{"id":24372,"date":"2026-07-24T01:58:42","date_gmt":"2026-07-24T01:58:42","guid":{"rendered":"https:\/\/nft.runfyers.com\/index.php\/2026\/07\/24\/bitcoin-ethereum-linked-protocols-lose-35-million-in-coordinated-attacks-within-hours-nft-plazas\/"},"modified":"2026-07-24T01:58:42","modified_gmt":"2026-07-24T01:58:42","slug":"bitcoin-ethereum-linked-protocols-lose-35-million-in-coordinated-attacks-within-hours-nft-plazas","status":"publish","type":"post","link":"https:\/\/nft.runfyers.com\/index.php\/2026\/07\/24\/bitcoin-ethereum-linked-protocols-lose-35-million-in-coordinated-attacks-within-hours-nft-plazas\/","title":{"rendered":"Bitcoin, Ethereum-Linked Protocols Lose $35 Million in Coordinated Attacks Within Hours &#8211; NFT Plazas"},"content":{"rendered":"<p><\/p>\n<div>\n<p><span style=\"font-weight: 400;\">Crypto\u2019s bridges and cross-chain protocols endured a brutal 24 hours this week, with at least three separate exploits draining more than $35 million from decentralized platforms in roughly six hours. The cluster of attacks, detected by security firms Blockaid and PeckShield and tracked by Lookonchain, pushed July\u2019s total hack losses well past June\u2019s tally, underscoring a persistent weakness in how bridges and privileged contract permissions are secured.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">None of the three confirmed incidents involved a broken cryptographic algorithm. Instead, each exploited either a logic flaw that let attackers extract funds the code was never meant to release, or a compromised administrative key that handed an outside party control it should never have held.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"AFX_Trade_Loses_24_Million_on_Arbitrum\"\/><span style=\"font-weight: 400;\">AFX Trade Loses $24 Million on Arbitrum<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">The largest single loss came from AFX Trade, a decentralized perpetual exchange that settles in USDC and operates a bridge on Arbitrum. Blockaid detected the exploit at 9:30 p.m. UTC on July 22, tracing roughly $24.15 million in USDC drained from the bridge after the attacker compromised its validator signing keys; five hot-validator signatures met the quorum needed to authorize the withdrawal once a 200-second dispute period elapsed. The underlying contract logic functioned exactly as designed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Offchain Labs co-founder Steven Goldfeder, whose team maintains Arbitrum, said the transaction originated from a third-party protocol and that Arbitrum\u2019s native bridge was not compromised. <\/span><a href=\"https:\/\/x.com\/PeckShieldAlert\/status\/2080088731558801909\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><span style=\"font-weight: 400;\">PeckShield traced<\/span><\/a><span style=\"font-weight: 400;\"> the stolen funds as they were bridged to Ethereum and swapped for roughly 12,467 ETH, which on-chain trackers say now sits in a single wallet, nearly emptying AFX\u2019s total value locked.<\/span><\/p>\n<p><noscript><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload aligncenter wp-image-98392 size-large\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/07\/2-12-e1784858200143-1024x502.jpg\" alt=\"Offchain Labs co-founder Steven Goldfeder Status (Source: X)\" width=\"1024\" height=\"502\"\/><\/p>\n<p style=\"text-align: center;\"><i><span style=\"font-weight: 400;\">Offchain Labs co-founder Steven Goldfeder Status (Source: <\/span><\/i><a href=\"https:\/\/x.com\/sgoldfed\/status\/2080071210847674709\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><i><span style=\"font-weight: 400;\">X<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">)<\/span><\/i><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Verus-Ethereum_Bridge_Hit_for_the_Second_Time_in_Two_Months\"\/><span style=\"font-weight: 400;\">Verus-Ethereum Bridge Hit for the Second Time in Two Months<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">Hours later, Blockaid flagged a fresh exploit on the Verus-Ethereum bridge, draining roughly $7.54 million in ether, tokenized bitcoin, and stablecoins including USDC, USDT, and EURC. Blockaid said the attacker abused the bridge\u2019s import verification path to trigger Ethereum-side payouts that were never properly backed by locked assets on Verus, and described the attack as using the same bridge contract, entry path, and vulnerability class as an earlier breach, though carried out by a different attacker using a new wallet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That earlier incident, reported in May, cost the protocol roughly $11.5 million. The attacker in that case returned most of the stolen ether for a bounty, and Verus redeposited the recovered funds into the same bridge on July 8, about two weeks before the second drain. Verus held close to $100 million in total value locked at the start of 2025, per <\/span><a href=\"https:\/\/defillama.com\/chain\/verus\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><span style=\"font-weight: 400;\">DefiLlama<\/span><\/a><span style=\"font-weight: 400;\">; that figure has fallen to roughly $9 million following this week\u2019s attack, reflecting how repeated failures erode confidence beyond the direct dollar losses.<\/span><\/p>\n<p><noscript><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-98391\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/07\/3-8-1024x576.png\" alt=\"Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum (Source: Etherscan)\" width=\"1024\" height=\"576\"\/><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload size-large wp-image-98391\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/07\/3-8-1024x576.png\" alt=\"Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum (Source: Etherscan)\" width=\"1024\" height=\"576\"\/><\/p>\n<p style=\"text-align: center;\"><i><span style=\"font-weight: 400;\">Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum (Source: <\/span><\/i><a href=\"https:\/\/etherscan.io\/tx\/0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><i><span style=\"font-weight: 400;\">Etherscan<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">)<\/span><\/i><\/p>\n<h2><span class=\"ez-toc-section\" id=\"B%C2%B2_Networks_Staking_Contract_Compromised\"\/><span style=\"font-weight: 400;\">B\u00b2 Network\u2019s Staking Contract Compromised<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">The third confirmed exploit hit <\/span><a href=\"https:\/\/x.com\/BSquaredNetwork\/status\/2080077286238454109\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><span style=\"font-weight: 400;\">B\u00b2 Network<\/span><\/a><span style=\"font-weight: 400;\">, a project built to make Bitcoin transactions cheaper and faster. The team said an attacker gained unauthorized access to the upgrade authority of its token staking contract on the BNB Chain. Lookonchain traced roughly 8.59 million B2 tokens, valued near $3.86 million, that were sold and converted into wrapped BNB before moving onward. B\u00b2 said it suspended staking, is pursuing a security review, and intends to fully compensate affected users, and sent an on-chain message offering the attacker a form of legal immunity in exchange for returning a portion of the funds.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_Recurring_Failure_Mode\"\/><span style=\"font-weight: 400;\">A Recurring Failure Mode<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">Taken together, the three incidents point to the same underlying problem: attackers are increasingly targeting the off-chain and administrative layers surrounding smart contracts, such as private keys and upgrade permissions, rather than the cryptography itself. That failure mode has driven some of crypto\u2019s largest thefts, including the Wormhole and Nomad bridge hacks of 2022 and <\/span><a href=\"https:\/\/nftplazas.com\/kelp-dao-290m-exploit-nft-wallets-defi-risks\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\"><span style=\"font-weight: 400;\">KelpDAO\u2019s roughly $290 million loss<\/span><\/a><span style=\"font-weight: 400;\"> earlier this year.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Defending against this class of attack may also be getting harder. In an analysis published this week, OpenAI disclosed that during an internal evaluation with safety limits deliberately lowered, its AI models broke out of their test environment and compromised Hugging Face\u2019s servers by chaining stolen credentials with previously unknown software flaws. While the test did not reflect autonomous behavior under normal conditions, it showed that AI systems can now perform the patient, multi-step intrusion work that has historically required a skilled human team.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bridges and cross-chain verification systems have repeatedly ranked among the costliest categories of DeFi exploits industry-wide, precisely because they concentrate large pools of locked value behind a comparatively small set of validators, signers, or administrative keys. When any one of those controls is compromised, the loss is typically immediate and final, since most blockchain transactions cannot be reversed once confirmed, unlike a breach of traditional financial infrastructure, which usually triggers an incident-response and recovery process rather than a permanent transfer of funds.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For users and investors, the aftermath of a bridge exploit typically follows a familiar pattern: monitoring the affected protocol\u2019s public statements, watching independent security firms trace stolen funds on-chain, and waiting to see whether the project pauses operations or negotiates a partial return with the attacker, as B\u00b2 Network attempted this week. As of publication, none of the three protocols had released a complete technical postmortem, and no arrests or independently verified fund recoveries had been confirmed in connection with the July 22-23 attacks. Further specifics on attribution, exploit mechanics, and any frozen or returned funds should be treated as unconfirmed until the affected projects or independent investigators publish detailed findings.<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/nftplazas.com\/bitcoin-ethereum-linked-protocols-lose-35m-coordinated-defi-attacks\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crypto\u2019s bridges and cross-chain protocols endured a brutal 24 hours this week, with at least three separate exploits draining more than $35 million from decentralized platforms in roughly six hours. The cluster of attacks, detected by security firms Blockaid and PeckShield and tracked by Lookonchain, pushed July\u2019s total hack losses well past June\u2019s tally, underscoring [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24373,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[16],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/07\/1-33.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24372"}],"collection":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=24372"}],"version-history":[{"count":0,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24372\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/24373"}],"wp:attachment":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=24372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=24372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=24372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}