DeFi hacks cost decentralized finance protocols $35.56 million on July 23, 2026, impacting three platforms in a six-hour span. 56 million in a single day, July 23, 2026, marking what some are calling a “Black Thursday” for the sector. Three separate platforms — AFX Trade, Verus Bridge, and B² Network — fell victim to exploits within a six-hour span, prompting fresh scrutiny of protocol security and the controversial practice of offering bounties to attackers.
These incidents highlight persistent vulnerabilities within cross-chain bridge technology and compromised administrative keys. The repeated nature of some attacks, alongside increasingly generous bounty offers, is raising questions about whether such incentives inadvertently foster a climate for further exploitation.
Protocols reel from substantial financial losses
The total sum of $35.56 million vanished across three distinct attacks. Each incident targeted different facets of DeFi infrastructure, from cross-chain bridges to staking contracts. This underscores the diverse threat landscape that developers face.
Verus Bridge suffers second major exploit
Verus Bridge, a protocol designed for secure transfers between the Verus blockchain and Ethereum, lost approximately $7.54 million. This marks its second exploit in about two months.
The latest breach involved the withdrawal of various assets, including ETH, tokenized Bitcoin (tBTC), USDC, USDT, EURC, MKR, and scrvUSD, from its reserves. Blockaid detected the exploit on the Verus-Ethereum bridge early Thursday. Just 15 days prior to this attack, Verus had redeposited the recovered money from a previous $11 million hack in May.
That earlier incident saw the attacker return most of the funds in exchange for a 25% bounty.
The latest exploit reused the same bridge contract and entry path as the May hack, leveraging an identical class of bug. Funds from this current hack are being laundered through Tornado Cash.
The Verus Bridge’s total value locked (TVL) plummeted from nearly $100 million at the start of 2025 to roughly $9 million as of Thursday, July 23, 2026, reflecting a sharp decline in user confidence. This latest attack again points to fundamental DeFi security concerns within bridge infrastructure.
AFX Trade’s Arbitrum bridge drained of $24.15M USDC
Another significant incident saw AFX Trade’s USDC custody bridge on Arbitrum drained of approximately $24.15 million. The attack targeted the AFX Trade protocol on Arbitrum, with some reports indicating detection on July 22.
Security firm BlockSec believes this was due to “malicious use of authorized validator keys” which were used to sign “the bridge’s 5-of-7 validator quorum.” Responding to the incident, AFX stated it had suspended bridge operations and is investigating the root cause. It also reassured users that its “AFX trading infrastructure, mainnet, and the Arbitrum network itself have not been compromised.”
AFX is offering a 30% bounty, worth $7.2 million, for the return of the remaining funds “as a white hat bounty.” PeckShieldAlert detected the attack, noting the exploiter swapped the stolen funds for 12,467.5 ETH. These funds were bridged from Arbitrum to Ethereum.
B² Network staking contract loses $3.86M
Finally, the BTC-for-AI-agents project B² Network, also known as BSquaredNetwork, suffered a loss of $3.86 million. Attackers drained 8.59 B2 tokens from its staking contract on the BNB Chain due to “unauthorized access to the staking contract’s upgrade authority.”
The B² Network team has promised affected B2 stakers will be fully compensated, and is offering a standard 10% bounty. The tokens were swapped for over 5,000 WBNB, then converted into 1,128 ETH. These funds were bridged using NEAR Intents. PeckShieldAlert also detected this attack, and the price of B2 dropped by over 15% after the exploit.
The controversial role of bounty payments
The repeated use of “white hat” bounties by compromised protocols has become a contentious topic within the crypto security community. While intended to encourage the return of stolen funds, critics argue these lucrative offers might paradoxically incentivize malicious actors.
AFX Trade’s 30% bounty offer, following Verus Bridge’s earlier 25% payout, represents a substantial reward for what is essentially grand theft. Some in the industry question the wisdom of such generous gestures.
These terms could blur the lines between ethical security research and outright exploitation, potentially luring skilled individuals to the “dark side” for illicit profit. The practice essentially legitimizes a portion of illicit gains, treating criminals as negotiating partners. This creates a challenging ethical landscape for legitimate security researchers.
These latest DeFi hacks, particularly the Verus Bridge’s second compromise, highlight a fundamental flaw. It’s the persistent reuse of vulnerable code or flawed logic, even after previous incidents. These vulnerabilities, whether logic flaws or compromised administrative keys, didn’t break core cryptography.
Instead, they leveraged weaknesses in implementation or operational security, which are often harder to detect and mitigate effectively. The rapid succession of these attacks, barely hours apart, underscores the urgency for the sector to move beyond reactive bounties towards proactive, robust security frameworks to maintain broader market confidence.
Outlook for DeFi security
The events of July 23, 2026, serve as a stark reminder of the ongoing security challenges inherent in the DeFi landscape. While bounties offer a short-term solution for fund recovery, their long-term impact on the ecosystem’s integrity and the moral compass of security professionals remains dubious.
Protocols must prioritize fundamental security enhancements, including rigorous and frequent audits, multi-layered defense mechanisms, and improved operational security practices, especially concerning privileged access and validator keys.
The industry needs to foster a culture where preventing exploits is more attractive and rewarding than capitalizing on them. This involves not only technological advancements but also a re-evaluation of how security talent is engaged and rewarded.
Without a concerted shift towards more preventative and less reactive measures, the DeFi space risks a cycle of repeated breaches and bounty negotiations, perpetually navigating a landscape where the lines between white hat and black hat are increasingly blurred.
