Verus Bridge Hacked for $7.54 Million in Second Exploit This Year

2 hour ago 4 sources negative

Key takeaways:

  • Repeat exploit signals structural weakness, urging DeFi investors to reassess cross-chain risks.
  • Attacker's $7.5M laundering via Tornado Cash heightens regulatory scrutiny on privacy protocols.
  • Absence of swift recovery may erode trust in smaller bridges, favoring established alternatives.

The Verus Ethereum Bridge was drained of approximately $7.54 million on July 23, 2026, marking the second major exploit of the cross-chain protocol in recent months. Security firm Blockaid confirmed the attack was executed using the same submitImports function and bug class that led to an $11.58 million breach in May 2026. The attacker triggered unbacked payouts from the bridge contract on Ethereum, exploiting a missing validation that should have ensured the value locked on the Verus chain matched the value released on Ethereum.

The stolen assets included 1,137.45 ETH, 71.50 tBTC v2, 149,275 USDC, 78,300 USDT, 31,475 EURC, 59.43 MKR, and 92,784 scrvUSD, along with internal transfers of 220,357 DAI. According to Cyvers, the attacker swapped most funds into roughly 3,916 ETH, worth about $7.52 million at the time. Within hours, the laundered proceeds were moved through Tornado Cash in batches of 100 ETH and 10 ETH, leaving the attacker-controlled wallet with only 0.09 ETH.

On-chain data shows the exploit targeted the bridge contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63, with the funds initially sent to attacker address 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54. No asset freeze, recovery plan, or official response from the Verus team had been issued at the time of reporting. The team’s primary communication channel remains its X account, where updates on the breach are expected.

The recurrence of this vulnerability has drawn criticism from security analysts. Halborn’s Rob Behnke stated the flaw was “not a cryptographic failure, but a missing validation ensuring that the value committed on the Verus chain matched the value released on Ethereum.” Similarly, Merkle Science’s Mir Jalal noted the bridge failed to confirm that the source request locked or burned enough value. SlowMist analysts pointed to a weakness in the bridge’s proof logic, where only selected fields were checked—allowing the attacker to connect a low-value request to a massive Ethereum payout.

The May 2026 incident saw the hacker return roughly 75% of the stolen funds under a bounty deal, but the repeat attack raises serious concerns about the bridge’s security. The incident adds to a wider wave of bridge exploits, with over $35 million lost across Bitcoin and Ethereum-linked protocols in a single recent period. As users await a formal post-mortem from Verus, the breach underscores the persistent risks of cross-chain infrastructure.

Previously on the topic:
Jul 20, 2026, 4:25 a.m.
Allbridge Core Pauses After $1.65M Flash Loan Exploit
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.