Last week had over $53 million in onchain losses, with 10 major incidents spanning key management, signer/validator control, upgrade authority, and more
AFX (Anti-Fragile Exchange): $24.15M USDC. AFX is a Layer 1 chain running a perpetuals exchange with an onchain orderbook. Compromised validator hot keys reportedly met the quorum with enough signatures to clear the threshold. AFX suspended the bridge and said trading infrastructure and mainnet were untouched; a 70% white-hat offer went unanswered.
Triple-A: estimated $9.7M to $11.8M. Triple-A is a Singapore payments processor that lets merchants accept crypto and get paid in fiat. Attackers took control of operational and treasury wallets across at least four chains. Triple-A says client funds weren't touched, and the Singapore Police Force is involved.
VerusCoin Ethereum Bridge: $7.54M. VerusCoin is a blockchain that lets people launch their own interoperable chains. This is the bridge’s second loss in two months, after the attacker abused submitImports to trigger Ethereum-side payouts unbacked on the Verus source chain.
@blockaid_ calls it the same entry point and bug class as the $11.58M May loss.
Wanchain Cardano-BNB Bridge / NIGHT: $9M to $13M (depending on NIGHT's price, 515.2M taken in nine minutes). Wanchain operates cross-chain bridges. NIGHT is the token of Midnight, a privacy sidechain on Cardano. BlockSec's early read blames non-injective signed-message encoding in the Cardano-side TreasuryCheck validator, which let an approval for ~3,110 NIGHT on BNB Chain be reused to pull 203M. Wanchain took the bridge offline and acknowledged unauthorised withdrawals, the Midnight Foundation called it contained, and exchanges added precautions.
B² Network B2 staking: $3.86M (~$3.01M to $3.11M realised after ~$850K of slippage). B² Network is a Bitcoin Layer 2 and a staking service on BNB Chain. The draining address had held the staking contract's upgrade authority since 2025 and only lost it after the transfer, so this was likely a compromised or insider key rather than a seizure, though B² hasn't disclosed which. B² suspended staking, promised full compensation, and offered the hacker a white-hat bounty.
WEMIX: $5.22M (only ~$724K realised as the token collapsed from $1 to ~$0.0008). The attacker compromised owner authority on a WEMIX$-related contract (WEMIX is the blockchain arm of Korean game publisher Wemade), and minted 5.2M tokens outside DIOS, the stabiliser that only mints against incoming USDC, so the new supply had no reserve behind it. WEMIX suspended bridges, paused the WEMIX$ Module and PNIX DEX, withdrew foundation liquidity, requested exchange and issuer freezes, and has a contract-wide audit underway.
42DAO / Balance Protocol: $914K (plus ~$3.5M of nominal BLC erased as the token fell from $0.9954 to ~$0.0014). 42DAO is a MakerDAO fork on BNB Chain, critically missing the original’s Oracle Security Module. The attacker manipulated the BTCB feed through the Spotter/VAT liquidation path, which lacked TWAP, bounds, floor, drawdown and delay controls.
Lien Finance: $542K USDC. An attacker exploited this options protocol via a logic exploit that allowed for price manipulation in their OTC pools. SlowMist blames exchangeEquivalentBonds in BondMakerCollateralizedEth, which lacked multiset integrity checks and minted BondTokens without consuming collateral, while Defimon and ExVul trace the drain through GeneralizedDotc OTC pools. These are the original Lien BondMaker contracts, and the bug class matches the September 2020 whitehat rescue of ~$10M.
Garden Finance: $450K USDT across Ethereum, Base, Arbitrum and BNB Chain. Garden Finance is a Bitcoin bridge where solvers compete to fill cross-chain swaps. The bridge suffered an exploit after an offchain database breach let the solver release funds for unfunded swaps, its second such compromise in nine months after a ~$11M loss. Garden took the app offline, said nobody lost funds, and is investigating with zeroShadow, Quantstamp and Blockaid.
Guru-fund Lotus deployments: $96K to $101K (~$61.5K realised after slippage). The fund management protocol suffered a loss after an attacker exploited a legacy, never-verified P2P adapter that was left enabled in the protocol registry and could grant arbitrary token allowances through the delegatecall function during normal deposits. The Guru-fund team paused the protocol and announced the protocol will be winding down in the wake of this hack.
With the variety of attack vectors and pace of exploits, it’s clear that attackers are constantly looking for any way in.
Whether you’re a protocol, investor, or fund looking for protection against these risks and more, get in touch with our team today.
You’re Covered with Nexus Mutual