NewsCryptoThree Crypto Protocols Lose More Than $35 Million in 24 Hours of Exploits

Three Crypto Protocols Lose More Than $35 Million in 24 Hours of Exploits

Author: Crypto Potato·

Key Takeaways

  • AFX Trade suffered the largest loss of approximately $24.15 million in USDC when its Arbitrum-based bridge was exploited on July 22.
  • BSquaredNetwork lost roughly $3.86 million in B2 tokens on BNB Chain, with the token's price dropping over 15% following the attack.
  • Verus experienced its second exploit in two months, losing $7.55 million through the same bridge contract and bug class identified in its earlier $11.58 million incident.
  • Arbitrum contributor Steven Goldfeder confirmed that the compromised AFX bridge was independently operated and not maintained by Arbitrum's core team.
  • Security expert Taylor Monahan criticized AFX's security posture, noting minimal test coverage, acknowledged but unfixed audit issues, and incomplete code reviews.
Three Crypto Protocols Lose More Than $35 Million in 24 Hours of Exploits

AFX Trade, BSquaredNetwork, and Verus were all targeted in separate exploits within a 24-hour period, with combined losses exceeding $35 million in crypto assets.

The wave of incidents, described by some observers as “Hackers Day,” affected protocols across Arbitrum, BNB Chain, and Ethereum-linked bridge infrastructure. The incidents also put renewed attention on bridge security, since cross-chain systems often sit between networks and can hold or route large amounts of user assets.

Three Separate Exploits Hit Crypto Protocols

PeckShieldAlert said it detected an attack on the Arbitrum-based protocol AFX on July 22, estimating the loss at about $24.15 million in USDC. According to the on-chain security firm, the exploiter bridged the stolen funds from Arbitrum to Ethereum and then swapped them for 12,467.5 ETH. https://x.com/PeckShieldAlert/status/2080088731558801909

Less than an hour later, PeckShieldAlert reported another incident involving BSquaredNetwork on BNB Chain. Attackers drained $8.59 million worth of B2 tokens, causing an estimated loss of approximately $3.86 million. The stolen tokens were quickly swapped for more than 5,000 WBNB, converted into 1,128 ETH, and then bridged out through NEAR Intents. https://x.com/i/status/2080095004484395028

B2’s price fell by more than 15% following the exploit.

A third incident was flagged by blockchain security firm Lookonchain, which alerted users to an exploit affecting Verus, an Ethereum-based cross-chain bridge protocol. In that case, the attackers took $7.55 million. https://x.com/lookonchain/status/2080161575923761418?s=20

The latest Verus incident came roughly two months after the protocol lost about $11.58 million in a separate exploit. Blockaid said the July attack appeared to be connected to the earlier incident, describing both as involving the same bridge contract, the same entry path, and the same class of bug. Repeated incidents involving the same infrastructure can be especially damaging for protocols because they raise questions not only about a specific bug, but also about whether fixes and post-incident reviews were sufficient.

Monahan Raises Questions Over AFX Security

Steven Goldfeder, a contributor at Arbitrum, confirmed that the compromised bridge was operated independently by AFX and was not one of Arbitrum’s native bridges. https://x.com/i/status/2080143511173611704

That distinction matters for users assessing risk across an ecosystem: a protocol can operate on a major network without its contracts or bridge infrastructure being maintained by the network’s core teams.

Separately, on-chain security expert Taylor Monahan questioned why the AFX bridge held $24 million in the first place. She said she found “terrifying” details after reviewing a recently published audit of the bridge. https://x.com/tayvano_/status/2080132658949210292?s=20

According to Monahan, the protocol had almost no test coverage, several issues identified by auditors had been acknowledged but not fixed, and the auditors allegedly could not fully review the code because they had received only parts of it.

“Honestly, they seem like a super chill team. Ah yeah it’s probably fine we’ll just wait it out and then manually send if we need to,” she wrote.

Monahan said the biggest red flags were not only the technical vulnerabilities themselves, but what they indicated about the team’s approach to security. She said the situation suggested a culture that did not prioritize security.