Crypto news

23.07.2026
16:41

$35.5 million in a day: a new era of DeFi attacks — hackers no longer break the code

Over the past 24 hours, three DeFi protocols lost a total of $35.5 million. Notably, none of these attacks were related to errors in smart contracts. The market is witnessing a paradigm shift: hackers have switched from exploiting code vulnerabilities to seizing control through keys and administrative privileges.

The victims were the projects AFX, B² Network, and Verus. According to independent analysts, each case demonstrates that the weak link was not the bridges themselves, but the keys designed to protect them.

Three Strikes in One Day

The largest loss was suffered by the AFX protocol on the Arbitrum network — approximately $24 million in USDC. The attacker gained control of the bridge validator keys, transferred the stolen funds to Ethereum, and converted them into 12,467.5 ETH, which ended up in a single address.

The second target was the B² protocol on the BNB Chain. The attacker intercepted the upgrade rights for the staking contract. As a result, 8.591 million B2 tokens worth approximately $3.86 million were stolen. The hackers exchanged the assets for over 5,000 WBNB, then for 1,128 ETH, and withdrew the funds via NEAR Intents. The native token of the B2 project instantly dropped by 15%.

The third victim was the Verus bridge on Ethereum, which lost about $7.5 million. Notably, this is the second instance of exploiting the same vulnerability — the bridge's trusted path. Almost immediately after the theft, the attacker began laundering the funds through Tornado Cash.

Keys — The New Battlefield

All three incidents reflect a fundamental shift in hacker tactics. Previously, attacks exploited code errors, but now, when the vast majority of contracts undergo strict AI audits, finding logical loopholes has become nearly impossible. Attackers have shifted their focus to compromising keys, administrative rights, and contract upgrade permissions. The emphasis is moving from the vulnerability level to the access level.

The scale of the problem is confirmed by statistics: in 2026, about 40% of all stolen cryptocurrency was due to key compromises, not smart contract hacks. The bridges themselves withstand attacks, but their protection — access keys — fails.

Cryptalist Comment: This trend is an alarming signal for the entire industry. DeFi projects have invested millions in code audits but have neglected the simplest rules of cyber hygiene: key storage, multi-factor authentication, and privilege management. Until infrastructure security becomes a priority on par with code security, we will continue to see such incidents again and again.