Four DeFi bridges and staking platforms lost a combined $47 million or more to attackers within a single week in July 2026. If part of that money was yours, the tax question in front of you is not abstract. It comes down to three things: what you actually owe, what you can actually deduct, and what you need to prove if the IRS, a bank, or your own peace of mind asks later.
Here's what actually happened in the wave of DeFi bridge hacks between July 19 and July 25, 2026, why the exploits kept landing on bridges rather than the blockchains underneath them, and what current US tax law actually says about stolen or hacked crypto. Then comes the part that matters no matter what the law says: how to document exactly what you held, when you lost access to it, and what happened next.
Key Takeaways
- Four incidents, not three: Wanchain, AFX Trade, and Verus were bridge exploits. B² Network's staking-contract breach is a separate, fourth incident, not part of the widely quoted $31.7 million figure.
- $31.7 million is AFX Trade and Verus combined: AFX Trade lost $24.15 million and Verus lost $7.54 million within hours of each other in the same week.
- B² Network halted staking after a $3.86 million breach: caused by unauthorized access to the staking contract's upgrade authority, not a bridge exploit.
- Deductibility depends on why you held the crypto: personal-use losses follow the disaster-only casualty-loss rule, while crypto held for investment or trading, the common case for DeFi users, may still qualify for a theft-loss deduction with no disaster requirement.
- Documentation matters regardless of deductibility: proving what you held and when protects you from being taxed on money you no longer have access to.
What Happened: Four DeFi Bridge Hacks in 48 Hours
Between July 21 and July 23, 2026, attackers hit four separate protocols. Three were bridge exploits. The fourth was a staking-infrastructure breach that gets lumped in with the bridge hacks because of when it happened, not because of how it happened.
Wanchain: roughly $10-13 million (Cardano-BNB Chain bridge)
On July 21, 2026, Wanchain's bridge connecting Cardano and BNB Chain lost roughly 515 million NIGHT tokens. Third-party analysis attributes the exploit to a signature-reuse flaw in the bridge's validator logic, which let the attacker reuse a legitimately signed message to authorize a withdrawal far larger than what had actually been approved. Wanchain hasn't published a final post-mortem as of this article's publish date, so treat the exact mechanism as third-party analysis, not a confirmed statement from Wanchain itself.
The dollar value moved with NIGHT's price after the exploit. Early estimates put the loss near $10 million, while later figures land closer to $13 million once the token's roughly 30 percent price drop is factored in. Wanchain took the bridge offline while it investigates and has promised full transparency once that investigation concludes.
AFX Trade: $24.15 million (Arbitrum)
The following day, on July 22, 2026, the Arbitrum-based perpetuals exchange AFX Trade lost $24.15 million in USDC after its bridge's validator signing keys were compromised. Enough signatures were compromised to fake the bridge's quorum and approve an unauthorized withdrawal, though the exact method behind the key compromise remains under investigation. AFX Trade's head of growth publicly offered the attacker a deal: return 70 percent of the funds and keep the remaining 30 percent as a "white hat bounty," with no confirmed resolution reported as of this article's publish date.
Verus: $7.54 million (Ethereum bridge)
Hours after the AFX Trade incident, the Verus bridge on Ethereum lost $7.54 million across a mix of assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. The bridge approved eight withdrawals without verifying that matching reserves actually backed them, the same class of bug behind an earlier Verus exploit in May 2026.
AFX Trade's $24.15 million and Verus's $7.54 million add up to the widely reported $31.7 million figure. That number describes two separate hacks that happened to land within hours of each other, not one event with one cause.
B² Network: $3.86 million (staking, not a bridge)
Also on July 22, 2026, B² Network, a Bitcoin scaling network, discovered that an attacker had gained unauthorized access to its staking contract's upgrade authority and drained roughly 8.59 million B2 tokens, worth about $3.86 million. B² Network's own X thread confirmed the team suspended $B2 staking as a precaution, offered the attacker legal immunity in exchange for returning at least 10 percent of the funds within 24 hours, and committed to compensating affected users in full.
This is the incident that halted staking, and its cause, a compromised contract upgrade authority, is different from the signature and key-compromise bugs behind the three bridge exploits above.
| Protocol | Date (2026) | Amount | What happened |
|---|---|---|---|
| Wanchain (Cardano-BNB Chain bridge) | July 21 | ~$10-13M | Signature-reuse flaw in the bridge's validator logic |
| AFX Trade (Arbitrum) | July 22 | $24.15M | Compromised bridge validator signing keys |
| Verus (Ethereum bridge) | July 22-23 | $7.54M | Withdrawals approved without matching reserves |
| B² Network (staking) | July 22 | $3.86M | Compromised staking-contract upgrade authority |
Add two smaller incidents from the same week, an Allbridge Core flash-loan exploit on Solana (about $1.65 million on July 19) and a Lien Finance bond-pricing exploit (about $542,000 on July 24), and total verified losses across July 19-25, 2026 run past $47 million, according to industry reporting.
Four different root causes hit four different protocols, and anyone with funds sitting in a bridge or a staking contract had a very bad week.
Know exactly what you held, and when
If your funds touched Wanchain, AFX Trade, Verus, or B² Network, CoinTracking shows you exactly what was in that wallet before the exploit, timestamped and ready to back up your records.
Why Bridges Keep Getting Hit, Not the Blockchains Themselves
None of the four incidents touched the underlying blockchain each protocol runs on. The Midnight Foundation confirmed that the Cardano-linked Midnight blockchain "remains unaffected" throughout the Wanchain incident, with the core network continuing to operate as intended. Reporting on the AFX Trade exploit was consistent on the same point: the breach stayed contained to the bridge's custody layer and never reached Arbitrum's underlying network.
That distinction matters if you're trying to figure out your own exposure. A bridge is separate infrastructure that a protocol operates on top of a blockchain, usually a set of smart contracts and signing keys that lock tokens on one chain and mint or release them on another. DeFi protocols rely on bridges precisely because no single blockchain can natively talk to another. That same design, a smaller set of contracts and keys with outsized control over funds, is what makes bridges a concentrated target.
Signature-reuse bugs, compromised validator keys, and unchecked withdrawal approvals are three different technical failures. All three exploited the same category of weak point: the bridge's authorization logic, not the base chain's consensus mechanism.
Do You Owe Tax on Cryptocurrency That Was Stolen?
You don't owe tax on the theft itself. Having crypto stolen from you isn't a taxable event the way a sale or trade is. You didn't dispose of the asset by choice, so there's nothing to recognize as a gain. The IRS's own digital asset reporting guidance centers on selling, exchanging, or receiving digital assets, not on assets that were simply taken from you without your involvement. If your funds never moved on your instruction, you have no reporting obligation for that specific loss event.
Two situations can still create a real tax obligation even after a hack. First, if you earned income, staking rewards, airdrops, trading gains, before the exploit happened, that income was already taxable when you received it, regardless of what happened to it afterward. Second, if a protocol later compensates you, in tokens, in a settlement, or through a recovery process, that compensation may itself need to be evaluated for tax purposes depending on how it is structured. None of the four July 2026 incidents had a finalized compensation process as of this article's publish date, so treat this as a flag to revisit with a tax professional once, and if, a payout actually materializes.
Can You Deduct a Crypto Theft Loss on Your Taxes? What Current Law Says
This is the harder answer, and it depends on why you were holding the crypto that got stolen. If you held it purely for personal use, the loss falls under the same rule as any other personal casualty loss: a deduction is generally not allowed unless the loss was caused by a federally or State-declared disaster, per the IRS's own page on its 2026 casualty-loss-deduction changes, and a DeFi bridge exploit doesn't meet that bar. Most people moving funds through a DeFi bridge, though, are holding that crypto as an investment or for trading, and that puts them in a different category entirely.
A theft loss on crypto held for investment or profit can still be deductible, disaster or no disaster. A 2025 IRS Office of Chief Counsel memorandum on scam and hack victims confirms this path stays open where the underlying motive behind holding the crypto was investment-related, though it still depends on the specific facts: you generally need a genuine profit motive and no reasonable prospect of recovering the funds. Form 4684 (Casualties and Thefts) reflects the same split. Section A covers personal-use property and is gated by the disaster requirement above. Section B covers investment and income-producing property, and it carries no disaster requirement at all.
Separately, a narrow safe harbor exists for certain investment theft losses tied to fraudulent arrangements with an identified, indicted lead figure, think Ponzi-scheme cases, but whether that narrower provision could ever apply to an anonymous DeFi bridge exploit is a different and much less certain question. Which category your own loss falls into, personal-use, investment-motivated, or neither, is something only a tax professional can determine for your specific situation. It shouldn't be assumed either way.
None of this is a special rule invented for these four incidents. The personal-use side of it is the same framing CoinTracking has used for other exchange failures and hacks, including crypto losses from the FTX bankruptcy and the BlockFi bankruptcy. What changes the calculation for a lot of DeFi users is the investment-motive path above, which is exactly why the answer here isn't a flat no.
Which category applies changes the outcome completely, so don't assume the answer before you've had that conversation.
Outside the US, the rules differ by jurisdiction. Australia's Tax Office, for instance, publishes its own guidance for loss or theft of crypto assets, worth checking if you file outside the US.
How to Report Stolen Cryptocurrency on Your Taxes: Documentation That Holds Up
If the loss itself isn't deductible, documenting it might feel pointless, but that instinct is wrong. Good documentation protects you from a different problem: being unable to prove what you actually held, when you lost access to it, and what your cost basis was on everything that came before and after. That protects the accuracy of your remaining holdings, supports you if a protocol eventually compensates victims, and gives you something concrete if the rules around theft losses change again in the future.
The mechanics look a lot like building a Source of Funds report. Instead of proving where money came from, you are proving what you had, at what point in time, and what happened to it next. A few things are worth pulling together immediately, before records get harder to find.
- Wallet or account balance: a timestamped screenshot or export showing exactly what you held in the affected protocol immediately before the exploit.
- Transaction history and cost basis: the acquisition dates and cost basis of the specific coins that were in that wallet, calculated the same way as any other taxable event, typically using FIFO or another accounting method.
- The protocol's own statement: Wanchain, AFX Trade, Verus, and B² Network each published some form of official update. Save a copy, since official pages can be edited or taken down as an investigation continues.
- Any correspondence about compensation: if a protocol offers a partial refund, a token swap, or a claims process, keep every message and date.
- A clear timeline: when you deposited funds, when the exploit happened, and when, if ever, you learned about it.
A CoinTracking import does most of this automatically for anything already connected to your account. Every trade, deposit, and transfer carries its own timestamp and cost basis, so if a wallet you were using gets caught in a future incident, you already have the underlying record instead of trying to reconstruct it from memory. Reporting crypto losses correctly for everything that's still deductible, like closing out a different position at a loss elsewhere in your portfolio, still depends on that same clean transaction history.
Document the loss properly
CoinTracking imports your transaction history from over 400 exchanges and wallets and generates a Source of Funds report that traces exactly where your crypto came from and where it went, gaps included.
What This Means for You: Three Scenarios
Where you stand depends on your own situation, not just on which protocol made headlines. Most readers will fall into one of three cases: funds caught in one of the four affected protocols, regular DeFi bridge use that happened to escape this particular wave, or staked crypto exposed the way B² Network's users were.
Scenario A: Your funds were in one of the four affected protocols
Save everything listed above now, while the protocol's statements and your own records are still easy to find. Check the protocol's official channels for a compensation or claims process rather than third-party rumors, since B² Network and AFX Trade have both signaled some form of user compensation or negotiated recovery. Don't assume a deduction is available. Assume documentation is your only leverage until a tax professional tells you otherwise.
Scenario B: You use DeFi bridges regularly, but weren't affected this time
Use this as the moment to get your DeFi transaction history and cost-basis records current, rather than after the next incident. Bridges concentrate risk in a way that a single exchange account often doesn't, since your funds pass through separate infrastructure with its own keys and contracts.
Scenario C: You hold staked crypto, like the B² Network users affected here
A staking-contract breach raises a slightly different question than a bridge hack: whether your staked tokens themselves were compromised, or only the contract's upgrade permissions. Our guide to how staking works covers the mechanics if you're trying to understand exactly what was and wasn't exposed in your specific case.
"A stolen coin doesn't stop being yours for tax purposes just because someone else has it now. Whether or not you end up able to deduct the loss, you still need to prove what you owned, when you lost access to it, and what happened afterward. That proof is what protects you later, regardless of which way the deduction question goes."
Luis Schilli, Head of Marketing at CoinTracking
Conclusion
The tax answer isn't a flat no: it depends on why you held the crypto, personal use or investment, not on a blanket rule. Four incidents, not three, drove the week's losses past $47 million, and the "$31.7 million" figure is AFX Trade and Verus combined, not one hack with a staking halt attached. Documentation is what you control either way: save your balances, cost basis, and the protocol's statements now, and you're ready whichever way the deduction question lands.
Keep your records ready for whatever comes next
CoinTracking has tracked crypto portfolios and calculated taxes for over 2.2 million users since 2012, across more than 400 exchanges and wallets. Import your history once, and you're ready the next time a bridge, exchange, or protocol has a bad week.
Disclaimer
The information in this article reflects publicly available reporting as of July 27, 2026. Wanchain has not published a final technical post-mortem for its bridge exploit as of this publish date, and dollar figures for several of these incidents may change as investigations continue and token prices move. This article is for general informational purposes only and does not constitute financial, tax, or legal advice. Tax treatment of stolen or hacked cryptocurrency depends on your individual circumstances and on current law, which can change. Readers should consult a qualified tax professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.