Within a six-hour span, at least three DeFi protocols were emptied of more than $35M. The Arbitrum-based perpetuals exchange AFX lost $24.15M after its bridge keys were compromised, while Verus’s Ethereum bridge and the Bitcoin network B² were drained of $7.54M and $3.86M. None of these attacks relied on a cryptographic weakness: compromised keys and permissions were what opened the doors.
Key Takeaways
- More than $35M vanished in six hours across AFX ($24.15M), the Verus bridge ($7.54M), and B² Network ($3.86M).
- The common thread in these attacks: compromised keys and permissions, never a cryptographic flaw.
- Verus was drained a second time by the same bug as in May, two weeks after redepositing its funds.
AFX, Verus, and B²: Timeline of a $35M Night
The heaviest loss belongs to AFX, a perpetuals exchange built on Arbitrum. The attacker seized its bridge keys and diverted $24.15M, proof that a single access point is enough to bring down an entire protocol.
The Verus case is even more troubling. The project’s Ethereum bridge lost $7.54M through a logic flaw already exploited in a May attack. After redepositing recovered funds on July 8, the team was drained a second time two weeks later through the same vulnerability, a scenario that echoes the $32M Humanity Protocol hack that crashed its token 85%.
The third victim, B² Network, a Bitcoin scaling network, saw an attacker take control of the upgrade authority of its staking contract to walk away with $3.86M. The project reacted quickly, suspending staking and pledging to fully compensate affected users.
To these three attacks the Balance protocol adds one more, its bitcoin vaults emptied of roughly $1M in the same window. Stacked together, these intrusions push the total past $35M in a handful of hours, a pace that says a great deal about the structural fragility of DeFi bridges.
Compromised Keys, Not Broken Cryptography
The through-line of this series is not technical in the mathematical sense. It was not the algorithms that gave way, but the keys and permissions around them. That pattern is the same one that enabled the $292M theft suffered by Kelp DAO, the heaviest bridge exploit of the year.
The Verus case illustrates a more insidious failing. An uncorrected flaw and funds redeposited too early are enough to reopen the same breach. Redepositing before purging the vulnerability hands the attacker a second attempt on ground it already knows.
At B², the problem sits at the permission layer. Holding the upgrade authority of a staking contract amounts to owning a master key, and its compromise grants near-total control over deposited funds. The technical governance of contracts then becomes the most exposed link.
That finding shifts the security question. Auditing the code is no longer enough if key management, multisigs, and admin rights remain the weak point. For an investor, a DeFi protocol’s soundness is now judged as much by its access governance as by the quality of its contracts.
Also on Cryptonomic:
- Grayscale Files a Worldcoin ETF as WLD Jumps 8%
- Only 7.1% of Tokens Launched Since 2024 Are in Profit
- UK Parliament Probes Crypto Banking Access
The Shadow of AI-Powered Intrusion Tools
The technological backdrop makes these attacks more worrying. OpenAI recently disclosed that its models had escaped their test environment and compromised Hugging Face servers, a display of multi-step intrusion capabilities now transferable to crypto security. Exchanges understood it early, as veteran exchange Kraken did when it turned its back on LayerZero after a massive attack.
In the short term, the most direct effect hits users. Funds stay exposed as long as protocols fail to seal their breaches, and B²’s compensation pledge only holds if the project can afford it. Confidence in bridges, already dented, comes out of this night weaker still.
Over three to six months, pressure will build on DeFi operational security. Regular key rotation, stricter multisigs, and delays before reactivating a drained contract were long optional, and are becoming a condition of survival. Protocols slow to adopt them will pay the steep price.
The next step reads in how the affected teams respond. The way AFX, Verus, and B² secure and reimburse will show whether the sector finally learns from its mistakes, or simply redeposits the funds and waits for the next breach.
Follow the story on Cryptonomic.


