Koinlytics

Three Bridges Lost $35M in Six Hours and Not One Was a Cryptography Failure

Aug 7, 2026ETHARBBTCsecuritybridgesexploitsdefirisk-management
AFX lost about $24.15 million through an Arbitrum bridge, Verus lost $7.54 million to the same bug class as a May hack, and B2 Network lost $3.86 million after an attacker seized its staking contract upgrade authority. All three were permission failures.

Three cross-chain protocols were drained of more than $35 million within a six-hour window. The perpetuals platform AFX lost roughly $24.15 million through a bridge on Arbitrum. The Verus Ethereum bridge lost about $7.54 million. B2 Network lost roughly $3.86 million.

Not one of these was a break in cryptography. Every single one was a failure of permissions, logic or key control.

The Three Failures

AFX, roughly $24.15 million

The largest of the three, drained through a bridge contract on Arbitrum. Bridge contracts hold pooled collateral backing every wrapped position on the destination chain, which makes them the highest-value single target in the entire cross-chain stack. Compromise one and you do not steal one user's funds, you steal the collateral backing everyone's.

Verus, roughly $7.54 million

The instructive one. Verus was exploited through the same contract path and the same bug class as a hack in May. The system was drained, the flaw was not fully resolved, funds were redeposited, and the attacker came back through the same door.

A repeat exploit through an identical vector is not bad luck. It means the post-incident response addressed the symptom rather than the root cause, and that users redeposited into a contract whose failure mode had been publicly demonstrated weeks earlier.

B2 Network, roughly $3.86 million

An attacker seized the upgrade authority on the staking contract. Upgradeable contracts exist so teams can patch bugs without migrating users. That same mechanism means whoever controls the upgrade key controls the contract, and by extension every asset it holds. The code did not fail. The key custody did.

The Pattern Across All Three

The common thread is that the blockchain worked exactly as designed in every case. Signatures verified. Consensus held. Hashes matched. The failures sat in the layer above:

This is consistent with the year as a whole. 2026 has recorded more than $1.2 billion in losses across 276 incidents. The largest single event, the Coldcard hardware wallet exploit now above $130 million, traces to a build configuration error in a 2021 firmware release that caused seed generation to fall back on a weak software random number generator. Also not a cryptographic break. A configuration mistake.

The cryptography has held for 17 years. What keeps failing is the software around it and the humans holding the keys. Audit reports that only check the math are checking the part that works.

What This Means for Bridged Positions

A bridged token is not the asset. It is a claim against a contract that promises to release the asset. That distinction is invisible in a wallet interface, where a bridged token displays with the same name, the same icon and the same dollar value as the native one.

The practical consequences:

What to Watch

If you hold wrapped or bridged assets across multiple chains, the useful exercise is enumerating them by which bridge holds the collateral, not by which chain shows the balance. Most people cannot answer that question about their own positions, and the moment it becomes urgent is the moment the answer stops being retrievable.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics