According to security firms BlockAid and PeckShield, as well as on-chain analytics provider Lookonchain, within hours on July 23 there were four back-to-back attacks targeting crypto protocols, involving the Bitcoin and Ethereum ecosystems, with total losses exceeding $35 million. The biggest loss was from Arbitrum derivatives protocol AFX Trade, where leaked private keys from a cross-chain bridge led to $24 million being withdrawn.
AFX Trade’s cross-chain bridge private key leak
AFX Trade, built on Arbitrum, was the worst-hit case among the four attacks. According to detections by security firm BlockAid, the attacker obtained the protocol’s cross-chain bridge private key, then transferred roughly $24 million in assets out.
Once a private key is stolen, attackers effectively hold the keys to the vault, leaving user funds with almost no way to stop the transfer in real time. Cross-chain bridge private key leaks are not unheard of: in May this year, Stake DAO was attacked after a deployer’s private key was leaked, with attackers minting 5.4 trillion vsdCRV on Arbitrum as well—highlighting the fragility of cross-chain infrastructure in key management.
Verus’s bridging logic flaw exploited again
Ethereum cross-chain bridge protocol Verus lost about $7.54 million. The attacker exploited a logic flaw in the bridge’s inbound routing path, causing the system to pay out assets without actual collateral; the stolen tokens included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
This is the second time the same type of flaw has been exploited. In May, Verus previously lost about $11.5 million due to the same contract defect; after the funds were deposited again on July 8, about two weeks later they were drained again on July 23, showing the original vulnerability was never fixed.
Same-day attacks on B² Network and Balance
The four attacks on July 23 were as follows:
AFX Trade (Arbitrum): lost about $24 million; cross-chain bridge private key leak; detected by BlockAid
Verus (Ethereum): lost about $7.54 million; bridging logic flaw (same as in May); ETH, tBTC, USDC, USDT, etc. stolen
B² Network (Bitcoin layer 2): lost about $3.86 million; attacked via staking contract upgrade permissions; B2 tokens exchanged for ETH and stablecoins; the protocol has paused staking functionality and promised full compensation; tracked by Lookonchain
Balance: lost about $1 million; Bitcoin vault drained; the price of the stablecoin issued by the protocol crashed by about 99%
FAQ
What crypto protocols were involved in the attacks on July 23, and how much was lost for each?
Based on tracking by BlockAid, PeckShield, and Lookonchain, the four attacks involved: AFX Trade (loss of about $24 million due to cross-chain bridge private key leak), Verus (loss of about $7.54 million due to bridging logic flaw), B² Network (loss of about $3.86 million due to an attack on contract upgrade permissions), and Balance (loss of about $1 million due to the Bitcoin vault being drained). Total losses exceeded $35 million.
Why was the same vulnerability exploited twice for Verus?
In May this year, Verus lost about $11.5 million due to the bridging inbound path logic flaw. After the funds were deposited back on July 8, the original vulnerability was not patched, leading to another attack around two weeks later on July 23, with losses of about $7.54 million.
What commitments has B² Network made to affected users?
According to reports, after the attack B² Network paused its staking functionality and promised full compensation for affected users; the specific compensation plan will be based on B² Network’s official announcement.