Three DeFi Exploits Expose Growing Security Weaknesses

Three decentralized finance protocols were exploited within hours of each other, exposing weaknesses across validator infrastructure, cross-chain bridge architecture and privileged administrative controls in one of the sector's busiest security incidents this year.
Summary:
- Three DeFi exploits drained more than $35.5 million within hours.
- The incidents targeted validator infrastructure, cross-chain bridges and administrative controls.
- The attacks highlight how DeFi security risks are expanding beyond smart contract vulnerabilities.
Three Protocols, Three Different Attack Paths
Although the incidents occurred independently, each exploited a different layer of protocol infrastructure rather than a shared software vulnerability.
The losses were distributed as follows:
- AFX Trade: $24.15 million
- Verus: $7.55 million
- B² Network: $3.86 million
The attacks demonstrate that security risks in decentralized finance are extending beyond smart contract code into validator operations, bridge design and privileged access management.
AFX Trade Hit Through Validator Infrastructure
AFX Trade suffered the largest loss after attackers compromised the signing infrastructure supporting the protocol’s USDC custody bridge on Arbitrum.
According to blockchain security researchers, the bridge contracts executed exactly as designed. Instead, attackers obtained control of five hot-validator signing keys – the minimum threshold required to authorize withdrawals—and used them to approve fraudulent transfers.
Following the exploit, the stolen USDC was bridged to Ethereum and exchanged for approximately 12,467 ETH. The protocol suspended bridge operations while investigating the incident.

Security firms and Offchain Labs said Arbitrum’s native bridge was not affected.
Verus Exploit Exposed Cross-Chain Validation Weakness
According to data from etherscan.io, the $7.55 million exploit targeting the Verus Ethereum Bridge stemmed from a flaw in how the protocol verified incoming cross-chain transfers.
Researchers from Blockaid said the attacker created a forged import payload that successfully passed cryptographic verification despite representing virtually no economic value on the originating chain. By exploiting the missing validation step, the attacker triggered unbacked payouts of assets including ETH, tBTC and USDC on Ethereum.
Exploit tx:
https://t.co/XPN25gbZp4
Target bridge contract: 0x71518580f36feceffe0721f06ba4703218cd7f63Funds were transferred from the bridge to attacker-controlled wallet:
0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54— Blockaid (@blockaid_) July 23, 2026
The incident follows a similar exploit disclosed in May that relied on the same underlying failure mode, raising renewed questions about economic validation within cross-chain bridge designs.
B² Network Contained Administrative Compromise
Unlike the other two attacks, the breach affecting B² Network did not exploit transaction validation or bridge infrastructure.
Instead, attackers gained unauthorized control of the staking contract’s upgrade authority, allowing changes to privileged contract functions. After detecting the activity, the project suspended staking while security teams investigated the incident.
READ MORE: Allbridge Halts Core Bridge After Flash Loan Attack
The protocol later said the compromise had been contained, security reviews were completed and no additional impact on protocol funds is expected.
Attackers Continue to Expand Their Playbook
The three exploits illustrate how attack strategies in decentralized finance continue to evolve beyond vulnerabilities in smart contract logic alone.
Rather than relying on coding flaws, attackers increasingly target operational components that sit around blockchain applications, including validator key management, cross-chain settlement mechanisms and privileged administrative controls. The incidents reinforce a broader shift in DeFi security, where protecting off-chain infrastructure and governance systems has become as critical as auditing on-chain code.
The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.











