TL;DR
-
The Verus-Ethereum Bridge lost approximately $7.54 million in a new exploit on Wednesday.
-
Attackers exploited the same vulnerability class that was used in the bridge's $11.6 million hack in May.
-
The stolen assets were swapped for 3,916 ETH before being transferred to Tornado Cash, according to CertiK.
The Verus-Ethereum Bridge has suffered another major security breach, with attackers stealing approximately $7.54 million in digital assets in the protocol's second exploit in just two months.
Blockchain security firm Blockaid disclosed the incident on Wednesday, saying the attacker leveraged the same category of vulnerability that enabled the bridge's $11.6 million exploit in May.
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
— Blockaid (@blockaid_) July 23, 2026
An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
More details in 🧵
The repeated attack raises fresh concerns about unresolved security weaknesses within the bridge's infrastructure.
Attacker Exploited Bridge Import Mechanism
According to Blockaid, the hacker manipulated the bridge's import path, allowing unauthorized payouts on the Ethereum side of the protocol without sufficient asset backing.
The exploit enabled the attacker to drain multiple cryptocurrencies held in the bridge's reserves, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
After extracting the assets, the attacker converted the stolen funds into Ether.
Blockchain security company CertiK independently confirmed the exploit and estimated total losses at approximately $7.53 million.
According to the firm, the attacker ultimately exchanged the stolen assets for approximately 3,916.1 ETH before transferring the proceeds to Tornado Cash, a cryptocurrency mixing protocol commonly used to obscure blockchain transaction trails.
The movement of funds into Tornado Cash may complicate efforts to trace or recover the stolen assets.
Attack Mirrors May Security Breach
Blockaid believes the latest exploit is closely connected to the attack that struck the Verus-Ethereum Bridge in May.
Researchers said both incidents involved the same bridge contract, the same transaction entry point, and the same class of underlying vulnerability.
However, Blockaid noted that the latest exploit appears to have been carried out by a different attacker, who used a newly created wallet to receive the stolen funds.
Previous Hack Ended with Partial Fund Recovery
The Verus-Ethereum Bridge previously suffered a major exploit on May 18, when attackers stole approximately $11.6 million after exploiting the same bridge infrastructure.
Following that attack, the hacker converted the stolen assets into roughly 5,402 ETH. In an unusual outcome, the attacker later returned 4,052 ETH, effectively accepting a 25% white-hat bounty while keeping the remaining funds.
Despite that partial recovery, the recurrence of a similar exploit suggests that underlying security issues may not have been fully resolved.
Security Concerns Intensify
The latest incident underscores the ongoing risks associated with cross-chain bridge infrastructure, one of the most frequently targeted segments of decentralized finance (DeFi).
Bridge protocols often hold large pools of locked assets while relying on complex smart contract logic, making them attractive targets for sophisticated attackers. When vulnerabilities remain unpatched or insufficiently mitigated, they can be exploited repeatedly by different threat actors.
The second successful attack against the Verus-Ethereum Bridge in less than two months raises serious questions about the protocol's security posture and remediation efforts following the May exploit.
Hassan Maishera