A series of coordinated exploits has hit Verus, B² Network, and other cross-chain platforms, exposing how vulnerabilities in private keys, upgrade permissions, and validation mechanisms can be just as dangerous as flaws in code. These attacks drained funds without ever breaking the underlying cryptography, underscoring a persistent weakness in crypto infrastructure.
The incidents unfolded rapidly, with at least three protocols compromised within six hours and total losses surpassing $35 million, according to blockchain data reviewed by CoinDesk along with security firms BlockAid and PeckShield.
What ties these attacks together is not faulty encryption, but weaknesses beyond the blockchain itself. In each case, either the system’s logic allowed unintended withdrawals, or attackers gained access to privileged keys that handed them control.
The attacks
The hardest hit was the perpetuals platform AFX, which lost around $24.15 million through a bridge on Arbitrum. The Verus-Ethereum bridge followed, drained of $7.54 million—its second exploit this year via the same vulnerability. Meanwhile, B² Network, a Bitcoin scaling solution, suffered losses of $3.86 million from its staking contract.
Verus stands out as the most concerning case. Early Thursday, BlockAid detected an exploit targeting its Ethereum bridge, where attackers siphoned off ether, tokenized bitcoin, and multiple stablecoins worth $7.54 million.
Investigators found that the exploit reused the same pathway and contract previously targeted in a May attack that resulted in $11.5 million in losses. The flaw allowed attackers to trigger withdrawals on Ethereum that were not properly backed by assets on the Verus side, effectively releasing real funds against invalid claims.
Bridges, which enable assets to move between otherwise incompatible blockchains, rely entirely on accurate verification of locked funds. When that verification fails, the entire system breaks down.
After the earlier attack, most of the stolen funds were returned in exchange for a bounty. However, Verus later redeposited those recovered assets into the same bridge earlier this month—only for it to be exploited again two weeks later.
The fallout is visible in the platform’s declining metrics. Verus held close to $100 million in total value locked at the start of 2025, but that figure has now fallen to roughly $9 million, reflecting both losses and waning user confidence.
Repeated breaches do more than drain funds—they erode trust, prompting users to withdraw assets and weakening the platform further.
B² Network’s breach highlights a different but equally critical risk. The project revealed that attackers gained control over the upgrade authority of its staking contract, giving them the ability to alter its behavior.
Blockchain analysts traced the stolen $3.86 million in tokens as they were sold, converted into ether and stablecoins, and moved off-platform. B² responded by halting staking and pledging to fully reimburse affected users.
These events reinforce a key lesson: smart contracts are only as secure as the permissions and keys that govern them. If those controls are compromised, attackers do not need to exploit code—they can simply take control.
This pattern echoes some of crypto’s biggest historical breaches, including the Wormhole and Nomad bridge hacks of 2022, as well as KelpDAO’s $290 million loss earlier this year.
The threat landscape may also be evolving. A recent OpenAI analysis showed that AI systems, under controlled testing conditions, were able to chain together stolen credentials and unknown vulnerabilities to breach external servers—demonstrating capabilities once limited to skilled human attackers.
While these tests involved relaxed safety constraints, they highlight how emerging technologies could accelerate and scale such attacks.
Unlike traditional finance, where breaches can often be reversed or mitigated, crypto offers no such safety net. Once funds are drained, recovery is rarely possible.
In just 24 hours, four platforms—Verus, B², AFX, and Balance—were compromised due to failures in trust and access controls, not broken encryption. As tools for identifying these weaknesses become more advanced, the risks facing crypto infrastructure continue to grow.

































