Loading market data...

Three Protocols Hacked in 24 Hours, Over $35 Million Drained in Bridge Exploits

Three Protocols Hacked in 24 Hours, Over $35 Million Drained in Bridge Exploits

Three crypto protocols were drained of more than $35 million in a 24-hour window this week, with attackers exploiting cross-chain bridges on Arbitrum, BNB Chain, and Ethereum. The coordinated spree adds to what is already shaping up to be a record year for crypto-related thefts in 2026, according to data tracked by blockchain security firms.

The three targets

On Arbitrum, an unnamed lending protocol lost roughly $12 million after a bridge contract was manipulated. The attacker used a flash loan to inflate the value of a collateral token, then drained the bridge's liquidity pool. A similar technique was deployed on BNB Chain, where a decentralized exchange's bridge was exploited for about $15 million. The third incident hit an Ethereum-based cross-chain messaging protocol, netting the hacker around $8 million. All three attacks occurred within a 24-hour period starting early Tuesday.

How the exploits worked

In each case, the attacker targeted a bridge's verification logic. On Arbitrum, the exploit relied on a discrepancy between how the bridge validated incoming messages and how the destination contract processed them. The BNB Chain attack used a reentrancy vulnerability in a smart contract that handled token swaps. The Ethereum exploit involved a signature replay attack, where a valid transaction on one chain was replayed on another. None of the affected protocols had paused their bridges before the attacks.

2026's record-breaking year for hacks

This week's haul pushes the total value lost to crypto hacks in 2026 past $2.8 billion, surpassing the previous annual record of $2.6 billion set in 2022. Bridge exploits alone account for roughly 60% of that figure, according to on-chain analytics. The frequency has also increased: July has seen at least one major exploit every three days.

What comes next

Two of the three protocols have since paused their bridges and are working with security auditors to patch the vulnerabilities. The third has not publicly commented. Law enforcement agencies in the U.S. and Europe have been notified, though the stolen funds have already been moved through mixers and cross-chain swaps. The teams behind the affected protocols are expected to release post-mortem reports within the next week.