Crypto news

23.07.2026
16:56

$35.5 million per day: a new wave of attacks on DeFi — hackers no longer break the code

Over the past 24 hours, three DeFi protocols — AFX, B² Network, and Verus — have lost a total of $35.5 million. But a key detail that is forcing the market to rethink security approaches: none of these attacks were related to vulnerabilities in smart contracts. Hackers are no longer breaking code — they are seizing control of projects through access keys and administrative privileges.

Chronicle of Three Hacks

The largest loss belongs to the AFX protocol on the Arbitrum network. Attackers compromised the bridge validator keys and withdrew approximately $24 million in USDC. The funds were quickly moved to Ethereum and converted into 12,467.5 ETH, which are now concentrated on a single address.

The second blow hit B² Network on the BNB Chain. The hacker gained access to the staking contract upgrade rights, allowing them to withdraw 8.591 million native B2 tokens worth about $3.86 million. After the theft, the assets were exchanged for over 5,000 WBNB, then into 1,128 ETH, and withdrawn via NEAR Intents. The market reaction was immediate — the B2 token crashed by 15%.

The third victim was the Verus bridge. The attack was carried out through a trusted bridge path, and this is already the second time the same vulnerability has been exploited. The damage amounted to about $7.5 million. The hacker immediately began laundering the stolen funds through Tornado Cash.

Paradigm Shift: From Code to Control

Analysts are noting a worrying trend. In 2025, about 40% of all stolen cryptocurrency came from key compromises, not smart contract hacks. The reason is simple: code auditing has become an industry standard, and finding vulnerabilities in contract logic is becoming increasingly difficult. Hackers are adapting — they have shifted to access-level attacks: stealing private keys, seizing contract upgrade rights, and manipulating administrative privileges.

Bridges themselves can be secure, but their protection is primarily about protecting keys. Until the industry transitions to multi-factor governance schemes and hardware wallets for administrative keys, such attacks will continue. This is not a code error — it is an operational security error.

Cryptalist Analyst Opinion: The DeFi market is entering a new era of threats. Projects should reconsider their priorities: instead of endless smart contract audits, they need to invest in key management infrastructure, multi-signature schemes, and regular privilege rotation. Otherwise, the next victim could be even larger.