Multi-Chain Mayhem: Hackers Exploit Bitcoin and Ethereum Projects for $35M

A string of rapid-fire exploits has struck Verus, B² Network, and other cross-chain platforms, exposing a familiar but dangerous weakness in crypto systems: failures in control mechanisms rather than cryptography itself. In each case, attackers exploited compromised keys, privileged upgrade access, or flawed validation processes to siphon funds—without breaking the underlying encryption.

The incidents unfolded within roughly six hours, with at least three protocols breached and total losses exceeding $35 million, based on blockchain data reviewed by CoinDesk alongside security firms BlockAid and PeckShield.

What unites these attacks is a shared vulnerability beyond smart contract code. None involved cracked cryptography. Instead, they relied on logic flaws—where systems executed as intended but still enabled improper withdrawals—or on stolen credentials that granted attackers unauthorized control.

The breaches

AFX, a perpetuals exchange, suffered the largest loss at approximately $24.15 million through a bridge on Arbitrum. The Verus-Ethereum bridge followed, losing $7.54 million in its second exploit this year via the same flaw. B² Network, a Bitcoin scaling platform, lost $3.86 million from its staking contract.

The Verus case is particularly striking. Early Thursday, BlockAid detected an exploit on its Ethereum bridge that drained millions in ether, tokenized bitcoin, and various stablecoins.

Investigations revealed that the attacker reused the same contract pathway exploited in a May breach that resulted in $11.5 million in losses. The flaw allowed withdrawals on Ethereum that were not properly backed by assets on the Verus chain—effectively enabling real funds to be released against invalid claims.

Cross-chain bridges, which allow assets to move between otherwise incompatible blockchains, depend entirely on accurate verification of reserves. When that verification fails, the system becomes vulnerable to exploitation.

Following the earlier attack, most of the stolen funds were returned in exchange for a bounty. However, those recovered assets were later redeposited into the same bridge—only for it to be drained again within weeks.

The impact is reflected in Verus’s metrics. From nearly $100 million in total value locked at the start of 2025, the protocol now holds around $9 million, illustrating both direct losses and declining user confidence.

Repeated breaches do more than drain capital—they erode trust, driving users away and weakening the platform further.

B² Network’s exploit underscores a different but equally critical issue: administrative control. The project disclosed that attackers gained access to the upgrade authority of its staking contract, allowing them to alter its behavior.

Blockchain analysts tracked the stolen $3.86 million as it was sold, converted into ether and stablecoins, and moved off-platform. In response, B² paused staking operations and committed to reimbursing affected users.

These incidents reinforce a key point: smart contracts are only as secure as the keys and permissions that govern them. If those controls are compromised, attackers do not need to find code bugs—they can simply take over.

This pattern mirrors some of crypto’s largest historical breaches, including the Wormhole and Nomad bridge hacks of 2022, as well as KelpDAO’s $290 million loss earlier this year.

The threat landscape is also evolving. A recent OpenAI analysis showed that AI systems, under controlled conditions, were capable of chaining together stolen credentials and undisclosed software flaws to breach external servers—demonstrating increasingly sophisticated attack capabilities.

While these tests were conducted with reduced safeguards, they highlight how emerging technologies could make complex intrusions faster and more scalable.

Unlike traditional finance, crypto offers no safety net once funds are lost. There are no chargebacks or easy recovery mechanisms, making such breaches particularly severe.

Within just 24 hours, four platforms—Verus, B², AFX, and Balance—were compromised due to failures in trust and access controls, not broken encryption. As tools for identifying and exploiting these weaknesses continue to improve, the risks facing crypto infrastructure are only growing.

  • Related Posts

    Bitcoin Bulls Build $5B Options Fortress Around $70K-$72K Range

    Bitcoin options traders are signaling a bullish outlook, with a massive concentration of nearly $5 billion in open interest built around the $70,000 and $72,000 call strikes on Deribit. The…

    Continue reading
    Crypto Markets Stay Calm as Bitcoin Consolidates While Oil Nears $100

    Bitcoin remained near the $65,000 level on Friday as crypto markets moved higher despite a sharp increase in crude prices, with Brent oil approaching $100 per barrel amid ongoing geopolitical…

    Continue reading