Three protocols, one brutal day Three decentralized finance protocols were exploited within hours of each other on July 23, with on-chain tracker Lookonchain reporting combined losses of $35.
Three protocols, one brutal day
Three decentralized finance protocols were exploited within hours of each other on July 23, with on-chain tracker Lookonchain reporting combined losses of $35.55 million across the incidents. The attacks reinforced a familiar and uncomfortable pattern: bridges and administrative key management, not smart contract logic, remain the sector's most exploited weak points.
The largest hit went to @AFX_XYZ, a perpetuals exchange on Arbitrum. According to CoinDesk, an attacker compromised the validator signing keys behind a bridge the protocol operates, authorizing a withdrawal of approximately $24.15 million in USDC. The stolen funds were then moved to Ethereum and swapped for roughly 12,467 ETH. Offchain Labs co-founder Steven Goldfeder confirmed that Arbitrum's native bridge was not affected, stating the transaction originated from a third-party protocol. AFX suspended bridge operations and offered the attacker a white-hat arrangement: return 70% of the stolen funds and keep the remaining 30% as a bounty.
A repeat attack and a compromised upgrade key
@VerusCoin took the second-largest loss of the day, around $7.5 million, when its Ethereum bridge was drained through the same vulnerability class that cost it $11.5 million in May. Crypto.news reported that security firm Blockaid described the two incidents as involving the same bridge contract, the same entry path, and the same bug class. The May attacker had returned most of the stolen funds, and the project redeployed liquidity back into the bridge on July 8, before any structural fix was confirmed. A different attacker then exploited the same unpatched flaw two weeks later. The stolen assets, including ETH, tBTC, USDC, USDT, and several other tokens, were converted into approximately 3,916 ETH and routed through Tornado Cash.
Bitcoin L2 @BSquaredNetwork lost $3.86 million after an attacker seized upgrade authority over its staking contract. B² Network has since suspended staking and pledged to make affected users whole.
The three exploits land during what has already been described as a punishing stretch for crypto security. Decrypt noted that DeFi has lost more than $840 million to hacks so far in 2026. None of Thursday's losses stemmed from broken cryptography or flawed contract logic. All three involved off-chain components: compromised signing keys, an unpatched bridge import path, and unauthorized admin access. As institutional capital continues moving on-chain, that distinction is growing harder to overlook.
Sources:CoinDesk: AFX Trade drained of $24 million after bridge keys compromisedCrypto.news: Verus Ethereum Bridge hacked again for $7.54M after May exploitDecrypt: AFX Trade drained of $24M, offers hacker 30% to return it