Thursday, July 23, 2026

Verus Ethereum Bridge Exploited for $7.53M in Repeat Vulnerability

Neon-lit cross-chain bridge with a crack, tokens spilling into a dark vortex, signaling a crypto security breach.

The Verus-Ethereum Bridge has suffered a second major exploit in roughly two months, losing approximately $7.53 million in assets on July 23. CertiK and Blockaid identified unauthorized transfers involving ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD from the bridge’s Ethereum-side reserves.

The attack targeted the bridge’s import-validation path, allowing Ethereum-side payouts without matching economic backing on the Verus source chain. Blockaid said the incident involved the same bridge contract, entry point and vulnerability class as the May breach, although a complete root-cause report for the latest exploit has not yet been released.

Unbacked Import Proofs Drained Bridge Reserves

The attacker used the submitImports function to authorize unsupported withdrawals from the bridge contract. The manipulated import payload passed enough verification steps to release real assets even though corresponding value had not been committed on the source side.

That failure resembles the missing source-amount validation identified after the May exploit, when an attacker used a cross-chain import payload to withdraw approximately $11.58 million. The earlier incident demonstrated that cryptographically valid messages can still produce fraudulent payouts when economic backing is not verified independently.

The latest attacker consolidated the stolen asset basket into approximately 3,916 ETH before routing the funds into Tornado Cash. Moving the proceeds through a mixing protocol obscures subsequent transaction paths and complicates direct on-chain recovery efforts.

Repeat Failure Raises Reserve-Solvency Concerns

The breach did not compromise Ethereum’s base layer or consensus mechanism. Exposure remained concentrated in the bridge contracts and the reserves backing assets transferred between Verus and Ethereum.

The recurrence creates a more serious problem than the dollar loss alone. A second exploit involving the same validation path suggests that remediation after May did not fully remove the bridge’s ability to release assets against inadequately backed import requests, although investigators have not yet confirmed whether the cause was an incomplete patch, a regression or a separate code path producing the same outcome.

For users holding bridge-linked assets, the immediate concern is whether remaining reserves can support outstanding claims. The next critical disclosures will be reserve accounting, contract status, the final technical postmortem and any recovery or recapitalization plan.

The Verus-Ethereum Bridge faces a repeated validation failure with approximately $7.53 million newly drained. Until the project confirms that the import mechanism has been secured and reserve obligations have been reconciled, users should treat the affected bridge as carrying unresolved operational and solvency risk.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.