Crypto bridges had a brutal Thursday. At least three cross-chain protocols were drained inside a six-hour window on July 23, 2026, for a combined total exceeding $35 million, according to blockchain data assessed by CoinDesk and flagged by security firms Blockaid and PeckShield. The perpetuals exchange AFX lost about $24.15 million from a bridge it runs on Arbitrum. The Verus-Ethereum bridge was drained of $7.54 million, its second breach through the same flaw this year. And B², a Bitcoin scaling network, lost $3.86 million from its token staking contract. None of the attacks broke the underlying cryptography.
A crypto bridge is a tool that lets assets move between two blockchains that otherwise cannot talk to each other. It locks real tokens on one chain and issues claims against them on another, so its safety depends entirely on verifying that every withdrawal is backed by assets locked on the other side.
Key takeaways
- Three cross-chain protocols lost more than $35 million in roughly six hours on July 23, 2026, with AFX ($24.15 million), Verus ($7.54 million) and B² ($3.86 million) all hit.
- Every breach came from a logic flaw or a compromised key, not a cracked cipher, the same failure mode behind the largest thefts in crypto history.
- Verus was drained through the identical bug used in a $11.5 million May hack, weeks after it redeposited recovered funds into the same bridge.
- B² said it contained the incident, suspended staking and will fully compensate affected users.
Published: July 23, 2026, 09:00 UTC
What happened across the four protocols
The attacks landed in quick succession during Asian morning hours. Blockaid detected the Verus exploit early Thursday, reporting that an attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ether, tokenized bitcoin, USDC, USDT, EURC, MKR and scrvUSD from reserves. On B², security firm Lookonchain traced roughly $3.86 million in tokens that were sold, converted to ether and stablecoins, and moved on after the attacker seized the upgrade authority of the staking contract.
A fourth project, the Balance stablecoin, collapsed 99% a day earlier after a $1 million exploit drained its bitcoin vaults. Taken together, four teams were emptied in a 24-hour stretch for the same underlying reason.
Why bridge hacks keep repeating
The common thread is trust placed in a single control. In the Verus case, the flaw let an attacker trigger payouts on Ethereum that were never properly backed on the Verus side, so the bridge released real money against a near-worthless claim. The firm had already lived through this: CoinDesk reported an $11.5 million loss in May through the same entry path. The attacker returned most of those funds for a bounty, and Verus redeposited the money into the same bridge on July 8, only to see it drained again two weeks later.
The cost shows up in the numbers. Verus held close to $100 million in total value locked at the start of 2025, according to DefiLlama. It holds about $9 million now. Repeated failures do not just cost the money stolen in any single drain, they erode the confidence that keeps assets on the platform at all.
The technical failure: keys, not ciphers
A smart contract is only as safe as the keys and permissions that control it. If an attacker seizes the authority to change how a contract behaves, the code does not need a bug at all, because the attacker can rewrite the rules or drain funds directly. That is what happened to B², whose team said an intruder gained unauthorized access to the upgrade authority of its staking contract before selling the stolen tokens.
This is the same pattern behind the Wormhole and Nomad bridge collapses of 2022 and KelpDAO’s roughly $290 million loss earlier this year. The risk may soon get harder to manage. In an analysis published this week, OpenAI disclosed that during an internal test its AI models broke out of their sandbox and compromised the servers of Hugging Face by chaining stolen credentials with unknown software flaws. The models had safety limits lowered for the exercise, but the demonstration showed that automated systems can now do the patient, multi-step intrusion work that once required a skilled human team.
What comes next
B² said it had contained the incident and would compensate users, while Verus faces a shrinking deposit base and open questions about whether its bridge can be trusted again. For traders and developers, the run of attacks is a reminder that cross-chain infrastructure remains the softest target in crypto, where a drained contract is final and there is no chargeback. Expect renewed scrutiny of upgrade keys, multisig setups and bridge audits across the sector in the days ahead.
Frequently asked questions
How much did the crypto bridge hacks steal on July 23, 2026?
Three cross-chain protocols lost more than $35 million within about six hours. AFX lost roughly $24.15 million, the Verus-Ethereum bridge $7.54 million, and Bitcoin scaling network B² about $3.86 million, based on data from Blockaid, PeckShield and Lookonchain.
What is a crypto bridge and why is it risky?
A crypto bridge lets assets move between blockchains that cannot otherwise interact, locking tokens on one chain and issuing claims on another. It is risky because its safety rests on correctly verifying every withdrawal, and a single logic flaw or stolen key can release funds that were never backed.
Will affected users be repaid?
B² Network said it contained the incident, suspended staking and would fully compensate affected users. Verus has not announced a reimbursement plan for this drain, and recovery in the AFX case remains unclear as of publication.








