Home/News/Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart
BTCUSDETHUSD

Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart

CoinDeskPublished on 2 weeks ago

The attacks hit Verus, B² Network and other cross-chain systems, showing how compromised keys, upgrade powers and validation checks can empty protocols without breaking the underlying cryptography.

Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart

The attacks hit Verus, B² Network and other cross-chain systems, showing how compromised keys, upgrade powers and validation checks can empty protocols without breaking the underlying cryptography.

In a six-hour span, at least three crypto bridges and cross-chain protocols were drained of more than $35 million, exposing recurring weaknesses in how these systems are designed and governed. Verus’s Ethereum bridge was exploited for about $7.54 million using the same contract path and bug class as a May hack, underscoring how unresolved flaws and redeposited funds left the system vulnerable to a second drain. The B² Network lost roughly $3.86 million after an attacker seized its staking contract’s upgrade authority, highlighting how compromised keys and permissions — not broken cryptography — remain the primary cause of major crypto thefts as AI-driven intrusion tools grow more capable.

Crypto's bridges and cross-chain protocols are having a brutal day.

At least three were drained in quick succession in a 6-hour period for a combined total exceeding $35 million, according to blockchain data assessed by CoinDesk and reported by security firms BlockAid and Peckshield.

The run of attacks share a common thread. None broke the underlying cryptography — each was either a logic flaw, where the code ran as written but the rules still let money out, or a compromised key that handed an attacker control it should never have had.

The most damning was blockchain network Verus. Blockaid detected an exploit on the Verus-Ethereum bridge early Thursday that drained about $7.54 million in ether, tokenized bitcoin and a spread of stablecoins.

🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.More details in 🧵— Blockaid (@blockaid_) July 23, 2026

The firm flagged that the attack reused the same bridge contract and entry path as an earlier hack, exploiting an identical class of bug. CoinDesk reported that earlier incident, an $11.5 million loss, in May.

A bridge is a blockchain-based tool that lets assets move between two networks that otherwise cannot interact with each other. It holds real tokens on one side and issues claims against them on the other, and its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain.

The Verus flaw let an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side, so the bridge released real money against a claim worth almost nothing.

The attacker returned most of the funds in exchange for a bounty after the May attack. Verus then redeposited the recovered money into the same bridge on July 8, according to onchain records compiled by security researchers, and the bridge was drained again two weeks later.

The cost of that trust is visible in the protocol's own numbers. Verus held close to $100 million in total value locked at the start of 2025, according to DefiLlama. It holds about $9 million as of Thursday, a slow bleed punctuated by a fresh drop this week as the latest hack landed.

Such repeated failures do not just cost the money stolen in any single attack, but drain the confidence that keeps assets on the platform at all.

Another confirmed attack was B² Network, a scaling network built to make Bitcoin cheaper and faster to transact on.

B² said in Asian morning hours Thursday an attacker gained unauthorized access to the upgrade authority of its token staking contract, the administrative permission that controls how that contract behaves.

Security firm Lookonchain traced roughly $3.86 million in B2 tokens that were sold, converted to ether and stablecoins, and moved on. B² said it had contained the incident, suspended staking and would fully compensate affected users.

A smart contract is only as safe as the keys and permissions that control it. If an attacker seizes the authority to change how a contract works, the code does not need a bug, because the attacker can simply rewrite the rules or drain the funds directly.

This is the failure mode behind the largest thefts in crypto history, from the Wormhole and Nomad bridge hacks of 2022 to KelpDAO's roughly $290 million loss earlier this year.

And it is about to get harder to defend. In an analysis published this week, OpenAI disclosed that during an internal evaluation its AI models broke out of their test environment and compromised the servers of Hugging Face, chaining together stolen credentials and previously unknown software flaws to do it.

The models had their safety limits lowered for the test, so this was not a system acting on its own. But it was a concrete demonstration that AI can now perform the patient, multi-step intrusion work that until recently required a skilled human team.

In most industries a breach means incident response and, eventually, recovery. In crypto, where a drained contract is final and there is no chargeback, the same capability points at a threat with no undo button.

In a 24-hour period, four teams — Verus, B², AFX and Balance — were drained for the same underlying reason. None fell to a broken cipher. Each lost a trusted control, and the tools for finding those controls are only getting sharper.

1Arbitrum-based AFX Trade drained of $24 million after bridge keys compromised2 hours ago 2XRP whales accumulate as small holders capitulate 2 hours ago 3Bitcoin wilts as oil and rates rise. Clarity Act odds tumble to 38%3 hours ago 4Senator Lummis: Ethics, other provisions in crypto Clarity Act to be further discussed7 hours ago 5Key Democratic lawmakers say crypto Clarity Act 'falls short' on ethics, other issues8 hours ago 6Tesla holds bitcoin treasury steady, reports $112M impairment loss10 hours ago 7New draft of Clarity Act is out, and it would impose limits on Trump's crypto empire14 hours ago 8Revolut hits $115 billion valuation in employee share sale: WSJ15 hours ago 9SEC's Peirce warns some DeFi vaults, onchain lending may fall under securities laws15 hours ago 10UK digital bond plans hinge on one missing piece: onchain cash15 hours ago

Crypto Flows, Share and the Selective Rotation

Crypto Flows, Share and the Selective Rotation

Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.

Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.

Why it matters:

Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.

Arbitrum-based AFX Trade drained of $24 million after bridge keys compromised

Balance stablecoin collapses 99% after $1 million exploit drains its bitcoin vaults

Live updates: Bitcoin holds near $66,000 as stocks claw back from big early decline