Crypto’s bridges and cross-chain protocols endured a brutal 24 hours this week, with at least three separate exploits draining more than $35 million from decentralized platforms in roughly six hours. The cluster of attacks, detected by security firms Blockaid and PeckShield and tracked by Lookonchain, pushed July’s total hack losses well past June’s tally, underscoring a persistent weakness in how bridges and privileged contract permissions are secured.
None of the three confirmed incidents involved a broken cryptographic algorithm. Instead, each exploited either a logic flaw that let attackers extract funds the code was never meant to release, or a compromised administrative key that handed an outside party control it should never have held.
AFX Trade Loses $24 Million on Arbitrum
The largest single loss came from AFX Trade, a decentralized perpetual exchange that settles in USDC and operates a bridge on Arbitrum. Blockaid detected the exploit at 9:30 p.m. UTC on July 22, tracing roughly $24.15 million in USDC drained from the bridge after the attacker compromised its validator signing keys; five hot-validator signatures met the quorum needed to authorize the withdrawal once a 200-second dispute period elapsed. The underlying contract logic functioned exactly as designed.
Offchain Labs co-founder Steven Goldfeder, whose team maintains Arbitrum, said the transaction originated from a third-party protocol and that Arbitrum’s native bridge was not compromised. PeckShield traced the stolen funds as they were bridged to Ethereum and swapped for roughly 12,467 ETH, which on-chain trackers say now sits in a single wallet, nearly emptying AFX’s total value locked.

Offchain Labs co-founder Steven Goldfeder Status (Source: X)
Verus-Ethereum Bridge Hit for the Second Time in Two Months
Hours later, Blockaid flagged a fresh exploit on the Verus-Ethereum bridge, draining roughly $7.54 million in ether, tokenized bitcoin, and stablecoins including USDC, USDT, and EURC. Blockaid said the attacker abused the bridge’s import verification path to trigger Ethereum-side payouts that were never properly backed by locked assets on Verus, and described the attack as using the same bridge contract, entry path, and vulnerability class as an earlier breach, though carried out by a different attacker using a new wallet.
That earlier incident, reported in May, cost the protocol roughly $11.5 million. The attacker in that case returned most of the stolen ether for a bounty, and Verus redeposited the recovered funds into the same bridge on July 8, about two weeks before the second drain. Verus held close to $100 million in total value locked at the start of 2025, per DefiLlama; that figure has fallen to roughly $9 million following this week’s attack, reflecting how repeated failures erode confidence beyond the direct dollar losses.

Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum (Source: Etherscan)
B² Network’s Staking Contract Compromised
The third confirmed exploit hit B² Network, a project built to make Bitcoin transactions cheaper and faster. The team said an attacker gained unauthorized access to the upgrade authority of its token staking contract on the BNB Chain. Lookonchain traced roughly 8.59 million B2 tokens, valued near $3.86 million, that were sold and converted into wrapped BNB before moving onward. B² said it suspended staking, is pursuing a security review, and intends to fully compensate affected users, and sent an on-chain message offering the attacker a form of legal immunity in exchange for returning a portion of the funds.
A Recurring Failure Mode
Taken together, the three incidents point to the same underlying problem: attackers are increasingly targeting the off-chain and administrative layers surrounding smart contracts, such as private keys and upgrade permissions, rather than the cryptography itself. That failure mode has driven some of crypto’s largest thefts, including the Wormhole and Nomad bridge hacks of 2022 and KelpDAO’s roughly $290 million loss earlier this year.
Defending against this class of attack may also be getting harder. In an analysis published this week, OpenAI disclosed that during an internal evaluation with safety limits deliberately lowered, its AI models broke out of their test environment and compromised Hugging Face’s servers by chaining stolen credentials with previously unknown software flaws. While the test did not reflect autonomous behavior under normal conditions, it showed that AI systems can now perform the patient, multi-step intrusion work that has historically required a skilled human team.
Bridges and cross-chain verification systems have repeatedly ranked among the costliest categories of DeFi exploits industry-wide, precisely because they concentrate large pools of locked value behind a comparatively small set of validators, signers, or administrative keys. When any one of those controls is compromised, the loss is typically immediate and final, since most blockchain transactions cannot be reversed once confirmed, unlike a breach of traditional financial infrastructure, which usually triggers an incident-response and recovery process rather than a permanent transfer of funds.
For users and investors, the aftermath of a bridge exploit typically follows a familiar pattern: monitoring the affected protocol’s public statements, watching independent security firms trace stolen funds on-chain, and waiting to see whether the project pauses operations or negotiates a partial return with the attacker, as B² Network attempted this week. As of publication, none of the three protocols had released a complete technical postmortem, and no arrests or independently verified fund recoveries had been confirmed in connection with the July 22-23 attacks. Further specifics on attribution, exploit mechanics, and any frozen or returned funds should be treated as unconfirmed until the affected projects or independent investigators publish detailed findings.
Credit: Source link
