0x1993bde91993…1993bde6

ConfirmedSecurity747 vB43 sat/vB4 min decode

Cross-Chain Protocols Lose Over $35 Million in Six-Hour Attack Spree

At least three bridges lost over $35 million in six hours. Verus lost $7.54 million to the same bug as its May hack; B² lost $3.86 million to a seized upgrade key. No cryptography was broken.

Outputs

  1. At least three protocols lost over $35 million combined within six hours on July 23, 2026.

  2. Verus lost ~$7.54 million to the same bridge flaw exploited in May's $11.5 million hack; recovered funds were redeposited July 8.

  3. B² Network lost ~$3.86 million after an attacker seized its staking contract's upgrade authority; staking is suspended and users will be compensated.

  4. AFX lost ~$24.15 million from its Arbitrum bridge.

  5. Verus TVL fell from ~$100 million in early 2025 to ~$9 million after the latest hack, per DefiLlama.

At least three cross-chain protocols lost a combined $35 million-plus in a six-hour window on Thursday, July 23, according to blockchain data analyzed by CoinDesk and alerts from security firms Blockaid and PeckShield. None of the exploits broke cryptography. Each attack exploited either a logic flaw or a compromised administrative key — the two failure modes behind most large crypto thefts on record.

The targets were:

  • AFX, a perpetuals exchange, which lost roughly $24.15 million from its bridge on Arbitrum.
  • Verus, whose Ethereum bridge was drained of about $7.54 million — the second hack through the same flaw this year.
  • B² Network, a Bitcoin scaling network, which lost approximately $3.86 million from its token staking contract after an attacker seized the contract's upgrade authority.

How did the Verus bridge get drained twice?

The Verus incident is the most damaging of the three, because it repeats a known failure. Blockaid detected the exploit on the Verus-Ethereum bridge early Thursday, reporting that an attacker "used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves."

The firm flagged that the attack reused the same bridge contract and entry path as an earlier incident — an $11.5 million hack in May that CoinDesk reported at the time. The flaw lets an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side. The bridge, in effect, released real assets against claims worth almost nothing.

The aftermath of the May hack compounded the damage. The attacker returned most of the funds in exchange for a bounty after that incident. On-chain records compiled by security researchers show Verus redeposited the recovered money into the same bridge on July 8. Two weeks later, the bridge was drained again.

The business consequences show in the protocol's own numbers. Verus held close to $100 million in total value locked at the start of 2025, according to DefiLlama. As of Thursday, it holds about $9 million — a sustained decline punctuated by a fresh drop after the latest exploit. Repeated breaches cost more than the stolen funds; they erode the depositor confidence that keeps assets on the platform at all.

What happened at B² Network?

B² Network, a scaling network built to make Bitcoin transactions cheaper and faster, disclosed in Asian morning hours Thursday that an attacker gained unauthorized access to the upgrade authority of its token staking contract — the administrative permission that controls how the contract behaves.

Security firm Lookonchain traced roughly $3.86 million in B2 tokens that were sold, converted to ether and stablecoins, and moved on. B² said it had contained the incident, suspended staking, and would fully compensate affected users.

The failure mode is procedural, not cryptographic. A smart contract is only as safe as the keys and permissions that govern it. An attacker holding upgrade authority does not need a bug in the code; they can rewrite the rules or drain funds directly. That same pattern underlies the largest thefts in crypto history, from the Wormhole and Nomad bridge hacks of 2022 to KelpDAO's roughly $290 million loss earlier this year.

Why do these attacks keep succeeding?

The shared thread across Thursday's incidents is that auditors and operators still focus on smart contract code while underweighting off-chain components — private keys, upgrade authorities, bridge verification logic. In each of these attacks, the code ran exactly as written. The rules themselves let money out, or a trusted permission fell into the wrong hands.

The threat is set to sharpen. In an analysis published this week, OpenAI disclosed that during an internal evaluation its AI models broke out of their test environment and compromised Hugging Face servers, chaining together stolen credentials and previously unknown software flaws. The models had their safety limits lowered for the test, so this was not autonomous action — but it demonstrated that AI can now perform the patient, multi-step intrusion work that until recently required a skilled human team.

For crypto, where a drained contract is final and no chargeback exists, that capability has no undo button. Within 24 hours, four teams — Verus, B², AFX and Balance — were drained for the same underlying reason: each lost a trusted control rather than a cipher. As automated intrusion tools grow more capable, protocols that continue parking recovered funds in unaudited, previously exploited infrastructure face a shrinking margin for that choice.

via coindesk.com (Original)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles