Three Crypto Hacks in 24 Hours Drain Over $35M from Protocols

iconCryptoBriefing
Share
AI summary iconSummary
On-chain news reveals three major crypto hacks in 24 hours, draining over $35.5 million from protocols. AFX (Arbitrum), BSquaredNetwork (BNB Chain), and Verus (Ethereum) were targeted, with bridge vulnerabilities exploited. AFX lost $24.15 million in USDC, BSquaredNetwork $3.86 million in B2 tokens, and Verus $7.55 million. PeckShield identified the attacks. Crypto news reports 207 security incidents in H1 2026, with Q2 losses hitting $764 million.

Three separate crypto protocols got carved up within a single 24-hour window, with combined losses topping $35.5 million. The victims span three different chains, three different attack vectors, and one very familiar story: bridges remain the soft underbelly of decentralized finance.

The largest hit landed on AFX, an Arbitrum-based protocol that lost approximately $24.15 million in USDC through a bridge exploit on July 22. BSquaredNetwork on BNB Chain saw $3.86 million in B2 tokens drained. And the Verus cross-chain bridge on Ethereum hemorrhaged $7.55 million, a wound made worse by the fact that Verus had already been exploited for roughly $11.58 million back in May.

How each exploit played out

The AFX breach was the headliner. Attackers siphoned $24.15 million in USDC from the protocol’s bridge infrastructure on Arbitrum, then moved the funds to Ethereum and swapped them into around 12,467.5 ETH.

BSquaredNetwork’s exploit was smaller in dollar terms but arguably messier for holders. The $3.86 million in stolen B2 tokens were exchanged for more than 5,000 WBNB, which were then converted into roughly 1,128 ETH. The sell pressure from the dump sent B2’s price cratering more than 15%.

Advertisement

Then there’s Verus. The $7.55 million loss on July 23 is concerning on its own, but context makes it worse. This is the same cross-chain bridge that suffered an approximately $11.58 million exploit in May 2026. That means Verus has lost north of $19 million in roughly two months to what appear to be related security vulnerabilities.

PeckShield, the blockchain security firm, was among the first to flag each incident on-chain.

A brutal quarter for crypto security

These three exploits didn’t happen in a vacuum. According to data from TRM Labs, the first half of 2026 saw a record 207 security incidents. Q2 alone accounted for $764 million stolen across 67 separate incidents, with operational weaknesses cited as a primary attack surface.

Vitalik Buterin flagged bridge security risks as far back as 2022, arguing that multi-chain futures would not be secured by the same trust assumptions as single-chain applications.

What this means for investors

B2’s 15%-plus price drop is the most direct example of immediate market impact. When three protocols get exploited in a single day, it puts a chill on risk appetite across the broader DeFi ecosystem.

The $764 million stolen in Q2 2026 alone represents real capital permanently removed from the ecosystem. That’s money that funded development, provided liquidity, and backed lending markets.

For individual investors, the Verus situation is particularly instructive: a protocol that gets exploited once and doesn’t fully remediate its vulnerabilities before getting hit again is broadcasting something important about its security posture. The first hack might be bad luck. The second one is information.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.