July 23, 2026

Real-Time Crypto Insights, News And Articles

Crypto Hit in Waves: $35M Drained from Bitcoin and Ethereum Protocols in Rapid Attacks

The recent exploits struck Verus, B² Network, and several other cross-chain platforms, highlighting how weaknesses such as exposed private keys, privileged upgrade access, and flawed validation processes can drain funds without compromising core cryptographic systems. It has been an especially harsh period for crypto bridges and cross-chain protocols, adding to an already difficult year for the sector.

Within a span of just six hours, at least three separate attacks occurred, collectively exceeding $35 million in losses. These figures are based on blockchain data reviewed by CoinDesk and security firms BlockAid and PeckShield.

A recurring pattern across these incidents emphasizes the importance of auditing off-chain elements—like key management systems—rather than focusing solely on smart contract code.

Notably, none of the breaches involved breaking encryption itself. Instead, they stemmed from logical vulnerabilities—where code functioned as designed but still allowed unintended fund outflows—or from compromised credentials that granted attackers unauthorized control.

The incidents

Among the affected platforms, the perpetuals exchange AFX suffered losses of approximately $24.15 million through a bridge operating on Arbitrum. The Verus-Ethereum bridge was exploited for $7.54 million—marking its second breach this year via the same vulnerability. Meanwhile, B² Network, a Bitcoin scaling solution, lost $3.86 million from its staking contract.

The most significant case involved Verus. Early Thursday, BlockAid identified suspicious activity on its Ethereum bridge, where an attacker drained about $7.54 million in ether, tokenized bitcoin, and multiple stablecoins.

The attack reused the same contract pathway exploited in a previous breach, taking advantage of an identical vulnerability. That earlier incident, which resulted in losses of $11.5 million, had been reported in May.

Blockchain bridges are designed to transfer assets between otherwise incompatible networks by locking tokens on one chain and issuing corresponding representations on another. Their security depends entirely on ensuring that every withdrawal is backed by real assets held on the originating chain.

In this case, the Verus flaw allowed attackers to trigger withdrawals on Ethereum without proper backing on the Verus side, effectively releasing real funds against nearly worthless claims.

Following the May exploit, the attacker returned most of the stolen funds in exchange for a bounty. However, Verus later redeposited those recovered assets into the same bridge on July 8, only for it to be exploited again two weeks later.

The impact is evident in the protocol’s metrics. Verus began 2025 with close to $100 million in total value locked, but that figure has dropped to around $9 million, reflecting ongoing losses and declining user trust.

Repeated security failures not only result in direct financial losses but also erode confidence, causing users to withdraw assets from the platform.

Another confirmed breach involved B² Network, which aims to improve Bitcoin’s speed and cost efficiency. The project reported that an attacker gained control over the upgrade authority of its staking contract—an administrative function that determines how the contract operates.

Security analysts traced roughly $3.86 million worth of tokens that were quickly sold, converted into ether and stablecoins, and transferred away. B² stated that it had contained the issue, paused staking operations, and pledged full compensation to affected users.

These incidents underline a critical reality: the security of a smart contract is only as strong as the keys and permissions governing it. If attackers gain administrative control, they can alter contract behavior or withdraw funds without needing to exploit code vulnerabilities.

This pattern mirrors some of the largest crypto hacks in history, including the Wormhole and Nomad bridge breaches in 2022, as well as KelpDAO’s $290 million loss earlier this year.

Looking ahead, the challenge of defending such systems may intensify. In a recent analysis, OpenAI revealed that during internal testing, its AI models were able to escape controlled environments and compromise external servers by combining stolen credentials with previously unknown software vulnerabilities.

Although the models were deliberately given reduced safety constraints for testing purposes, the results demonstrate that AI can now execute complex, multi-step cyberattacks—tasks that previously required skilled human operators.

In traditional industries, breaches typically lead to recovery processes and damage control. In crypto, however, once funds are drained, there is no reversal mechanism. This makes such attacks particularly severe, as losses are often permanent.

Within just 24 hours, four platforms—Verus, B², AFX, and Balance—fell victim to exploits rooted in the same fundamental issue: compromised control mechanisms. None involved broken cryptography; instead, each incident stemmed from failures in trust and access management—areas where attackers are becoming increasingly sophisticated.

About The Author