Cross-chain crypto protocols lose $35m to key and logic flaws
Attackers drained more than $35 million from three cross-chain protocols in six hours by exploiting administrative keys and code logic rather than breaking cryptography, highlighting systemic governance risks as AI-driven intrusion tools become more capable.
At least three crypto bridges and cross-chain protocols were drained of more than $35 million in a six-hour span on Thursday. The attacks targeted Verus, B² Network, and AFX, relying on compromised administrative keys and code logic rather than broken cryptography. Security firms BlockAid and Peckshield confirmed the incidents.
The largest single loss hit AFX, a perpetuals exchange on Arbitrum, which lost roughly $24.15 million. B² Network, a Bitcoin scaling protocol, lost about $3.86 million after an attacker seized its staking contract's upgrade authority. Verus’s Ethereum bridge was drained of approximately $7.54 million in ether, tokenized bitcoin, and stablecoins.
The Verus exploit represents a severe failure of protocol governance. BlockAid noted the attacker used the same bridge contract and entry path as a previous hack, exploiting an identical class of bug. After an $11.5 million loss in May, the attacker returned the funds for a bounty. Verus then redeposited that capital into the same unpatched bridge on July 8, leaving it exposed to a second drain just two weeks later.
The financial cost of that oversight is evident in Verus's total value locked. The protocol held nearly $100 million at the start of 2025, but that figure has collapsed to roughly $9 million. Repeated failures drain not only stolen capital but the broader market confidence required to keep assets on a platform.
B² Network’s loss points to a parallel vulnerability in smart contract administration. By gaining unauthorized access to the permission that controls how the staking contract behaves, the attacker did not need to find a code bug. They simply rewrote the rules to extract the funds. B² has suspended staking and pledged to fully compensate users.
This pattern of failed trust controls is responsible for the largest thefts in crypto history, including the 2022 Wormhole and Nomad bridge hacks and KelpDAO's roughly $290 million loss earlier this year. The structural risk is worsening as AI-driven intrusion tools mature. OpenAI disclosed this week that its models successfully compromised external servers during a test by chaining stolen credentials and unknown software flaws.
For market participants, the takeaway is clear. Crypto bridges remain highly exposed not to mathematical breaking, but to human and administrative failures. As AI lowers the barrier to executing complex, multi-step intrusions, these governance weak points present an asymmetric threat in a financial system where drained contracts offer no chargebacks.