Jul 23, 2026, 6:38 a.m.

3 min read

Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart. (Mika Baumeister/Unsplash)
Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart. (Mika Baumeister/Unsplash)

Summary

  • In a six-hour span, at least three crypto bridges and cross-chain protocols were drained of more than $35 million, exposing recurring weaknesses in how these systems are designed and governed.
  • Verus’s Ethereum bridge was exploited for about $7.54 million using the same contract path and bug class as a May hack, underscoring how unresolved flaws and redeposited funds left the system vulnerable to a second drain.
  • The B² Network lost roughly $3.86 million after an attacker seized its staking contract’s upgrade authority, highlighting how compromised keys and permissions — not broken cryptography — remain the primary cause of major crypto thefts as AI-driven intrusion tools grow more capable.

Crypto's bridges and cross-chain protocols are having a brutal day.

At least three were drained in quick succession in a 6-hour period for a combined total exceeding $35 million, according to blockchain data assessed by CoinDesk and reported by security firms BlockAid and Peckshield.

The run of attacks share a common thread. None broke the underlying cryptography — each was either a logic flaw, where the code ran as written but the rules still let money out, or a compromised key that handed an attacker control it should never have had.

The most damning was blockchain network Verus. Blockaid detected an exploit on the Verus-Ethereum bridge early Thursday that drained about $7.54 million in ether, tokenized bitcoin and a spread of stablecoins.

🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
More details in 🧵

— Blockaid (@blockaid_) July 23, 2026

The firm flagged that the attack reused the same bridge contract and entry path as an earlier hack, exploiting an identical class of bug. CoinDesk reported that earlier incident, an $11.5 million loss, in May.

A bridge is a blockchain-based tool that lets assets move between two networks that otherwise cannot interact with each other. It holds real tokens on one side and issues claims against them on the other, and its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain.

The Verus flaw let an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side, so the bridge released real money against a claim worth almost nothing.

The attacker returned most of the funds in exchange for a bounty after the May attack. Verus then redeposited the recovered money into the same bridge on July 8, according to onchain records compiled by security researchers, and the bridge was drained again two weeks later.

The cost of that trust is visible in the protocol's own numbers. Verus held close to $100 million in total value locked at the start of 2025, according to DefiLlama. It holds about $9 million as of Thursday, a slow bleed punctuated by a fresh drop this week as the latest hack landed.

(Shaurya Malwa/CoinDesk)
(Shaurya Malwa/CoinDesk)

Such repeated failures do not just cost the money stolen in any single attack, but drain the confidence that keeps assets on the platform at all.

Another confirmed attack was B² Network, a scaling network built to make Bitcoin cheaper and faster to transact on.

B² said in Asian morning hours Thursday an attacker gained unauthorized access to the upgrade authority of its token staking contract, the administrative permission that controls how that contract behaves.

Security firm Lookonchain traced roughly $3.86 million in B2 tokens that were sold, converted to ether and stablecoins, and moved on. B² said it had contained the incident, suspended staking and would fully compensate affected users.

A smart contract is only as safe as the keys and permissions that control it. If an attacker seizes the authority to change how a contract works, the code does not need a bug, because the attacker can simply rewrite the rules or drain the funds directly.

This is the failure mode behind the largest thefts in crypto history, from the Wormhole and Nomad bridge hacks of 2022 to KelpDAO's roughly $290 million loss earlier this year.

(Shaurya Malwa/CoinDesk)
(Shaurya Malwa/CoinDesk)

And it is about to get harder to defend. In an analysis published this week, OpenAI disclosed that during an internal evaluation its AI models broke out of their test environment and compromised the servers of Hugging Face, chaining together stolen credentials and previously unknown software flaws to do it.

The models had their safety limits lowered for the test, so this was not a system acting on its own. But it was a concrete demonstration that AI can now perform the patient, multi-step intrusion work that until recently required a skilled human team.

In most industries a breach means incident response and, eventually, recovery. In crypto, where a drained contract is final and there is no chargeback, the same capability points at a threat with no undo button.

In a 24-hour period, four teams — Verus, B², AFX and Balance — were drained for the same underlying reason. None fell to a broken cipher. Each lost a trusted control, and the tools for finding those controls are only getting sharper.

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10

Crypto Flows, Share and the Selective Rotation

Market Spotlight Square Image

Crypto Flows, Share and the Selective Rotation

Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.

16 hours ago

Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.

Why it matters:

Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.

View Full Report

Read full story at CoinDesk