
At least three crypto bridges and cross-chain protocols were drained of more than $35.5 million in a six-hour period on July 23, marking what has been dubbed 'Hackers' Day' by the crypto industry. The attacks occurred within a 24-hour period, with four teams - Verus, B² Network, AFX and Balance - all falling victim to the same underlying security failures. As reported by multiple security firms, none of the attacks broke the underlying cryptography - each was either a logic flaw or compromised key that handed attackers control they should never have had. According to industry analysis, the market is already calling it the worst day for DeFi in months, bringing back memories of earlier hack-driven selloffs.
BlockAid detected an exploit on the Verus-Ethereum bridge that drained approximately $7.54 million in ether, tokenized bitcoin and stablecoins. According to CoinDesk, the attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining funds from bridge reserves. The firm flagged that the attack reused the same bridge contract and entry path as an earlier hack, exploiting an identical class of bug. Earlier incident reports from CoinDesk documented an $11.5 million loss in May, with the attacker returning most funds in exchange for a bounty after the May attack. The Verus bridge currently holds about $9 million in total value locked, representing a significant decline from its previous $100 million holdings at the start of 2025.
B² Network, a scaling network built to make Bitcoin cheaper and faster to transact on, confirmed that an attacker gained unauthorized access to the upgrade authority of its token staking contract. Security firm Lookonchain traced roughly $3.86 million in B² tokens that were sold, converted to ether and stablecoins, and moved on. As reported by CoinDesk, B² said it had contained the incident, suspended staking and would fully compensate affected users. The breach demonstrates how compromised keys and permissions - not broken cryptography - remain the primary cause of major crypto thefts. Current investigations are ongoing as the industry works to understand the full scope of the compromise.
On July 22, AFX's third-party cross-chain bridge was exploited, resulting in a loss of $24.15 million USDC. According to recent reports, the attacker moved the stolen stablecoins from Arbitrum to Ethereum and converted them into approximately 12,467 ETH. The breach did not affect the underlying AFX protocol, demonstrating how third-party bridge integrations can create additional security vulnerabilities. As reported by CoinDesk, the attacker is currently negotiating with the platform, with the incident highlighting how cross-chain bridges remain attractive targets for sophisticated attackers who can exploit integration points between different blockchain networks.
The attacks highlight recurring weaknesses in how crypto bridges and cross-chain protocols are designed and governed, with security experts emphasizing that security is not a challenge unique to any single protocol, platform or architecture - it is a responsibility shared across the entire crypto industry. According to industry analysis, the incidents demonstrate how security must evolve alongside innovation as the industry's infrastructure becomes increasingly interconnected. The breaches occurred in cross-chain bridges and supporting infrastructure rather than the underlying blockchains themselves, highlighting the growing importance of infrastructure resilience, protection mechanisms, and user confidence through transparency. As reported by AMBCrypto, these exploits come at a particularly challenging time as DeFi TVL had finally started recovering, with $10 billion in monthly growth in July marking the strongest increase since the Q1-Q2 hack wave.