Last night, while you were sleeping, your money may have been carried away.
AFX Trade cross-chain bridge: 24.15 million USDC drained.
B² Network: 8.59 million B2 tokens scooped up.
Balance Coin, an algorithmic stablecoin: crashed 99%, with its nominal market cap nearly wiped out.
Three protocols, three attack methods, all in the same night.
Cross-chain bridges, token contracts, oracles—these are DeFi’s three critical lifelines. All three fell in that same night.
This isn’t a coincidence. This was a comprehensive stress test. And the results? The entire DeFi security perimeter is riddled with holes.

AFX Trade: with just five signatures, 24 million dollars were released.
First, take a look.
AFX Trade, a derivatives exchange on Arbitrum, USDC settlement, up to 100x leverage.
Then last night at 21:30, Blockaid detected anomalies.
The attacker compromised the verification-signature key of the cross-chain bridge.
With five validator signatures—enough to reach two-thirds of the voting power—a withdrawal of 24.15 million USDC was approved normally.
During a 200-second objection period, no one noticed, and no one stopped it.
Then what? Funds moved from Arbitrum to Ethereum, where, at an average price of $1,937, they immediately bought 12,467 ETH in one go.

B² Network: 8.59 million tokens—15% evaporated instantly.
Now look at the second one.
On BNB Chain, B² Network had 8.591 million B2 tokens stolen, worth about $3.86 million.
The attacker swapped these tokens for 5,409 WBNB, bridged to Ethereum, and then transferred them to Zcash via the NEAR Intents bridge.
Zcash—privacy coin.
This means the money may never be recovered.
What did the B² team do? They posted a message on-chain to the attackers:
“Return at least 10% within 24 hours, and we won’t initiate legal proceedings.”
Reading this, I laughed.
$3.86 million—so you want them to return $380,000 and call it done?

Balance Coin: a wrong price—its $3.5 million market cap went to zero.
Finally, the most outrageous one.
Algorithmic stablecoin Balance Coin, running on BNB Chain, pegged to $1.
What did the attacker do? Manipulated the protocol’s price oracle, writing an abnormally low Bitcoin price into the system.
That’s it—just one incorrect price.
The lending contract didn’t perform proper range checks, and there was no liquidation delay mechanism.
With a single transaction, the attacker instantly liquidated a Bitcoin collateral vault that should not have been liquidated.
Balance Coin crashed from near $1 down to $0.0014.
The attacker netted $912,000.
One oracle loophole, and a stablecoin died instantly.