Security

$31.7M in 24 Hours: When DeFi's Foundations Crumble

2026-07-25

July 22 started like any other day in DeFi. It didn't end that way. Around 21:30 UTC, Blockaid watched $24.15 million in USDC vanish from AFX's bridge on Arbitrum. The culprit? Compromised validator hot keys. Someone had social-engineered their way into development systems, then propagated the damage through build and validator infrastructure until five validators' private keys were in hostile hands. That's quorum on Arbitrum. Game over.

The attacker swapped the loot into 12,467.5 ETH and disappeared. No freeze mechanism. No recovery lever. Just gone. Steven Goldfeder from Offchain Labs was quick to clarify that Arbitrum's own bridge wasn't touched—this was a third-party protocol's mess. Fair point. Doesn't help AFX much.

But wait, there's more.

Hours later on July 23, the Verus-Ethereum bridge got emptied again. Same bridge, roughly two months after a previous $11.58 million drain in May. The attacker abused the import path to trigger unbacked payouts on the Ethereum side. Seven point five-four million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD walked out the door. Here's the kicker: Blockaid confirmed it was the same bug class, same contract, same entry point. The flaw never got patched. Not in two months. Someone even redeposited funds on July 8, effectively reloading a bridge they knew was broken.

That's not incompetence. That's architectural negligence.

The third domino fell at B² Network. An attacker obtained upgrade authority over the staking contract and drained 8.59 million B2 tokens—about $3.86 million at the time. They sold the haul on BNB Chain for 5,409 BNB, worth roughly $3.01 million. The wallet that did this had held privileged access since 2025. Nobody noticed until the tokens were gone.

Three protocols. $31.69 million. One night.

What's truly alarming isn't that these systems got hacked. It's how they failed. In none of these attacks did cryptography break. The mathematical guarantees that underpin blockchain worked perfectly. Private keys stayed private when they were supposed to. Signatures verified correctly. Merkle proofs checked out. The systems failed because everything built on top of the cryptography was rotten.

AFX lost control of its validator infrastructure through social engineering. Verus released value without confirming that equivalent assets backed the transaction—a missing value check, not broken encryption. B² granted and forgot about administrative privileges.

Access control. Reserve validation. Governance hygiene. Three different failure modes. Three different architectural gaps.

Recovery is going nowhere fast. AFX hasn't recovered anything. Verus hasn't even issued a public statement, announced a patch, or laid out compensation. B² promised full restitution and offered manual staking exits through Discord, but as of July 24 the payouts weren't complete.

The fragility is now visible. Cross-chain infrastructure is held together by access controls that break under pressure, reserve mechanisms that don't actually reserve anything, and administrative processes that assume nobody's watching.

Someone was always watching.


Source & further reading:

Sources