Three cross-chain bridges were drained of more than 35 million USD in a single six-hour window last week, exposing the same weakness that has plagued decentralized finance for years: the connections between blockchains remain the most dangerous links in the entire crypto ecosystem.
By Priya Sharma | July 26, 2026
The Hook: Three Hacks, Six Hours, 35 Million USD Gone
In a brutal six-hour stretch on July 23, at least three crypto bridges and cross-chain protocols were exploited in rapid succession. The combined damage exceeded 35 million USD, according to blockchain data analyzed by CoinDesk and reported by security firms BlockAid and PeckShield.
The three attacks targeted:
- AFX Trade — a perpetuals exchange that lost approximately 24 million USD from its Arbitrum bridge after an attacker compromised the bridge’s keys
- Verus — a blockchain network whose Ethereum bridge was drained of about 7.5 million USD in ether, tokenized bitcoin, and stablecoins. This was the SECOND time the same bridge was hacked through the same flaw in 2026
- B2 Network — a Bitcoin scaling network that lost roughly 3.9 million USD after an attacker seized control of its staking contract’s upgrade authority
What ties these attacks together is a disturbing common thread: none of them broke the underlying cryptography. Each exploit was either a logic flaw — where the code worked exactly as written, but the rules still let money walk out the door — or a compromised private key that gave an attacker control they should never have had.
On-Chain Evidence: The Verus Double-Hack Is the Most Damning
The most troubling of the three attacks is Verus. Blockaid detected the exploit on the Verus-Ethereum bridge early on July 23, when an attacker used the bridge’s import path to trigger unbacked Ethereum-side payouts — essentially creating money out of thin air on one side without properly locking assets on the other.
Here’s what makes it worse: the same bridge was already hacked in May for about 11.5 million USD through the same class of bug. After that first attack, the hacker returned most of the funds in exchange for a bounty. Verus then redeposited the recovered money back into the same bridge contract on July 8. Two weeks later, it was drained again.
The numbers tell the story of a protocol in terminal decline. Verus held close to 100 million USD in total value locked at the start of 2025. After these repeated failures, that figure has collapsed to approximately 9 million USD — a slow bleed punctuated by fresh drops each time a new hack lands.
The Core Conflict: Bridges Are the Weakest Link in DeFi
A bridge is a blockchain-based tool that enables assets to move between two networks that otherwise cannot interact — like a tunnel connecting two islands. It holds real tokens on one side and issues claims against them on the other. Its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain.
The problem is that bridges concentrate risk. Instead of spreading assets across many independent systems, they pool large amounts of value into a single smart contract and a small set of administrative keys. That creates a honeypot — a juicy target that attracts the most sophisticated attackers in the space.
The B2 Network exploit illustrates this perfectly. The attacker didn’t need to crack any encryption. They simply seized the staking contract’s upgrade authority — the administrative keys that allow developers to modify the contract’s code. Once they had those keys, they could rewrite the rules and drain the funds at will. This is the crypto equivalent of stealing the manager’s key to the bank vault.
Security researchers note that as AI-driven intrusion tools grow more capable, compromised keys and permissions — not broken cryptography — remain the primary cause of major crypto thefts. The code itself is often fine. The humans managing it are the vulnerability.
Market Implications: What This Means for Your DeFi Portfolio
If you use DeFi protocols — lending platforms, staking services, yield aggregators, or anything that involves bridges — these attacks carry three practical lessons.
First, check the audit history. A protocol that has been audited by reputable security firms is safer than one that hasn’t. But audits are not guarantees — Verus was presumably audited, and it was still hacked twice through the same flaw. Treat audits as a minimum baseline, not a seal of approval.
Second, watch for repeated failures. When a protocol gets hacked once, it’s unfortunate. When it gets hacked twice through the same vulnerability, it’s a pattern. If you have funds in a protocol that has been hacked and the team has not clearly explained how they fixed the root cause, get your money out.
Third, understand what you’re actually using. Many DeFi users don’t realize their funds are flowing through a bridge. If you’re moving assets between Ethereum and Arbitrum, or between Bitcoin and a layer-2 network, you’re using a bridge. Every bridge crossing adds risk. The fewer bridges you cross, the lower your exposure.
The Verdict: DeFi’s Bridge Problem Needs More Than Better Code
The 35 million USD lost in six hours is not a freak event. It’s a structural problem. Bridges concentrate value and rely on administrative keys that can be stolen, leaked, or socially engineered. No amount of smart contract auditing can fully eliminate the human element from key management.
The industry is slowly moving toward solutions — multi-signature wallets, time-locked upgrades, and decentralized validator sets that make it harder for a single compromised key to cause catastrophe. But adoption is slow, and attackers move faster than governance processes.
For now, the best defense is diversification and caution. Don’t put all your assets in a single bridge or protocol. Don’t chase the highest yields on the newest platforms. And if a protocol you use gets hacked, don’t wait to see if they’ll fix it — the Verus example shows that “fixed” bridges can be drained again two weeks later.
DeFi promised to eliminate the need for trusted intermediaries. But as long as bridges remain the soft underbelly of the ecosystem, trust is still very much part of the equation — you’re just trusting different people, with less oversight and no insurance.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
nnnDisclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry inherent risks.
n
35 million in six hours across THREE bridges and people still send funds through these things. the bridge design pattern is fundamentally broken and nobody wants to admit it
bridge_body_count the bridge design pattern being fundamentally broken is the uncomfortable truth. 35M in 6 hours and TVL still flows through them
AFX Trade losing 24M from an Arbitrum bridge is wild. youd think after Wormhole and Nomad people would stop deploying the same multisig pattern
35M in 6 hours across 3 protocols is coordinated imo. same exploiters probing multiple bridges at once, not a coincidence
PeckShield caught two of these before the teams even knew. security firms doing gods work but protocols need to actually read the reports
Berkant Y. coordinated assumes skill. more likely one crew found a multisig phishing flow that worked and just ran it three times before breakfast
AFX Trade losing 24M on an Arbitrum bridge is wild. youd think a perps exchange would know better than to park treasury in a bridge contract
bridges are where the money goes to die. staggering how much TVL still sits on infrastructure from 2022 with no upgrade
Verus bridge hacked twice in the same year through the same flaw. at that point its not a bug, its a feature nobody bothered fixing
multisig_grave_ exactly. the first hack is understandable. the second time through the same vector is pure negligence from the team
hacked twice through the same flaw and people still bridged after the first one. that second hack was announced in advance basically
three bridges drained in six hours using the same multisig compromise pattern. at what point does the industry admit the bridge design itself is the vulnerability
35M in six hours across three bridges and the common thread is multisig signer compromise. when will people learn that 3-of-5 with humans holding keys is just a slower single point of failure
none of the three exploits broke cryptography. all keys and upgrade authority. bridge security is a human problem pretending to be a tech problem
relay_collapse_ yep. zero broken cryptography, three drained bridges. ZK light client verification or admit bridges are just custodians with extra steps
light clients fix the proof side but AFX lost keys, not a bad proof. ZK bridges still route through a multisig somewhere and thats exactly where the 24M walked out
AFX Trade parking 24M of treasury in a bridge contract is the kind of treasury management failure that should trigger immediate board resignations
Min-jun C. AFX Trade as a perps exchange should have understood counterparty risk. parking 24M in a bridge contract is a fundamental treasury failure
Min-jun C. a perps exchange should know counterparty risk better than anyone. parking treasury in a bridge means nobody on their risk team understood bridge architecture
Three bridges in six hours and each writeup treats them like isolated incidents. The common thread is signers behind a handful of keys that nobody rotates. Fix key management or keep donating to hackers.
the piece buries that AFX Trade alone was 24M of the 35M. one treasury decision was the whole story, the other two bridges were footnotes
footnotes is generous for verus, that bridge got drained a second time through the same flaw. getting hacked twice through identical code deserves its own post mortem
three signer compromises inside six hours reads like one crew shopping the same multisig weakness across protocols. AFX just had the deepest pocket
Teodora M. three multisig compromises in six hours reads as one crew shopping the same playbook. AFX losing 24M as a repeat victim is the part regulators should circle