Key facts
- At least three crypto bridges and cross-chain protocols lost over $35 million in a six-hour span.
- The Verus-Ethereum bridge was exploited for approximately $7.54 million, reusing a bug from a previous hack.
- B² Network lost about $3.86 million after its staking contract's upgrade authority was compromised.
- The attacks exploited logic flaws or compromised administrative keys, not underlying cryptography.
- Verus had redeposited funds recovered from a prior hack into the vulnerable bridge before the latest exploit.
Multiple cryptocurrency bridges and cross-chain protocols suffered significant losses totaling over $35 million within a six-hour period due to security exploits. The attacks, which occurred on July 23, 2026, targeted vulnerabilities in the design and governance of these systems, rather than breaking the underlying cryptography.
The Verus-Ethereum bridge was compromised for approximately $7.54 million. Security firm Blockaid noted that the exploit utilized the same contract path and bug class as a previous hack in May, which had resulted in an $11.5 million loss. Despite recovering most of the funds from the earlier incident and redepositing them on July 8, the bridge was drained again. Bridges function by holding assets on one chain and issuing claims on another, with their security dependent on verifying that withdrawals are backed by locked assets.
Separately, the B² Network lost around $3.86 million when an attacker gained unauthorized access to the upgrade authority of its token staking contract. Security firm Lookonchain traced the sold B2 tokens, which were converted to ether and stablecoins. B² Network stated it had contained the incident, suspended staking, and would compensate affected users.
These incidents highlight that compromised keys and administrative permissions, rather than cryptographic flaws, remain primary causes of major crypto thefts. The increasing capability of AI-driven intrusion tools poses a growing threat, as demonstrated by OpenAI's disclosure of its models' ability to perform complex, multi-step intrusions. In the crypto space, where transactions are often final and irreversible, such breaches have no undo button.
