
Bitcoin and Ethereum-linked protocols suffer $35 million loss in consecutive attacks within hours: 2026 security crisis deepens
On July 23, 2026, major cross-chain protocols, including Verus and B² Network, were attacked within hours of each other, resulting in the loss of $35 million in assets. The incident, attributed to the misuse of administrative privileges and key theft rather than cryptographic flaws, once again highlights the security vulnerabilities of the 2026 cryptocurrency market, which is currently recording its worst-ever hacking losses.
On July 23, 2026, the decentralized finance (DeFi) ecosystem was shaken by a series of attacks that occurred within just a few hours. Major targets included Verus and B² Network, cross-chain systems linked to Bitcoin and Ethereum, with total losses estimated at approximately $35 million. Rather than breaking complex cryptographic algorithms, the attackers used administrative privileges and stolen keys to withdraw protocol assets by masquerading as legitimate transactions.
This attack did not collapse the cryptographic foundation; instead, it exploited loopholes in administrative keys, upgrade permissions, and verification procedures to drain the protocols.
The incident, which took place throughout the morning and afternoon of July 23, 2026, clearly demonstrated the vulnerabilities of cross-chain infrastructure. The attackers infiltrated the systems of Verus and B² Network, bypassing the validation logic that authorizes asset movement. In particular, they exploited the fact that both protocols act as bridges connecting different networks, using methods to unauthorizedly transfer assets from one network to another.
Misuse of Stolen Keys and Upgrade Permissions
According to technical analysis, the root cause of this hack was poor management of private keys, which are core security elements of the protocols. Rather than searching for bugs in the smart contracts themselves, the attackers focused on hijacking administrator accounts with system upgrade permissions. This allowed them to disable security filters and insert malicious code to authorize large-scale fund withdrawals.
- Unauthorized access through the theft of administrator private keys
- Insertion of malicious logic by exploiting system upgrade privileges
- Asset leakage by exploiting loopholes in cross-chain verification procedures
- Exposure of vulnerabilities in the GG20 threshold signature scheme
This incident aligns with the recent $32 million hack of the Humanity Protocol. Humanity Protocol also suffered massive losses due to the theft of private keys, but renowned on-chain analyst ZachXBT sparked controversy by claiming the incident was 'possibly staged.' These suspicions suggest that security incidents occurring in 2026 are taking the form of internal collusion or complex fraud, rather than simple external attacks.
The second quarter of 2026 was recorded as the quarter with the highest number of hacks in cryptocurrency history. According to data from DeFiLlama, approximately 70 exploits occurred during this period alone, and the cumulative losses from hacks in 2026 have exceeded $840 million. In particular, large-scale incidents, such as the $292 million outflow from Kelp DAO last June, have amplified market anxiety.
The vulnerability of the GG20 threshold signature scheme, a core technology of cross-chain infrastructure, has also emerged as a major target for attacks. According to a recent report, cases have been identified where newly replaced validator nodes leaked sensitive key material while joining the active set. These technical flaws are acting as serious factors threatening the safety of protocols amidst the trend of frequent asset movement between networks.
As security incidents surge, trust in traditional smart contract audits is declining. According to Hacken's Q2 2026 Security and Compliance Report, only 9% of the 1,427 projects surveyed had implemented real-time third-party monitoring. Institutional investors are now calling for a change in security standards, demanding 24/7 continuous monitoring and immediate response systems rather than simple one-time audits.
Regulatory Pressure and Market Direction
Security incidents are acting as a catalyst for accelerating intervention by regulatory authorities. Polymarket, a prediction market platform that suffered a $3 million hack last May due to third-party dependency issues, is currently under extensive investigation by the U.S. Commodity Futures Trading Commission (CFTC). The chain of attacks on July 23rd is also expected to serve as a strong justification for regulators to strengthen infrastructure security standards for DeFi protocols.
In conclusion, the security crisis of 2026 stems more from operational management loopholes than from technical incompleteness. Experts emphasize that protocol operators need a fundamental shift in their security paradigm, such as innovating key management systems and reducing external dependencies. It is also time for investors to closely examine real-time security metrics rather than relying solely on past audit history.
| Protocol | Date | Amount Lost | Primary Vulnerability |
|---|---|---|---|
| Kelp DAO | June 2026 | $292 Million | Protocol Exploit |
| Humanity Protocol | July 2026 | $32 Million | Private Key Hack |
| Verus & B² Network | July 23, 2026 | $35 Million | Compromised Keys / Upgrade Powers |
| Polymarket | May 2026 | $3 Million | Third-party Dependency |
A summary of significant protocol exploits leading up to and including the July 23 attacks.



This content is for information and commentary only and is not investment advice.
Join the reader conversation
Read reactions to this article and leave your own note.