Crypto news

23.07.2026
19:17

Access Key Leak: Three DeFi Protocols Lost $35.5 Million in One Day

Over the past 24 hours, three DeFi protocols — AFX, B² Network, and Verus — have collectively lost approximately $35.5 million. Notably, none of the incidents involved the exploitation of vulnerabilities in smart contract code. The attacks were carried out exclusively through the compromise of access keys and administrative privileges.

AFX: $24 million loss due to theft of validator keys

The biggest blow hit the AFX protocol operating on the Arbitrum network. Attackers stole the bridge validator keys, allowing them to withdraw approximately $24 million in USDC. Within minutes, the funds were transferred to Ethereum and converted into 12,467.5 ETH. All stolen assets are currently concentrated at a single address, indicating a well-planned operation.

B² Network: $3.86 million via staking contract upgrade

The second target was the B² protocol on the BNB Chain. Hackers intercepted the rights to upgrade the staking contract and withdrew 8.591 million B2 tokens worth approximately $3.86 million. After the theft, the attackers exchanged the assets for over 5,000 WBNB, then for 1,128 ETH, and withdrew the funds via NEAR Intents. This caused an instant 15% drop in the price of the native B2 token.

Verus: repeat attack via trusted bridge path

The third victim was the Verus bridge, which lost approximately $7.5 million. Interestingly, the attack was carried out through the same vulnerability as the previous time — the trusted bridge path. The attacker almost immediately began laundering the funds through Tornado Cash, making them difficult to trace.

Paradigm shift: from code to keys

These three incidents confirm a worrying trend: hackers are increasingly targeting administrative privileges and access keys rather than the smart contract code itself, which now undergoes thorough audits. Estimates suggest that in 2026, approximately 40% of all stolen crypto assets resulted from key compromises, not contract hacks.

Expert opinion: This wave of attacks is a serious signal for the entire industry. Protocols may have flawless code, but if their security relies on centralized keys and administrative rights, they remain vulnerable. Transitioning to multi-signature, hardware wallets, and decentralized governance schemes is no longer an option but a necessity for survival.