Blockchain AcademicsBlockchain Academics
Three Protocols Lose $35M in 24-Hour Attack Spree

Three Protocols Lose $35M in 24-Hour Attack Spree

Three cryptocurrency protocols were drained of $35 million in a 24-hour attack sequence. Verus Protocol suffered its second exploit in two months, with investigators identifying striking technical similarities between incidents, raising questions about inadequate remediation and systemic bridge...

Hadi GhadbanEdited by Wael RajabJuly 23, 20263 min read
Share

Three Protocols Lose $35M in 24-Hour Attack Spree

Three cryptocurrency protocols linked to Bitcoin and Ethereum were drained of a combined $35 million on Wednesday in a sequence of exploits spaced hours apart, raising immediate questions about whether the attacks were coordinated or the work of separate actors racing to capitalize on disclosed vulnerabilities.

The incidents unfolded across a single 24-hour window, a clustering pattern that security researchers have historically associated with either organized threat actors running parallel campaigns or copycat attackers monitoring public mempool and on-chain data for replication opportunities. No single group has claimed responsibility as of publication.

Verus Protocol sits at the center of the most alarming finding. The cross-chain bridge suffered its second exploit in approximately two months, and investigators identified striking technical similarities between the two incidents, a detail that points directly to inadequate remediation after the first breach. When a protocol patches a vulnerability incompletely and an attacker returns to the same attack surface, it typically signals one of two failures: the original audit missed the root cause, or the fix introduced a related flaw. Either scenario reflects poorly on the post-incident response.

Bridge infrastructure has long been the softest target in cross-chain architecture. By design, bridges hold large pools of locked assets on one chain while issuing wrapped representations on another, creating concentrated custodial risk that smart contract bugs can unlock in a single transaction. The Ronin bridge lost $625 million in March 2022. Poly Network was drained of $611 million in August 2021. Nomad fell for $190 million in August 2022. Against that backdrop, a $35 million loss spread across three protocols in one day is numerically smaller, but the recurrence pattern at Verus and the multi-protocol scope of Wednesday's events suggest the threat environment has not materially improved.

The involvement of both Bitcoin-linked and Ethereum-linked protocols in the same 24-hour window is notable for a structural reason. Bitcoin and Ethereum operate on separate consensus layers with distinct security models, so simultaneous targeting of protocols bridging into both networks is less likely to reflect a single shared vulnerability in the underlying chains and more likely to reflect opportunistic scanning of bridge contract code across the broader DeFi landscape. The core networks themselves remained fully operational throughout.

Periods of concentrated bridge attacks, including the DeFi summer of 2020 and the 2022-2023 wave that claimed Ronin, Nomad, and several smaller protocols, have historically preceded broader risk-off sentiment in DeFi tokens and a temporary compression in total value locked across bridge-dependent applications. Whether Wednesday's events trigger a similar repricing depends largely on whether investigators confirm coordination or rule it out in the coming days.

For Verus specifically, the path forward is narrow. A second exploit with similar technical fingerprints to the first makes a compelling case for a full third-party audit by a firm that was not involved in any prior review, combined with a public post-mortem that details exactly what the first patch did and did not address. Without that transparency, user confidence in the bridge will remain structurally impaired regardless of any technical fixes deployed.

The broader takeaway for protocol teams is one the industry has rehearsed before but not yet internalized at scale: an audit after an exploit is not the same as a remediation. Identifying a vulnerability, patching the specific line of code, and shipping a fix under time pressure frequently leaves adjacent attack surfaces open. Wednesday's events are the latest data point in that recurring lesson.

Discussion

Loading comments...