Security Breaches Hit DeFi Protocols with $31 Million in Losses
The decentralized finance ecosystem recently faced a series of significant security breaches, resulting in combined losses of approximately $31.69 million within a single 24-hour window. These incidents, involving the AFX protocol, the Verus-Ethereum bridge, and B² Network, highlight the ongoing vulnerabilities in cross-chain infrastructure and the critical importance of securing administrative controls.
The Multi-Million Dollar Exploits of AFX and Verus
The most substantial loss occurred at AFX, a decentralized trading protocol on Arbitrum, where an exploit led to the unauthorized withdrawal of 24.15 million USDC. Preliminary investigations suggest the breach was the result of a coordinated social engineering attack that compromised development environments before escalating into validator systems. Shortly after, the Verus-Ethereum bridge suffered a separate failure, releasing over $7.5 million in unbacked assets due to flawed cross-chain import-validation logic. While AFX is currently working on fund recovery and remediation plans, the Verus incident underscores a recurring class of validation errors that continue to plague bridge architectures.
B² Network Breach and the Risks of Administrative Authority
In a separate security event, the B² Network was forced to suspend token staking following unauthorized access to its contract upgrade authority. Although the network has not disclosed a specific loss amount, the breach prompted a full security review and the implementation of a manual unstaking process via Discord for concerned users. This incident, along with the bridge exploits, exposes the fragility of controls that exist outside of a base-chain's primary consensus mechanism. The collective failures emphasize that protecting infrastructure, verifying economic backing in real-time, and securing upgrade permissions are essential for maintaining user trust in the DeFi space.