Crypto news

23.07.2026
22:22

New era of DeFi hacks: $35.5 million stolen without a single code error — keys become the main target

In a single day, three DeFi protocols — AFX, B² Network, and Verus — lost a combined total of $35.5 million. However, unlike the vast majority of previous attacks, none of them were related to smart contract vulnerabilities. This is not a coincidence, but a persistent trend that I, as an analyst, have been pointing out for several quarters.

Attackers are no longer spending time searching for bugs in the code. Instead, they seize control through administrative keys, contract upgrade rights, and trusted bridge pathways. The attacks have become "dirtier" and less technical, but no less devastating.

Three Strikes in One Day: A Chronicle of Events

The largest blow hit the AFX protocol, operating on Arbitrum. The attackers stole approximately $24 million in USDC using compromised bridge validator keys. The funds were instantly transferred to Ethereum and converted into 12,467.5 ETH. This is a classic example of how a single compromised key can undermine the entire security of a bridge.

The second target was the B² protocol on the BNB Chain. The attacker intercepted the right to upgrade the staking contract and withdrew 8.591 million B2 tokens worth approximately $3.86 million. The stolen assets were quickly exchanged for over 5,000 WBNB, then into 1,128 ETH, and withdrawn via the NEAR Intents protocol. The project's native token, B2, crashed by 15% immediately after the incident — a classic market reaction to a loss of trust.

The third victim was the Verus bridge, which lost approximately $7.5 million. Notably, the attacker used a trusted bridge pathway — and did so for the second time through the same vulnerability. The funds were immediately sent for laundering via Tornado Cash.

Paradigm Shift: Code is Verified, Keys are Not

According to analysts, in 2026, approximately 40% of all stolen cryptocurrency was due to key compromises, not smart contract hacks. This is a turning point. Developers have been paying more attention to code audits, but infrastructure security — key storage and management — remains the "weak link."

My conclusion as an analyst: The bridges and protocols themselves are becoming increasingly resilient to direct code attacks. But their defense — the access keys — breaks just as easily as before. Until project teams rethink their approaches to privilege management and multi-signature, we will see more and more such incidents. The market must realize: DeFi security is not just about clean code, but also about iron discipline in handling keys.