Hours, Millions Lost: Bitcoin and Ethereum Protocols Reeling from Consecutive Attacks
A fresh wave of exploits has hit Verus, B² Network, and several cross-chain platforms, once again exposing a core weakness in crypto infrastructure: failures in access control rather than cryptography. In each case, attackers took advantage of compromised keys, upgrade privileges, or flawed validation logic to drain funds—without needing to break encryption.
The attacks occurred in quick succession, with at least three protocols breached within a six-hour window and total losses surpassing $35 million, according to blockchain data reviewed by CoinDesk and security firms BlockAid and PeckShield.
The common thread across these incidents lies outside smart contract code. None of the attackers cracked cryptographic systems. Instead, they exploited design flaws that allowed unintended fund movements or gained control through stolen credentials that should never have been exposed.
The incidents
AFX, a perpetuals exchange, suffered the largest loss, with about $24.15 million drained through a bridge on Arbitrum. The Verus-Ethereum bridge lost $7.54 million—its second exploit this year through the same vulnerability. Meanwhile, B² Network, a Bitcoin scaling solution, saw $3.86 million siphoned from its staking contract.
The Verus breach is particularly notable for its repetition. Early Thursday, BlockAid detected suspicious activity on its Ethereum bridge, where attackers drained millions in ether, tokenized bitcoin, and multiple stablecoins.
The exploit reused the same pathway targeted in a May incident that resulted in $11.5 million in losses. The vulnerability allowed withdrawals on Ethereum that were not properly backed by assets on the Verus chain, effectively enabling real funds to be released against invalid claims.
Cross-chain bridges function by locking assets on one network and issuing corresponding tokens on another. Their security depends entirely on accurate verification of reserves—when that fails, the system becomes exploitable.
After the earlier hack, most of the stolen funds were returned in exchange for a bounty. However, those recovered assets were later redeposited into the same bridge, which was then drained again within weeks.
The consequences are reflected in Verus’s declining metrics. The protocol held nearly $100 million in total value locked at the start of 2025 but now retains only around $9 million, as repeated exploits and loss of confidence drive users away.
Such incidents do more than remove funds—they undermine trust, accelerating capital flight from affected platforms.
B² Network’s breach highlights another critical vulnerability: administrative control. The project confirmed that attackers gained access to the upgrade authority of its staking contract, giving them the ability to modify its behavior.
Blockchain analysts traced the stolen $3.86 million as it was sold, converted into ether and stablecoins, and moved off-platform. In response, B² halted staking and promised full reimbursement to affected users.
These cases reinforce a fundamental lesson: the security of smart contracts depends not only on their code but on the integrity of the keys and permissions that govern them. Once those controls are compromised, attackers can bypass technical safeguards entirely.
This pattern echoes some of the largest crypto exploits in recent history, including the Wormhole and Nomad bridge hacks of 2022, as well as KelpDAO’s $290 million loss earlier this year.
At the same time, the threat environment is evolving. A recent OpenAI analysis demonstrated that AI systems, under controlled testing conditions, could chain together stolen credentials and undisclosed software flaws to breach external systems—showing how advanced attack methods are becoming more accessible.
While these tests involved reduced safeguards, they illustrate how emerging technologies could accelerate and scale complex intrusions.
Unlike traditional finance, crypto provides little recourse once funds are lost. With no chargebacks or recovery mechanisms, such breaches often result in permanent losses.
In just 24 hours, four platforms—Verus, B², AFX, and Balance—were compromised due to failures in trust and access controls rather than broken encryption. As attackers grow more sophisticated, the risks facing crypto infrastructure continue to intensify.
Share this content:













