Three protocols lost over $35 million in a single six-hour window on July 22-23, 2026. The detail that matters most is not the dollar figure: in none of the three attacks was cryptography broken. The mathematical code securing these blockchains worked exactly as designed.
What failed was everything built on top of it. That's a lesson the crypto sector keeps refusing to absorb, because it's far less comforting than a simple technical bug.
What Happened Across Three Attacks
Three apparently unconnected exploits struck in rapid succession overnight on July 22-23. The largest hit AFX, a decentralized derivatives platform on Arbitrum, for approximately $24.15 million, according to data from Lookonchain. Hours later, the Verus-to-Ethereum bridge was drained of roughly $7.54 million in ETH, tokenized bitcoin, and several stablecoins. B² Network followed, losing around $3.86 million.
Three Attacks, Six Hours, $35 Million
Estimated losses per protocol, July 22-23, 2026. Source: Blockaid, Lookonchain
Estimated total: approximately $35.55 million drained in a single six-hour window.
The Verus Case: The Same Door, Opened Twice
The hardest detail involves Verus, and it deserves a clear explanation. A bridge is a tool that moves value between two blockchains that can't communicate natively: it locks real tokens on one side and issues corresponding claims on the other. Its entire security rests on one verification: that every withdrawal on one side genuinely corresponds to funds locked on the other.
Verus — Ethereum Bridge Suffers Second Exploit in Two Months, $7.54M Drained
, Wu Blockchain (@WuBlockchain) July 23, 2026
Blockaid detected a new exploit targeting the Verus, Ethereum Bridge, with an attacker abusing the bridge's import path to trigger unbacked Ethereum-side payouts and drain approximately $7.54 million in… pic.twitter.com/eNGo8EILT7
In the Verus attack, the attacker abused the bridge's import path to trigger Ethereum-side payouts that had no backing on the Verus side. The bridge released real money against a claim that didn't exist. The real point, though, is this: according to Blockaid, the security firm that detected the attack, it was the same contract, the same entry point, and the same class of bug already exploited in a May attack that cost roughly $11.58 million. Two months later, that same door was still open.
What Broke, and What Didn't
Here's the uncomfortable truth the sector struggles to admit. None of these attacks broke cryptography. In the B² Network case, the attacker gained control of the staking contract's upgrade permissions. Nothing was forced. The attacker simply had the right keys. In the other cases, the code executed exactly what it was asked to do. The problem was that the logic allowed requests that should never have been possible.
The Weak Point Isn't the Math
Where crypto systems actually break
- Held: the cryptography. Not breached in any of the three incidents.
- Failed: verification logic, which allowed uncovered withdrawals to pass through.
- Failed: key management and admin permission controls.
- Failed: governance, which left a known two-month-old vulnerability unpatched.
This is the same pattern seen in the recent Cardano wallet incident: the chain itself wasn't compromised, the flaw lived in the software running on top of it. The industry keeps selling “blockchain” as a synonym for security, but blockchain only protects the layer it directly touches. Everything above it, bridges, upgradeable contracts, admin wallets, is ordinary software written by ordinary people, with permissions managed by ordinary people.
The New Variable: Automated Attacks
There's an element here that makes the picture more serious than a run of bad luck. Analysts tracking these incidents note that compromised keys and poorly managed permissions remain the leading cause of major crypto thefts, and that AI-assisted intrusion tooling is becoming measurably more capable.
What that means in practice: automated scanning of contract code for known vulnerability patterns now costs far less than it did a year ago. When a public flaw stays open for months, as it did with Verus, time no longer favors the defender. Three attacks in six hours across different protocols may be coincidence. They're also a snapshot of an ecosystem where finding the wrong door has become much faster than fixing it.
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
, Blockaid (@blockaid_) July 23, 2026
An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
More details in 🧵
The Wider Lesson for Investors and Builders
Anyone investing or building in this space should draw a practical, if unglamorous, conclusion. Bridges remain the most fragile point in the entire ecosystem. They concentrate large pools of funds, and their security rests on verification logic that, when even slightly wrong, opens a tap. Before parking value on any protocol that connects different chains, it's worth asking: who controls the upgrade permissions, does a recent independent audit exist, and have past vulnerabilities actually been closed or just patched over.
The real story here isn't that someone stole $35 million. It's that doing so required no cryptographic breakthrough whatsoever. It was enough to find a door that someone had left open two months ago and simply forgotten about. For anyone wanting to understand the fundamentals of how blockchains work and how to hold crypto securely, those questions are more relevant today than they've ever been.
