Four crypto protocols tied to the Bitcoin and Ethereum ecosystems were attacked within hours on July 23, with combined losses exceeding $35 million, according to CoinDesk. Security firm BlockAid, blockchain security company PeckShield and on-chain analytics firm Lookonchain tracked the related fund movements.
AFX Trade records the largest loss at about $24 million
The biggest hit came at AFX Trade, a derivatives protocol built on Arbitrum. BlockAid said the attacker obtained the private key for the protocol’s cross-chain bridge and then transferred out roughly $24 million in assets.
The report said that once a bridge private key is compromised, control of the treasury is effectively exposed, leaving little room to stop the movement of user funds in real time.
This was not the first case involving a leaked key. In May this year, Stake DAO was also attacked after a deployer private key was compromised, allowing the attacker to mint 5.4 trillion vsdCRV on Arbitrum. That case exposed weaknesses in key management across cross-chain infrastructure.
Verus hit again through an older vulnerability
Verus, an Ethereum cross-chain bridge protocol, lost about $7.54 million. BlockAid said the attacker exploited a logic flaw in the bridge import path, allowing the system to pay out assets that were not actually backed by collateral.
The stolen tokens included ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.
It was the second time the same type of flaw had been exploited. Verus lost about $11.5 million from the same contract weakness in May. After the funds were put back on July 8, they were drained again roughly two weeks later.
B² Network and Balance also attacked
B² Network, a Bitcoin layer-2 network, lost about $3.86 million. Lookonchain said the attacker gained upgrade authority over the network’s token staking contract and swapped B2 tokens into ETH and stablecoins.
B² Network later suspended its staking function and said affected users would be fully compensated.
Another protocol, Balance, was also attacked and lost about $1 million. The attacker drained its bitcoin vault, causing the price of the protocol’s stablecoin to drop by roughly 99%.
The four incidents broke out in the same window of time. The disclosed attack paths point to cross-chain bridge private keys, bridge logic flaws and contract upgrade privileges.

