📈 Get daily crypto insights that make you smarter about your money

Three Protocols Lost 35 Million in Six Hours — and the Real Threat to Your Staked Crypto Is Not What You Think

Three crypto protocols lost a combined 35 million dollars in just six hours this week — and the way it happened reveals a hard truth about the industry that every staker and delegator needs to understand before the next attack.

By Michael Nguyen | July 26, 2026

The Hardware and Software Landscape

On July 23, at least three cross-chain protocols were drained in rapid succession. The perpetuals exchange AFX Trade lost approximately 24 million dollars from a bridge it operates on Arbitrum. The Verus-Ethereum bridge was drained of about 7.5 million dollars. And B² Network, a Bitcoin scaling protocol, lost roughly 3.9 million dollars from its token staking contract.

What connects all three attacks is particularly sobering: none of them broke the cryptography. In every case, the code ran exactly as written — the problem was that the rules themselves allowed money to leave, or that someone gained control of keys and permissions they should never have had.

For anyone staking tokens, delegating to validators, or locking assets in bridges, this distinction matters enormously. The cryptographic foundations of blockchain remain sound. The weakness lies in the layers built on top — the smart contracts, administrative keys, and governance mechanisms that control how staked funds move.

Hashrate and Difficulty

The B² Network exploit is especially instructive for anyone involved in staking. According to security firms BlockAid and PeckShield, the attacker seized the staking contract’s upgrade authority — essentially gaining the master key that let them redirect staked funds.

Think of it like this: imagine you deposit money in a vault that requires two keys to open — yours and the bank manager’s. Now imagine someone manages to convince the system that they are the bank manager. They do not need to crack the vault. They just walk in with the right credentials and withdraw everything.

This is the dominant pattern in crypto theft today. According to data compiled by CoinDesk, compromised keys and administrative permissions — not broken cryptography — remain the primary cause of major losses. As AI-driven hacking tools grow more sophisticated, the risk of key compromise is increasing, not decreasing.

Profitability Metrics

The Verus bridge attack demonstrates a different but equally important failure mode. The bridge was drained through the same contract path and bug class that caused an earlier 11.5 million dollar hack in May. The flaw had not been fixed, and users who redeposited funds after the first attack lost everything again.

For stakers and liquidity providers, the lesson is brutal but clear: a protocol that has been hacked once is not safe just because it resumed operations. Until the underlying vulnerability is fully patched and independently audited, redepositing funds is a gamble. The Verus case shows what happens when that gamble goes wrong.

The AFX Trade exploit, the largest of the three at roughly 24 million dollars, involved a bridge running on Arbitrum. Security firm BlockAid detected the attack in real time, but the funds were already moving. Bridges remain the soft underbelly of the crypto ecosystem — they hold large pools of assets on one chain while issuing claims on another, making them rich targets for attackers.

Environmental Impact

While these attacks do not directly affect mining operations or energy consumption, they do have an indirect impact on the broader staking and validation ecosystem. When a staking contract is drained, trust in delegated proof-of-stake systems erodes. Users withdraw their staked assets, reducing the total value secured by the network and potentially affecting validator economics.

For Bitcoin miners and mining pools, the bridge attacks are a reminder that the crypto ecosystem’s security is only as strong as its weakest link. Bitcoin’s own network has never been compromised at the protocol level, but Bitcoin wrapped onto other chains — through bridges and tokenization protocols — is only as safe as the chain it sits on. The 3.9 million dollars lost from B² Network was Bitcoin scaling infrastructure, not Bitcoin itself, but it affects Bitcoin holders who use those scaling solutions.

Strategic Outlook

The cluster of attacks this week is not an isolated event. It is part of a punishing year for crypto security. Firms that build bridges, staking platforms, and cross-chain protocols are in an arms race with increasingly sophisticated attackers — and they are not always winning.

For investors who stake or delegate, the operational checklist is straightforward but often ignored:

  • Check audit history — has the protocol been audited by reputable firms? Were vulnerabilities found and fixed?
  • Understand upgrade mechanisms — who has the ability to change the staking contract? Is it a single key, a multisig, or a governance vote?
  • Diversify across protocols — never stake your entire holdings on a single platform, no matter how safe it seems
  • Be wary of recently-hacked protocols — if a platform was exploited recently, wait for evidence that the root cause was fully addressed before redepositing
  • Prefer simpler architectures — the more complex a bridge or staking system, the more attack surface it presents

The crypto industry’s fundamental promise — that you can be your own bank — only works if you take the operational security responsibilities seriously. The 35 million dollars lost in six hours this week is a reminder that the cost of getting that wrong is very real.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Three Protocols Lost 35 Million in Six Hours — and the Real Threat to Your Staked Crypto Is Not What You Think”

  1. access_control_void_

    none of the three attacks broke cryptography. the code ran exactly as written. auditing signature schemes while ignoring who can call withdraw is how you lose 35M in 6 hours

  2. bridge_hater_42

    AFX Trade losing 24M from a bridge on Arbitrum. same story every week. when will people stop parking liquidity on cross-chain bridges with 5M audit budgets guarding 100M TVL

    1. bridge_hater_42 parking 100M TVL behind a 5M audit budget is the cross-chain industry standard. bridges will keep getting drained until access control gets the same scrutiny as ZK proofs

    2. bridge_hater_42 parking 100M TVL behind a 5M audit budget is the cross-chain business model. bridges are the soft target of choice until access control gets taken seriously

      1. Exactly. These are not hacks, they are negligence dressed up as sophisticated attacks. Code ran as intended equals bad code.

    3. Access control keeps being the weakest link. Every single time its not the crypto being broken, its some admin key left lying around.

  3. rekt_auditor_

    AFX Trade losing 24M from a bridge on Arbitrum is wild. you would think after Wormhole and Nomad people would stop deploying bridges without proper access control reviews

  4. the article says none of them broke the cryptography. the code ran exactly as written. thats the scariest part because it means audits wouldnt have caught it either

    1. ^ exactly. the Verus bridge wasnt even hacked in the traditional sense. the protocol logic itself was the vulnerability. rekt by design

  5. the quote about none of them breaking cryptography is the scariest part. the math held up perfectly, the code just did what someone wrote. we keep auditing the wrong things

    1. exactly. everyone obsesses over zero knowledge proofs and signature schemes but your 24M disappears because someone forgot to check who can call withdraw()

      1. logic_flaw_ exactly. everyone audits signature schemes and ZK proofs while ignoring who can call withdraw(). AFX lost 24M to a permission gap not a crypto flaw

  6. 35M in 6 hours and nobody in the article mentioned circuit breakers. CEXes have had trading halts for decades. DeFi still refuses to learn

    1. mev_sweep_ circuit breakers in DeFi are hard because every chain is sovereign. CEX halts work because one entity controls the matching engine. on-chain youd need every validator to agree which defeats the point

      1. sovereign chains make global halts impossible but individual protocols can still gate withdrawals. a 6 hour delay on unusual bridge volume would have saved verus 7.5M, nobody wants the UX hit though

    2. 24M from AFX Trade alone is insane. Where were the circuit breakers? Oh wait, DeFi does not believe in safety nets.

  7. staked_and_burned

    B squared Network losing 3.9M from staking is painful. been telling people to check the withdrawal flow before staking on any BTC L2. nobody listens until the money is gone

  8. bridge_hopper_

    AFX Trade losing 24M from their Arbitrum bridge while Verus lost 7.5M and B2 Network 3.9M. three bridges drained in six hours means attackers are scanning bridge contracts in batches now

  9. the article says none of them broke cryptography but every bridge uses different verification logic. AFX was a canonical bridge with a multisig override. thats not a bridge problem thats a governance problem

    1. cross_chain_autopsy

      Tobias K. exactly. canonical bridges with multisig admins are just hot wallets with extra steps. the real cross chain security comes from optimistic verification or ZK light clients not admin keys

  10. access_control_rat_

    the quote about none of them breaking cryptography is the whole problem. the math held up, the access control logic did not. we keep auditing the wrong layer

    1. access_control_rat_ the industry keeps hiring auditors to check the math while the actual exploits come from permission logic. its like checking the locks on the front door while the back window is open

  11. B2 Network losing 3.9M from a Bitcoin L2 staking contract is the kind of thing that kills the BTCFi narrative. BTC holders already skeptical of smart contracts and this confirms their bias

  12. Six hours, three protocols, one common thread: fresh upgrades. Two of those three contracts had been modified within days of the drains. Freeze withdrawals for 24 hours after every upgrade and most of this attack class dies.

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,769.00-0.8%ETH$2,484.65-1.9%SOL$99.85-2.2%BNB$716.07-2.6%XRP$1.34-1.9%ADA$0.2050-1.8%DOGE$0.0836-1.7%DOT$1.01-3.4%AVAX$7.34-1.6%LINK$11.36-1.6%UNI$6.22-2.3%ATOM$1.58-3.6%LTC$53.73-0.7%ARB$0.1376-3.8%NEAR$2.31-2.8%FIL$0.8137+0.3%SUI$0.7123-2.1%BTC$76,769.00-0.8%ETH$2,484.65-1.9%SOL$99.85-2.2%BNB$716.07-2.6%XRP$1.34-1.9%ADA$0.2050-1.8%DOGE$0.0836-1.7%DOT$1.01-3.4%AVAX$7.34-1.6%LINK$11.36-1.6%UNI$6.22-2.3%ATOM$1.58-3.6%LTC$53.73-0.7%ARB$0.1376-3.8%NEAR$2.31-2.8%FIL$0.8137+0.3%SUI$0.7123-2.1%
Scroll to Top