Several encrypted cross-chain protocols were compromised in quick succession. According to CoinDesk's analysis of on-chain data and information from security agencies such as BlockAid and PeckShield, at least three bridging or cross-chain systems were hacked within six hours, resulting in a total loss of over $35 million.
Verus Bridge is being used again.
Verus's Ethereum bridge suffered a loss of approximately $7.54 million. Security agencies stated that the attackers used the same contract path and similar vulnerability as in the May incident, triggering withdrawals on the Ethereum side that were not adequately backed by assets, resulting in the transfer of reserves from the bridge.
Cross-chain bridges operate by locking real assets on one blockchain and issuing corresponding credentials on another. If the verification process goes awry, the system could potentially disburse loans without sufficient collateral. Verus's problem stemmed from this very issue.
In May of this year, Verus lost approximately $11.5 million due to a similar issue. The attacker subsequently returned most of the funds in exchange for a bounty. On-chain records show that the project team re-deposited the recovered funds into the same bridging system on July 8, only to have them emptied again two weeks later.
According to DefiLlama data, Verus's total locked value was close to $100 million at the beginning of 2025, but had dropped to approximately $9 million by this Thursday. Following the latest attack, the platform's funds have declined further.
B² Network upgrade privileges were revoked.
Another confirmed incident occurred at B² Network. This project positions itself as a Bitcoin scaling network, aiming to reduce Bitcoin transaction costs and increase processing speed. The project stated on Thursday during Asian trading hours that attackers gained unauthorized access to upgrade their token staking contract.
Lookonchain's tracking shows that approximately $3.86 million worth of B2 tokens were sold off, subsequently converted into Ethereum and stablecoins, and then transferred. B² Network stated that the incident has been contained, the staking function has been suspended, and affected users will receive full compensation.
The issues are concentrated on permissions and authentication.
These types of incidents do not necessarily stem from underlying cryptographic failures. More commonly, attackers gain critical access or control keys and then directly rewrite contract behavior or bypass existing restrictions to transfer assets.

CoinDesk noted that in this round of attacks, teams such as Verus, B², AFX, and Balance were attacked, and the common problem exposed was not that the encryption algorithm was cracked, but that bridging verification, upgrade permissions, and key control were compromised.
The article also mentions that an internal test disclosed by OpenAI this week showed that an AI model with relaxed security restrictions was able to combine stolen credentials and unknown software vulnerabilities to breach the test environment and compromise the server. While this does not equate to the system launching an attack autonomously, it demonstrates that automated, multi-step intrusion capabilities are increasing.

For cryptographic protocols, this type of risk is even more difficult to bear. When traditional industries are hacked, they can often mitigate their losses by freezing, revoking, or recovering funds; however, once an on-chain contract is emptied, the funds are usually difficult to recover, and the protocol's reputation and user deposits will also be lost.












