Crypto news

23.07.2026
16:11

A new era of DeFi attacks: $35.5 million stolen without a single code error — key compromise becomes the main threat

Over the past day, the crypto community has faced an alarming trend: three DeFi protocols — AFX, B² Network, and Verus — collectively lost $35.5 million. However, the key feature of these incidents is not the amount of damage, but the attack method. None of the hacks were related to exploiting vulnerabilities in smart contracts. The attackers acted more subtly: they seized control of administrative keys and access rights, bypassing code protection.

Three Strikes in One Day

The biggest blow hit the AFX protocol, operating on the Arbitrum network. Losses amounted to about $24 million in USDC. The hacker, gaining access to the bridge's validator keys, transferred funds to Ethereum and converted them into 12,467.5 ETH, which ended up in a single address. This is a classic example of an attack on the infrastructure level, not on contract logic.

The second victim was the B² protocol on the BNB Chain. Here, the attacker intercepted the right to update the staking contract. As a result, 8.591 million B2 tokens worth about $3.86 million were stolen. The stolen assets were converted into 5000 WBNB, then into 1128 ETH, and withdrawn through the NEAR Intents platform. The native token of the B2 project instantly lost 15% of its value, highlighting the vulnerability of ecosystems to such attacks.

The third was the Verus bridge. The hacker used the bridge's trusted path, and this was already the second attack through the same vulnerability. The Verus Ethereum bridge lost about $7.5 million. The attacker almost immediately began laundering funds through Tornado Cash, indicating a high level of professionalism.

Keys Instead of Code: A Paradigm Shift in Threats

These three cases are not a coincidence but a reflection of a global shift in hacker tactics. Previously, attacks targeted logical errors in smart contracts. Now, when most code undergoes strict audits, attackers have switched to the "human factor" and infrastructure. They seize control not through code, but through keys, administrative privileges, and contract update rights.

The scale of the problem is confirmed by statistics: in 2026, about 40% of all stolen cryptocurrency came from key compromises, not smart contract hacks. The conclusion is obvious: the bridges themselves may be technically reliable, but their protection collapses if access keys are compromised.

My expert opinion: DeFi projects urgently need to reconsider their security models. The focus should shift from code auditing to key management, multi-factor authentication, and the use of multi-signatures with cold wallets. Otherwise, we risk seeing these attacks repeated on an even larger scale.