DeFi protocols lost more than $35 million in the past 24 hours after three separate attacks hit Verus bridge, AFX, and BSquared.
Protos framed the wave of incidents around a broader question: whether increasingly large post-hack “white hat” bounty offers are starting to create the wrong incentives. Security expert Taylor Monahan argued that these offers are, at best, insulting to legitimate security researchers and, at worst, may tempt technically capable people into criminal activity.
Verus bridge hit again
Verus bridge lost more than $7.5 million, just two months after a similar exploit drained $11 million.
According to the timeline cited in the report, Verus Bridge was hacked for 5,402.4 ETH on May 17. On May 21, the attacker returned 4,052.4 ETH after a 25% bounty offer. Then, on July 8, the recovered funds were placed back into the Verus bridge. Just 14 days later, in the early hours of Thursday, the bridge was exploited again.
A single transaction withdrew a mix of assets from the bridge, including tBTC, ETH, USDC, scrvUSD, MKR, USDT, and EURC, with the total value estimated at $7.5 million.
Blockchain auditor SlowMist said both the May exploit and the latest incident shared the same root cause: “flawed cross-chain import validation,” although the attack vectors were slightly different.
This time, the odds of recovery appear lower. The attacker has since deposited a total of 3,916 ETH, worth more than $6.6 million according to the article, into Tornado Cash.
The report also noted that the latest Verus exploit pushed the 2026 total for bridge hacks to $329 million.
AFX loses more than $24 million from Arbitrum bridge
Late Wednesday, AFX’s USDC custody bridge on Arbitrum was drained of more than $24 million.
Security firm BlockSec said the incident appeared to involve a “malicious use of authorized validator keys.” Those keys were used to sign what it described as the bridge’s 5-of-7 validator quorum.
AFX said it had suspended bridge operations and was “investigating the root cause.” The project added that its “AFX trading infrastructure, mainnet, and the Arbitrum network itself have not been compromised.”

AFX also put forward a 30% bounty offer. Based on the reported loss, that would be worth $7.2 million. In its public message, the project asked for 70% of the stolen assets to be returned to a specified address and said the responsible party could keep the remaining 30% “as a white hat bounty.”
Monahan again questioned the wisdom of that approach.
Another audit firm, Peckshield, said the exploiter had already swapped the funds for more than 12,000 ETH, worth about $24 million. The funds remain in the attacker’s Ethereum address, according to the report.
Since the beginning of last week, bridge exploits alone have accounted for at least $40 million in losses, Protos reported.
BSquared staking contract drained
BSquared, described in the article as a BTC-for-AI-agents project, was also hacked for almost $4 million due to “unauthorized access to the staking contract’s upgrade authority.”
The team said affected B2 stakers would be fully compensated and offered a standard 10% bounty.
Blockchain investigator Specter said 8.591 million B2 tokens worth $3.86 million were drained on BNB Chain. The tokens were then swapped for 5,409 WBNB worth $3.11 million, bridged to Ethereum, and are now being moved to privacy protocol Zcash through NEAR Intents.
The article also said the contract was drained of $3.86 million in B2 tokens on BNB Chain. Specter added that the privileged role had been active for more than a year, which may point to an inside job.
Bounty offers face renewed scrutiny
The latest string of attacks has put post-exploit settlement offers back under the spotlight. Verus previously recovered part of its stolen funds after offering a 25% bounty, and AFX is now offering 30% after losing more than $24 million.
Protos did not present a definitive answer on whether these offers are encouraging more attacks. What the report did show is that several projects, auditors, and on-chain investigators are now dealing with a growing number of bridge and contract exploits while also debating whether generous bounty terms are helping recover assets or creating fresh incentives for attackers.

