Crypto news

23.07.2026
22:06

Three DeFi protocols lost $35.5 million in one day: hackers attack not the code, but the governance

Over the past 24 hours, the crypto community has faced three coordinated attacks on DeFi bridges, resulting in a total of $35.5 million being stolen. Notably, none of the incidents involved the exploitation of vulnerabilities in smart contracts. The attackers acted more subtly—through the compromise of access keys and administrative privileges.

Biggest Blow: AFX Protocol Loses $24 Million

The greatest damage was suffered by the AFX protocol, operating on Arbitrum. The hacker gained control of the bridge validator keys and withdrew approximately $24 million in USDC stablecoins. The funds were quickly moved to Ethereum and converted into 12,467.5 ETH, which are now concentrated on a single address. This is a classic example of how reliable bridge technology collapses due to the human factor in key management.

B² Network and Verus: A Repeat Scenario

The second victim was the B² Network bridge on BNB Chain. The attacker seized the rights to update the staking contract and stole 8.591 million native B2 tokens worth about $3.86 million. After the hack, the attacker converted the assets into WBNB, then into ETH, and withdrew the funds via the NEAR Intents protocol. The B2 token price instantly plummeted by 15%.

The third incident involved the Verus bridge. The hacker exploited a trusted bridge path, and this is already the second attack on the same vector. The damage amounted to approximately $7.5 million. The attacker almost immediately began laundering the funds through Tornado Cash, indicating a high level of sophistication.

New Threat Paradigm: Keys Instead of Code

These three incidents clearly demonstrate a shift in attackers' priorities. While previously the main vector was errors in smart contract logic, identified by auditors, hackers are now targeting the management infrastructure. Compromising private keys, administrative rights, and contract update functions is becoming the primary tool.

Statistics confirm this trend: in 2026, about 40% of all stolen cryptocurrency funds were due to key compromises, not code hacks. The bridges themselves remain resistant to direct attacks—the weak link becomes their security, or more precisely, access management.

Expert Opinion: We are witnessing a fundamental shift in the DeFi threat landscape. Projects that spend millions on smart contract audits but neglect key security and multi-signature schemes risk becoming the next victim. Investors should pay attention not only to the code but also to how the protocol's management is organized.