related transactions recorded on the Arbitrum chain. Around the same time, the Verus–Ethereum bridge also suffered losses, bringing the combined total from both incidents to roughly $31.69M. Separately, B² Network announced it was pausing token staking after unauthorized access to the upgrade privileges of its staking contract. What all three events have in common: the problem didn’t originate with any stablecoin issuer, but with the infrastructure that ferries assets “in transit” between chains.
Editorial take: what’s affected isn’t the card, it’s the road leading up to it
Let’s start with the conclusion — for the vast majority of USDT virtual card holders, the direct impact of this type of event is zero. Card balances are custodied within the issuer’s own account system and never touch the AFX or B² contracts. The real risk exposure appears before the top-up action itself: to save on fees, you withdraw USDT from an exchange to some L2, swap it to another chain via a third-party bridge, and only then top up the card. Every bridge along that path is an independent contract risk.
Looking at usage habits, users fall into three groups:
- Users who move funds via internal exchange transfers (a typical scenario for exchange-native cards like Bybit Card): funds move directly from the spot account to the card account without ever touching the chain. This incident poses no additional risk here.
- Users who top up directly via TRC20 / major public chains (the Asia Elite variant of MPCard, and most aggregator-type U-cards): USDT is sent directly from a wallet to the issuer’s designated address, with no third-party bridge involved — again, no risk here.
- Users who route through an L2 plus a third-party bridge to save on fees: this is the only group that needs to reassess. USDC liquidity on Arbitrum has come under short-term pressure after the incident, and both cross-chain swap slippage and bridge queue times may be amplified.
Expected timeline: within 7 days, some aggregator wallets and U-card providers may apply temporary risk controls to Arbitrum and lesser-known bridge deposit channels, showing up as delayed arrivals or “this chain is temporarily unsupported” notices. Within 30 days, whether AFX publishes an incident post-mortem and compensation plan, and whether B² restores staking, will determine whether funds flow back into the related ecosystems. Within 90 days, mainstream card issuers will likely further narrow their “officially supported chain” lists — a consistent pattern seen after nearly every bridge incident over the past two years. Readers unfamiliar with how U-card funds actually flow can start with the section on top-up routing and custody boundaries in What Is a U-Card.
Historical comparison: more like Multichain in 2023, not like the 2023 USDC depeg
The Multichain incident of July 2023 is the closest comparison — also a case of a bridge-side key/permission compromise, also resulting in bridged assets across multiple chains instantly losing their redemption backing, with bridged stablecoins on chains like Fantom trading at a notable discount. The $24.15M USDC in this AFX incident represents real assets withdrawn from within a custody bridge, and the nature of the event closely resembles Multichain: the issuer itself has no problem — the problem is “whoever was holding your money on your behalf.”
The USDC depeg of March 2023 (the Silicon Valley Bank episode, when USDC briefly fell to around $0.87) was a different kind of risk — a reserve-side problem that affects all holders equally, regardless of which chain they use. Back then, nearly every card balance denominated in USDC was affected. This time, that won’t happen.
Compared with Ronin ($625M) and Wormhole ($326M) in 2022, this $31.69M incident is relatively small in scale. But B²’s “unauthorized access to upgrade privileges” is a more concerning signal in its own right: admin privileges on upgradeable contracts are becoming a more frequent attack surface than code bugs themselves. This is a reminder for anyone who parks funds long-term in on-chain yield protocols and periodically withdraws them for card spending.
Compliance perspective: bridges aren’t a licensed layer, and recovery paths are essentially nonexistent
The boundaries here need to be spelled out clearly. Stablecoin issuers (Tether, Circle) have, in most jurisdictions, already entered licensing or registration frameworks — Hong Kong’s issuer-licensing regime under the Stablecoins Ordinance and Singapore’s MAS stablecoin regulatory framework are both moving forward; see Hong Kong Compliance Guide and Singapore Compliance Guide for key points. Virtual card issuers and acquirers are also generally bound by EMI / payment licensing requirements.
But cross-chain bridges sit in a regulatory blank spot: they are neither issuers nor licensed payment institutions, most operate as pure code, carry no obligation to segregate customer funds, hold no compensation reserves, and have no regulator you can appeal to. Once funds leave a bridge contract, you’re left relying on just two things — the issuer’s blacklisting capability (Circle has the technical ability to freeze USDC at specified addresses, though whether it acts is at its own discretion), and any voluntary compensation plan the project chooses to offer. This isn’t “illegal” — it’s simply “there’s no law that applies.” Treating this the same as fund security under a licensed card issuer is the most common misconception.
Milestones to watch next
- Whether Circle freezes the addresses involved — this determines how much of the $24.15M USDC might be recoverable, and is usually clear within days of the incident.
- B² Network’s staking restoration announcement — whether it replaces its multisig or introduces a timelock after the upgrade-privilege breach is key to judging the quality of its security remediation.
- AFX’s official post-mortem — whether it discloses the attack vector and publishes a user compensation ratio.
- Mainstream U-card providers’ supported-chain announcements — if any issuer quietly removes a chain’s top-up channel within the next 30 days, it usually won’t be announced with fanfare; readers should check official pages before topping up.
Editorial recommendations
- Holders of mainstream cards like MPCard and Bybit Card who use exchange transfers or direct mainchain top-ups: no action needed. Your funds never touched any contract involved in this incident.
- Users accustomed to “routing around” gas fees via third-party bridges: switch back to official channels this month. The few dollars saved in fees are disproportionate to the bridge contract risk. Users of self-custody routes like OneKey Card should pay particular attention — self-custody means the risk is yours alone, with no support desk to appeal to.
- Users currently parking soon-to-be-spent funds in on-chain protocols: minimize the time they sit there. What B² exposed this time is admin-privilege risk, not a code bug — reading audit reports won’t help you screen for it.
- Users preparing to renew USD subscriptions such as ChatGPT Plus: top up 3–5 days in advance. If an issuer applies temporary risk controls to certain chains recently, building in a buffer is safer than topping up on the day of the charge.
In one sentence: this isn’t a problem with the stablecoin, and it isn’t a problem with the card — it’s a problem of “taking an extra, unaccountable detour before topping up.”