Go to app

Exploit Breakdown by Protocol

Published 7/23/2026, 2:26:56 PM

On July 23, 2026, a coordinated wave of exploits dubbed "Hackers Day" resulted in the theft of $35.55 million from three major protocols—AFX Trade, Verus, and B² Network—within a single six-hour window [Source: https://www.coindesk.com/business/2026/07/23/35m-crypto-exploit-surge-three-protocols-hit-in-six-hours/]. The surge was primarily driven by failures in operational security and trusted controls rather than smart contract bugs, specifically compromised validator keys and unauthorized upgrade authority [Source: https://www.trmlabs.com/post/crypto-hack-report-h1-2026].

Exploit Breakdown by Protocol

ProtocolChainLossPrimary Cause
AFX TradeArbitrum$24.15MCompromised bridge validator keys
VerusEthereum$7.54MUnpatched logic flaw (repeat exploit)
B² NetworkBNB Chain$3.86MCompromised staking contract upgrade authority
Total—$35.55M—

Root Causes and Mechanisms

The surge was characterized by three distinct but rapid-fire attack vectors:

  • Compromised Validator Keys (AFX Trade): Attackers gained access to five hot-validator signing keys for the AFX bridge. This allowed them to authorize the withdrawal of $24.15M in USDC in just 200 seconds [Source: https://www.coindesk.com/business/2026/07/23/35m-crypto-exploit-surge-three-protocols-hit-in-six-hours/]. The stolen funds were subsequently converted into 12,467.5 ETH.
  • Repeat Logic Flaws (Verus): Verus suffered a drain of $7.54M due to the same bridge logic error that led to an $11.5M loss in May 2026 [Source: https://blockaid.io/blog/verus-exploit-july-2026]. The protocol had redeposited recovered funds into the same vulnerable bridge on July 8, 2026, which were then exploited again two weeks later.
  • Unauthorized Upgrade Authority (B² Network): The attacker seized the upgrade authority of the B2 staking contract, allowing them to rewrite contract rules to drain 8.59M B2 tokens [Source: https://x.com/PeckShieldAlert/status/1784816689]. These were swapped for WBNB and ETH before being bridged out via NEAR Intents.

Systemic Context

Security researchers have identified broader trends that contributed to this concentrated surge:

  1. Operational Vulnerabilities: Approximately 88% of total losses in H1 2026 have been attributed to compromised keys and permissions rather than cryptographic failures [Source: https://www.trmlabs.com/post/crypto-hack-report-h1-2026].
  2. AI-Enhanced Intrusions: The speed of these attacks aligns with recent warnings that AI models can now chain stolen credentials and perform multi-step intrusions autonomously [Source: https://openai.com/blog/ai-agent-security-analysis-2026].
  3. Bridge Security: Cross-chain infrastructure remains the most targeted sector, particularly bridges relying on validator-based security without sufficient collateralization.

Current Status: AFX Trade has offered the attacker a 30% whitehat bounty to return the remaining 70% of the stolen funds. Verus's Total Value Locked (TVL) has collapsed to approximately $9M following this second exploit. While individual post-mortems have identified specific causes for each protocol, the extreme temporal proximity of the attacks suggests a coordinated effort or the use of shared automated exploitation tools.