Sun, 6 September 2026
Security23 July 2026

Hackers take 35 million dollars from four protocols

Within hours, four crypto protocols were drained of more than 35 million dollars combined. No broken cryptography, but weak keys and logic flaws — and reportedly, attackers are now using AI for multi-step intrusions.

Article image for: Hackers take 35 million dollars from four protocols

The crypto world was rattled this week by a string of attacks that followed one another within hours. Four protocols lost more than 35 million dollars (roughly €30.6 million) between them. Strikingly, not a single attack broke the underlying cryptography. These were logic flaws and stolen administrative keys — the weak links of DeFi.

Four attacks, tens of millions

The biggest blow hit AFX on Arbitrum: 24.15 million dollars (roughly €21.1 million) vanished through compromised bridge keys. Verus, an Ethereum bridge, lost 7.54 million dollars (roughly €6.6 million) to a flaw in its bridge contract. B² Network lost 3.86 million dollars (roughly €3.4 million) when an attacker seized the upgrade authority of its staking contract, and the stablecoin Balance lost 1 million dollars (roughly €875,000) via a bitcoin-vault exploit.

Verus: the same flaw, twice

Verus stings most. The exact same vulnerability was already exploited in May, for 11.5 million dollars (roughly €10.1 million). The team recovered and redeposited the funds on 8 July — after which the attackers struck again two weeks later with unbacked payouts on the Ethereum side. The protocol's total value locked collapsed from around 100 million dollars (roughly €87.5 million) in early 2025 to barely 9 million dollars (roughly €7.9 million) now.

No cracked cryptography — but weak links

The common thread: it was not the maths behind crypto that failed, but the human and organizational layer around it. Bridges that move assets between blockchains, and administrative keys that can alter contracts, remain the most vulnerable parts of the ecosystem.

The new factor: AI

There is a worrying development in play. Reportedly, OpenAI disclosed that its AI models were able to carry out multi-step intrusion work. That suggests attackers are getting ever more powerful tools to find and exploit exactly these weak spots — faster and at greater scale than before.

What does it mean for Europe?

Security knows no borders: European DeFi users face exactly the same risks. And note — MiCA regulates exchanges and stablecoins, but not the DeFi protocols and self-custody where these attacks took place. The protection you get from a licensed provider does not apply here.

Caveat: it's the edges, not the core

Keep a level head: the base layers of bitcoin and ethereum themselves were not hacked. This is about bridges, young protocols and administrative keys. The practical lesson stays the same: be careful with bridges and new DeFi projects, spread your risk, and keep large amounts preferably in self-custody or with a regulated party.

Sources: CoinDesk. Last checked: 23 July 2026.

#hack#defi#security#bridge#ai