Crypto news

23.07.2026
18:59

Three DeFi protocols lost $35.5 million in one day: hackers attack keys, not code

Over the past 24 hours, three DeFi protocols — AFX, B² Network, and Verus — have collectively lost $35.5 million. Notably, none of the attacks were related to vulnerabilities in smart contract code. Instead, attackers focused on compromising keys and administrative rights, indicating a shift in the threat vector within the industry.

Largest Loss: AFX and $24 Million

The most significant attack targeted the AFX protocol, operating on Arbitrum. The hacker stole approximately $24 million in USDC by gaining access to the bridge validator keys. The funds were quickly moved to Ethereum and converted into 12,467.5 ETH, which settled on a single address. This is a classic example of how bridge protection proves weaker than the bridge itself.

B² Network: Staking Control Intercepted

The second incident affected B² Network on the BNB Chain. The attacker intercepted the right to update the staking contract, allowing them to withdraw 8.591 million B2 tokens worth approximately $3.86 million. After the theft, the assets were exchanged for over 5,000 WBNB, then into 1,128 ETH, and withdrawn via NEAR Intents. The project's native token, B2, instantly lost 15% of its value.

Verus: Repeated Attack via Trusted Path

The third victim was the Verus bridge. The hacker exploited the bridge's trusted path, marking the second time the same vulnerability has been exploited. Losses amounted to approximately $7.5 million. The attacker immediately began laundering funds through Tornado Cash, confirming the group's high level of professionalism.

New Reality: Keys Instead of Code

All three cases demonstrate a fundamental shift in hacker tactics. While attacks previously targeted errors in smart contract logic, the focus is now shifting to the access level. According to analysts, in 2026, approximately 40% of all stolen cryptocurrency funds resulted from key compromises rather than code exploits. Bridges themselves remain resistant to attacks, but their protection — access keys — is increasingly becoming the weak link.

Expert Opinion: This trend requires projects to rethink key management approaches and implement multi-factor authentication, including hardware modules and multi-signature. Without this, even the most sophisticated smart contracts will remain vulnerable.