$35.5 million lost in one day: three DeFi bridges fell victim to key attacks, not code
In a single day, three DeFi protocols lost a combined $35.5 million, and none of these attacks were related to smart contract errors. Attackers are no longer hacking code—they are taking control of protocols through keys and administrative privileges. This is a warning signal for the entire industry.
The victims were the AFX, B² Network, and Verus projects. Each incident, as analysis shows, revealed the same vulnerability: the weak link was not the bridges themselves, but the keys that protect them.
Three attacks in one day
The biggest blow hit the AFX protocol—approximately $24 million was lost. The cause was the compromise of bridge validator keys. The Arbitrum network lost roughly $24 million in USDC. The attacker quickly moved the stolen funds from Arbitrum to Ethereum, where they exchanged them for 12,467.5 ETH, which ended up in a single address.
The second target was the B² protocol. The attacker intercepted the right to update the staking contract. B² on the BNB Chain lost 8.591 billion B2 tokens worth approximately $3.86 million. The attackers exchanged the stolen assets for over 5,000 WBNB, then for 1,128 ETH, and withdrew the funds via NEAR Intents. The project's native token, B2, instantly dropped by 15%.
The third victim was the Verus bridge. The attacker exploited a trusted bridge path, doing so a second time through the same vulnerability. The Verus Ethereum bridge lost about $7.5 million. The attacker almost immediately began laundering the stolen funds through Tornado Cash.
Keys instead of code
All three cases reflect a fundamental shift in hacker tactics. Previously, attacks exploited errors in the code itself, but today developers audit most contracts with AI, and logic gaps have become fewer. Therefore, attackers take control of the code through other means—via keys, administrative rights, and contract update permissions. The focus of attacks is shifting from the vulnerability level to the access level.
The scale of the problem is confirmed by statistics: in 2026, about 40% of all stolen cryptocurrency came from key compromises, not smart contract hacks. The main conclusion is obvious: the bridges themselves withstand attacks, but their defense—access keys—breaks down.
Analyst's opinion: The industry has focused too long on code security, ignoring access management. Until projects implement multi-factor authentication, hardware wallets for keys, and decentralized privilege management schemes, we will see such incidents again and again. $35.5 million in one day is just the tip of the iceberg.