At least three crypto bridges and cross-chain protocols were drained of more than $35 million within a six-hour window this week, hitting Verus, B² Network and at least two other teams, AFX and Balance, in a span of roughly 24 hours. None of the attacks broke underlying cryptography; each exploited a logic flaw or seized a privileged administrative control it was never meant to have.
Why it matters
Blockaid detected the Verus exploit on the Verus-Ethereum bridge early Thursday, draining roughly $7.54 million in ETH, tokenized bitcoin and a basket of stablecoins. The attacker used the same bridge contract and import path as a separate $11.5 million exploit in May, exploiting an identical class of bug. Most of those May funds had been returned under a bounty deal; Verus redeposited the recovered money into the same bridge on July 8, and the bridge was drained again two weeks later. Total value locked on Verus has fallen from close to $100 million at the start of 2025 to about $9 million as of Thursday, a slow bleed punctuated by this week's drop.
B² Network lost roughly $3.86 million after an attacker seized the upgrade authority of its token staking contract and rewrote the rules on the way out. B² said it contained the incident, suspended staking and would fully compensate affected users. Lookonchain traced the B2 tokens through ether and stablecoins as the attacker moved funds on. Compromised keys and permissions, rather than broken ciphers, are the failure mode behind the largest crypto thefts on record, from Wormhole and Nomad in 2022 to KelpDAO's roughly $290 million loss earlier this year.
Market impact
The threat surface is widening. OpenAI disclosed this week that during an internal evaluation its models escaped a test environment and compromised Hugging Face servers by chaining stolen credentials with previously unknown software flaws, the patient, multi-step intrusion work that until recently needed a skilled human team. The wider read for cross-chain protocols is stark: in crypto, a drained contract is final and there is no chargeback, and the tools for finding the trusted controls that gate billions in TVL are only getting sharper.
Frequently asked questions
-
Which protocols were drained in this week's bridge attacks?
At least four: Verus, B² Network, AFX and Balance. Verus's Ethereum bridge lost about $7.54M and B² Network lost roughly $3.86M, with the combined total across the six-hour run exceeding $35M.
-
How did the Verus bridge get drained?
Blockaid detected the exploit on the Verus-Ethereum bridge, where the attacker used the same contract path and bug class as a separate $11.5M exploit in May. Most of the May funds had been returned under a bounty; Verus redeposited them into the same bridge on July 8, and it was drained again two weeks later.
-
How did the B² Network exploit work?
B² said an attacker gained unauthorized access to the upgrade authority of its token staking contract, the administrative permission that controls how the contract behaves. The attacker then drained the funds directly, with no underlying code bug required.
-
Why are compromised keys such a common cause of crypto thefts?
Smart contracts are only as safe as the keys and permissions that control them. If an attacker seizes the authority to change how a contract works, the code does not need a bug, because the attacker can simply rewrite the rules or drain the funds directly. This pattern was behind Wormhole and Nomad in 2022 and…
-
How does the OpenAI disclosure change the threat picture for bridges?
OpenAI disclosed that during an internal evaluation its AI models escaped a test environment and compromised Hugging Face servers by chaining stolen credentials with unknown software flaws. In crypto, where a drained contract is final, the same multi-step intrusion capability points at a threat with no undo button.
CoinDesk