Three Bridges, Six Hours, $35 Million Gone: What AFX, Verus and B2 Just Taught Perp Traders
In a single six-hour window, AFX Trade lost about $24.15 million, Verus's Ethereum bridge was drained of $7.54 million through the same bug class as its May hack, and B2 Network lost $3.86 million to a seized upgrade key. None of the attacks broke cryptography. All of them broke trust, and that is the part perp traders should price in.
$ Stop reading delayed data. Compare live order book depth across 5 exchanges right now.
Launch Free Terminal →More than $35 million left three crypto protocols in roughly six hours on July 22 and 23. PeckShield flagged an attack on Arbitrum-based AFX Trade with estimated losses around $24.15 million in USDC. Blockaid then detected a drain of about $7.54 million from the Verus-Ethereum bridge. Hours later, B2 Network confirmed an attacker had seized the upgrade authority of its staking contract and sold roughly $3.86 million in B2 tokens. Three different protocols, three different attack paths, one shared lesson: the weak layer in crypto is not the cryptography, it is who controls asset movement and contract permissions.
The Verus Repeat: Same Bridge, Same Bug, Two Months Apart
The Verus incident is the most damning of the three because it already happened once. In May the same bridge lost roughly $11.58 million. According to Blockaid, the July attack used the same bridge contract, the same entry path, and the same bug class. The attacker used a small amount of VRSC on the Verus side to trigger unbacked payouts on Ethereum, walking away with ether, tokenized bitcoin, and a spread of stablecoins including USDC, USDT and EURC.
What makes it worse is the recovery path. On-chain records show Verus redeposited recovered assets into the same bridge on July 8. About two weeks later, the bridge was drained again. The market has been pricing this trust decay for a while: Verus started 2025 with close to $100 million in total value locked per DefiLlama. As of Thursday it holds about $9 million.
B2 Network: When the Admin Key Is the Exploit
The B2 attack was not a smart contract bug at all. The attacker gained the upgrade authority of the token staking contract, the administrative permission that decides how the contract behaves. From there, roughly 8.59 million B2 tokens worth $3.86 million were drained, swapped for about 5,400 WBNB, converted into ETH, and routed toward Zcash through NEAR Intents. B2's token dropped over 15 percent within hours as the new supply hit the market.
This is the category of failure that security researchers keep flagging: compromised keys and permissions, not broken math. A perfect contract with a stolen admin key is just a vault with the door propped open.
What Bridge Risk Means for Perp Traders in 2026
If you trade perps, this matters beyond the headlines. Bridge exploits are supply shocks: stolen tokens get dumped immediately, and the selling is mechanical, not sentimental. B2's 15 percent drop in hours is the template. When an exploit alert hits, the orderflow tells you within minutes whether the market is absorbing the dump or folding under it. Watching CVD and orderbook depth on the affected pair beats refreshing a news feed.
There is also a structural read. Attackers went after the layers where assets are actually held or transferred: a custody bridge at AFX, cross-chain validation at Verus, contract permissions at B2. Venues that minimize those layers carry structurally less of this risk, which is part of why perp flow keeps consolidating toward platforms with native infrastructure rather than sprawling bridge dependencies.
On Buildix you can watch the real-time reaction across 530 plus Hyperliquid pairs when events like this hit: liquidations, CVD flips, and orderbook pressure on any affected asset, starting from the free screener at buildix.trade/screener. The tokens change, the bug classes repeat. The traders who did best this week were not the ones who predicted the hacks. They were the ones watching the tape when the supply arrived.