Three crypto hacks in 24 hours drain over $35 million from protocols

Three crypto hacks in 24 hours drain over $35 million from protocols

Bridge exploits on Arbitrum, BNB Chain, and Ethereum highlight persistent vulnerabilities as 2026's hack tally keeps climbing

Three separate crypto protocols got carved up within a single 24-hour window, with combined losses topping $35.5 million. The victims span three different chains, three different attack vectors, and one very familiar story: bridges remain the soft underbelly of decentralized finance.

The largest hit landed on AFX, an Arbitrum-based protocol that lost approximately $24.15 million in USDC through a bridge exploit on July 22. BSquaredNetwork on BNB Chain saw $3.86 million in B2 tokens drained. And the Verus cross-chain bridge on Ethereum hemorrhaged $7.55 million, a wound made worse by the fact that Verus had already been exploited for roughly $11.58 million back in May.

How each exploit played out

The AFX breach was the headliner. Attackers siphoned $24.15 million in USDC from the protocol’s bridge infrastructure on Arbitrum, then moved the funds to Ethereum and swapped them into around 12,467.5 ETH.

BSquaredNetwork’s exploit was smaller in dollar terms but arguably messier for holders. The $3.86 million in stolen B2 tokens were exchanged for more than 5,000 WBNB, which were then converted into roughly 1,128 ETH. The sell pressure from the dump sent B2’s price cratering more than 15%.

Advertisement

Then there’s Verus. The $7.55 million loss on July 23 is concerning on its own, but context makes it worse. This is the same cross-chain bridge that suffered an approximately $11.58 million exploit in May 2026. That means Verus has lost north of $19 million in roughly two months to what appear to be related security vulnerabilities.

PeckShield, the blockchain security firm, was among the first to flag each incident on-chain.

A brutal quarter for crypto security

These three exploits didn’t happen in a vacuum. According to data from TRM Labs, the first half of 2026 saw a record 207 security incidents. Q2 alone accounted for $764 million stolen across 67 separate incidents, with operational weaknesses cited as a primary attack surface.

Vitalik Buterin flagged bridge security risks as far back as 2022, arguing that multi-chain futures would not be secured by the same trust assumptions as single-chain applications.

What this means for investors

B2’s 15%-plus price drop is the most direct example of immediate market impact. When three protocols get exploited in a single day, it puts a chill on risk appetite across the broader DeFi ecosystem.

The $764 million stolen in Q2 2026 alone represents real capital permanently removed from the ecosystem. That’s money that funded development, provided liquidity, and backed lending markets.

For individual investors, the Verus situation is particularly instructive: a protocol that gets exploited once and doesn’t fully remediate its vulnerabilities before getting hit again is broadcasting something important about its security posture. The first hack might be bad luck. The second one is information.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Three crypto hacks in 24 hours drain over $35 million from protocols

Three crypto hacks in 24 hours drain over $35 million from protocols

Bridge exploits on Arbitrum, BNB Chain, and Ethereum highlight persistent vulnerabilities as 2026's hack tally keeps climbing

Three separate crypto protocols got carved up within a single 24-hour window, with combined losses topping $35.5 million. The victims span three different chains, three different attack vectors, and one very familiar story: bridges remain the soft underbelly of decentralized finance.

The largest hit landed on AFX, an Arbitrum-based protocol that lost approximately $24.15 million in USDC through a bridge exploit on July 22. BSquaredNetwork on BNB Chain saw $3.86 million in B2 tokens drained. And the Verus cross-chain bridge on Ethereum hemorrhaged $7.55 million, a wound made worse by the fact that Verus had already been exploited for roughly $11.58 million back in May.

How each exploit played out

The AFX breach was the headliner. Attackers siphoned $24.15 million in USDC from the protocol’s bridge infrastructure on Arbitrum, then moved the funds to Ethereum and swapped them into around 12,467.5 ETH.

BSquaredNetwork’s exploit was smaller in dollar terms but arguably messier for holders. The $3.86 million in stolen B2 tokens were exchanged for more than 5,000 WBNB, which were then converted into roughly 1,128 ETH. The sell pressure from the dump sent B2’s price cratering more than 15%.

Advertisement

Then there’s Verus. The $7.55 million loss on July 23 is concerning on its own, but context makes it worse. This is the same cross-chain bridge that suffered an approximately $11.58 million exploit in May 2026. That means Verus has lost north of $19 million in roughly two months to what appear to be related security vulnerabilities.

PeckShield, the blockchain security firm, was among the first to flag each incident on-chain.

A brutal quarter for crypto security

These three exploits didn’t happen in a vacuum. According to data from TRM Labs, the first half of 2026 saw a record 207 security incidents. Q2 alone accounted for $764 million stolen across 67 separate incidents, with operational weaknesses cited as a primary attack surface.

Vitalik Buterin flagged bridge security risks as far back as 2022, arguing that multi-chain futures would not be secured by the same trust assumptions as single-chain applications.

What this means for investors

B2’s 15%-plus price drop is the most direct example of immediate market impact. When three protocols get exploited in a single day, it puts a chill on risk appetite across the broader DeFi ecosystem.

The $764 million stolen in Q2 2026 alone represents real capital permanently removed from the ecosystem. That’s money that funded development, provided liquidity, and backed lending markets.

For individual investors, the Verus situation is particularly instructive: a protocol that gets exploited once and doesn’t fully remediate its vulnerabilities before getting hit again is broadcasting something important about its security posture. The first hack might be bad luck. The second one is information.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.