Crypto Fraud Watch: A $24M Bridge Drain, a Repeat Verus Hack, and a Stablecoin Wiped Out Overnight
The last 48 hours have been brutal for crypto security. Four separate protocols were drained in a single day, and not one of them fell to broken cryptography. Instead, attackers walked through the side doors that keep failing across the industry: compromised keys, hijacked upgrade permissions, and manipulated price feeds. Here is what happened, and what it means legally for anyone holding, building, or investing in digital assets.
A $24 Million Drain on AFX Trade
On July 22 at roughly 21:30 UTC, AFX Trade, a decentralized perpetuals exchange on Arbitrum that settles in USDC, was drained of about $24.15 million. Security firm Blockaid confirmed the smart contract itself worked exactly as designed. The problem was the private keys behind it: an attacker obtained five of the bridge's hot-validator signatures, cleared the roughly two-thirds quorum required to authorize a withdrawal, and moved 24,150,000 USDC to their own wallet after a 200-second dispute window closed.
The stolen funds were bridged to Ethereum and swapped for about 12,467 ETH, now sitting in a single wallet. Notably, the $24 million represented nearly the entire value locked in the protocol, meaning the vault was emptied at the moment it was fullest. Arbitrum's native bridge was not affected; this was a contained failure of a third-party protocol running on top of it. For investors, the distinction matters little when their deposits are gone.
Verus Gets Hit Twice Through the Same Flaw
Hours later, the Verus-Ethereum bridge was drained of roughly $7.54 million in ETH, tokenized bitcoin, and a spread of stablecoins. The most damning detail: this was the same class of bug that cost the bridge $11.5 million back in May. After that earlier attack, the hacker returned most of the funds for a bounty, and Verus redeposited the recovered money into the same bridge on July 8. Two weeks later, it was drained again. The bridge released real assets against claims that were never properly backed, and a protocol that held nearly $100 million in early 2025 now holds about $9 million.
From a legal standpoint, a repeat exploit through a known vulnerability raises hard questions about operator liability and disclosure. Redepositing user assets into an unpatched system is precisely the kind of decision that plaintiffs' attorneys and regulators scrutinize after the fact.
B² and Balance: Hijacked Permissions and a Rigged Oracle
The same 24-hour window claimed two more victims. B², a Bitcoin scaling network, lost about $3.86 million after an attacker seized the upgrade authority of its token staking contract, then sold the tokens and converted them to ether and stablecoins. B² says it contained the incident, suspended staking, and will fully compensate affected users. Separately, the stablecoin Balance Coin collapsed more than 99% to about $0.0014 after an attacker manipulated its median oracle, fed the lending system an artificially low bitcoin price, and triggered unwarranted liquidations, draining roughly $912,000 from governance entity 42DAO and minting 4.5 million BLC from nothing across two attacks two hours apart.
The common thread is unmistakable: none of these losses came from cracked encryption. Each was an off-chain control failure, a compromised key, a stolen permission, or an unprotected price feed. That pattern shifts the legal conversation from "was the code audited" to "who controlled the keys, and did they exercise reasonable care."
How to Protect Yourself
If you hold assets in DeFi protocols, treat bridges and newer perpetuals venues as high-risk. Withdraw idle funds rather than leaving deposits parked in a single vault, favor protocols with hardware-secured or multi-party key custody and transparent post-incident disclosures, and walk away from any project that redeposits into a system after a known exploit. For stablecoins, understand how the peg is maintained and whether the price oracle has liquidation delays and sanity checks. Diversify custody so no single compromise can wipe you out.
If you have already been hit, act fast. On-chain funds can sometimes be traced and frozen at the exchange level if you move quickly, and preserving transaction hashes, wallet addresses, and timestamps is critical to any recovery effort or law enforcement referral. Depending on the facts, victims may have claims against protocol operators for negligence or misrepresentation, and businesses that suffered losses may face their own regulatory reporting duties. An attorney experienced in crypto disputes can help you evaluate recovery options and preserve your rights before evidence disappears.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.