The Verus-Ethereum Bridge has suffered a second major exploit in roughly two months, losing approximately $7.53 million in assets on July 23. CertiK and Blockaid identified unauthorized transfers involving ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD from the bridge’s Ethereum-side reserves.
The attack targeted the bridge’s import-validation path, allowing Ethereum-side payouts without matching economic backing on the Verus source chain. Blockaid said the incident involved the same bridge contract, entry point and vulnerability class as the May breach, although a complete root-cause report for the latest exploit has not yet been released.
We have seen an exploit on @VerusCoin Ethereum bridge, from which ~$7.53M was withdrawn to 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54.
The bridge may have failed to check that Verus side inputs back the amounts paid, as in the May incident.
Stay Vigilant! pic.twitter.com/zfdDEIJE0G
— CertiK Alert (@CertiKAlert) July 23, 2026
Unbacked Import Proofs Drained Bridge Reserves
The attacker used the submitImports function to authorize unsupported withdrawals from the bridge contract. The manipulated import payload passed enough verification steps to release real assets even though corresponding value had not been committed on the source side.
That failure resembles the missing source-amount validation identified after the May exploit, when an attacker used a cross-chain import payload to withdraw approximately $11.58 million. The earlier incident demonstrated that cryptographically valid messages can still produce fraudulent payouts when economic backing is not verified independently.
Verus–Ethereum Bridge Suffers Second Exploit in Two Months, $7.54M Drained
Blockaid detected a new exploit targeting the Verus–Ethereum Bridge, with an attacker abusing the bridge’s import path to trigger unbacked Ethereum-side payouts and drain approximately $7.54 million in… pic.twitter.com/eNGo8EILT7
— Wu Blockchain (@WuBlockchain) July 23, 2026
The latest attacker consolidated the stolen asset basket into approximately 3,916 ETH before routing the funds into Tornado Cash. Moving the proceeds through a mixing protocol obscures subsequent transaction paths and complicates direct on-chain recovery efforts.
Repeat Failure Raises Reserve-Solvency Concerns
The breach did not compromise Ethereum’s base layer or consensus mechanism. Exposure remained concentrated in the bridge contracts and the reserves backing assets transferred between Verus and Ethereum.
The recurrence creates a more serious problem than the dollar loss alone. A second exploit involving the same validation path suggests that remediation after May did not fully remove the bridge’s ability to release assets against inadequately backed import requests, although investigators have not yet confirmed whether the cause was an incomplete patch, a regression or a separate code path producing the same outcome.
For users holding bridge-linked assets, the immediate concern is whether remaining reserves can support outstanding claims. The next critical disclosures will be reserve accounting, contract status, the final technical postmortem and any recovery or recapitalization plan.
The Verus-Ethereum Bridge faces a repeated validation failure with approximately $7.53 million newly drained. Until the project confirms that the import mechanism has been secured and reserve obligations have been reconciled, users should treat the affected bridge as carrying unresolved operational and solvency risk.
