Back-to-Back Breaches: Crypto Protocols on Bitcoin and Ethereum Lose $35M

A wave of exploits targeting Verus, B² Network, and other cross-chain platforms has highlighted a critical weakness in crypto systems: vulnerabilities beyond the code itself. In these cases, attackers leveraged compromised keys, privileged upgrade access, and flawed validation checks to drain funds—without ever breaking the underlying cryptography.

The attacks unfolded within a six-hour window, with at least three protocols hit in quick succession and combined losses exceeding $35 million, based on blockchain data analyzed by CoinDesk and security firms BlockAid and PeckShield.

What links these breaches is a shared failure outside core encryption. Rather than cracking cryptographic systems, attackers exploited logic gaps—where protocols behaved as designed but still allowed improper withdrawals—or seized control through compromised credentials.

The exploits

AFX, a perpetuals exchange, suffered the largest hit, losing about $24.15 million via a bridge on Arbitrum. The Verus-Ethereum bridge was drained of $7.54 million, marking its second exploit this year using the same flaw. Meanwhile, B² Network, a Bitcoin scaling platform, lost $3.86 million from its staking contract.

The Verus incident stands out for its severity and repetition. Early Thursday, BlockAid identified suspicious activity on its Ethereum bridge, where attackers siphoned off millions in ether, tokenized bitcoin, and stablecoins.

The exploit reused the same contract pathway involved in a previous May attack that caused $11.5 million in losses. The vulnerability allowed attackers to trigger withdrawals on Ethereum that were not properly backed by assets on the Verus chain, effectively exchanging worthless claims for real funds.

Cross-chain bridges function by locking assets on one network and issuing equivalent tokens on another. Their security depends entirely on verifying that every withdrawal is supported by genuine reserves. When that verification fails, the system can be exploited.

After the earlier breach, most stolen funds were returned in exchange for a bounty. However, those recovered assets were later redeposited into the same bridge—only for it to be exploited again within weeks.

The damage is reflected in Verus’s declining metrics. From nearly $100 million in total value locked at the start of 2025, the protocol now holds roughly $9 million, a drop driven by repeated losses and fading user trust.

Such incidents do more than remove funds—they undermine confidence, prompting users to exit and accelerating the platform’s decline.

B² Network’s exploit highlights another major risk: control over administrative permissions. The project reported that attackers gained access to the upgrade authority of its staking contract, enabling them to manipulate its behavior.

Blockchain analysts tracked the stolen $3.86 million as it was sold, converted into ether and stablecoins, and moved off the platform. In response, B² halted staking operations and pledged full reimbursement to affected users.

These events reinforce a central lesson: smart contract security depends not only on code, but on the integrity of the keys and permissions that govern it. If those controls are compromised, attackers can bypass code vulnerabilities entirely.

This pattern echoes some of the largest crypto hacks in history, including the Wormhole and Nomad bridge exploits of 2022, as well as KelpDAO’s $290 million loss earlier this year.

The threat landscape is also evolving. A recent OpenAI analysis demonstrated that AI systems, under controlled testing conditions, could combine stolen credentials with unknown software flaws to breach external servers—showcasing capabilities once limited to skilled human attackers.

Although the test involved relaxed safety constraints, it signals how emerging tools could make complex attacks faster and more scalable.

Unlike traditional financial systems, crypto offers little recourse once funds are lost. There are no chargebacks or recovery mechanisms, making such breaches especially severe.

In just 24 hours, four platforms—Verus, B², AFX, and Balance—were compromised due to failures in trust and access controls rather than broken encryption. As attackers gain more sophisticated tools, the risks facing crypto infrastructure continue to intensify.