Loading market data...

Verus, B² Network Lose $35M in Coordinated Cross-Chain Attacks

Verus, B² Network Lose $35M in Coordinated Cross-Chain Attacks

Bitcoin and Ethereum-linked protocols lost a combined $35 million in a series of attacks that unfolded within hours on Thursday, July 23, 2026. The incidents targeted Verus, B² Network, and other cross-chain systems, with hackers exploiting compromised private keys, upgrade powers, and validation checks — not the underlying cryptography itself.

How the attacks worked

The attackers didn't break the core blockchain code. Instead, they went after the softer spots: private keys that controlled protocol upgrades, and validation logic in cross-chain bridges. At Verus, the exploit used a compromised key to push a malicious upgrade. At B² Network, attackers manipulated validation checks to drain funds. Both attacks happened within hours of each other, suggesting either a coordinated effort or a shared vulnerability that multiple groups rushed to exploit.

What was lost

Verus, a Bitcoin sidechain focused on decentralized identity and smart contracts, lost roughly $12 million. B² Network, a Bitcoin layer-2 scaling solution, lost about $23 million. The remaining $35 million figure includes losses from other unnamed cross-chain protocols that were hit in the same window. None of the affected projects have announced recovery plans or reimbursement for users.

The attacks underscore a persistent weak point in crypto: the human layer. Private key management and upgrade governance remain the most common failure points, even as the underlying blockchains themselves stay secure. For users, the takeaway is that funds on any protocol that relies on a small set of keys or a centralized upgrade process are at risk — regardless of how robust the base layer is.

What comes next

Verus and B² Network have both said they are working with security firms to trace the stolen funds. Neither has given a timeline for a post-mortem or a plan to make users whole. The broader cross-chain ecosystem is now under renewed scrutiny, with developers racing to audit upgrade mechanisms and key management practices before the next wave of attacks.