Verus Bridge Exploited Again, $7.54M Drained in Second Attack
AI مارکیٹ کا خلاصہ
Verus Bridge suffered a repeat exploit (~$7.54M) after a similar May attack (~$11.58M), implying a previously identified validation flaw remained unfixed. The attacker allegedly triggered unbacked Ethereum-side payouts despite valid signatures and Merkle proofs, draining assets including ETH and stablecoins from bridge reserves. The recurrence highlights persistent operational and smart-contract risk in cross-chain infrastructure, pressuring user confidence and bridge liquidity until verified remediation and independent audit.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT-2.74%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
TL;DR Verus Bridge was hit by a second exploit, with roughly $7.54 million drained from its Ethereum bridge on Thursday—about two months after an earlier $11.58 million hack struck the same contract. Investigators say the issue was not broken cryptography but a missing on-chain value check: the contract accepted valid signatures and Merkle proofs yet did not verify that Ethereum payouts matched value actually committed on the Verus chain. Security firms tied the flaw to incomplete Solidity validation, and users were urged to avoid the bridge until fixes are publicly confirmed and independently audited.
Verus Bridge has suffered another major security incident, with an attacker extracting about $7.54 million from its Ethereum bridge reserves on Thursday. The breach appears to mirror May’s exploit, when approximately $11.58 million was stolen from the same contract, raising fresh questions about whether a known validation issue was left unresolved.
Blockaid said the latest theft impacted multiple assets, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. In a post dated July 23, 2026, Blockaid reported that the attacker used the bridge's import path to trigger payouts on Ethereum that were not backed by corresponding value on the Verus blockchain.
According to Blockaid, the bridge processed the required signatures and Merkle proofs but failed to confirm that the amount being released on Ethereum matched what had been committed on the source chain. The weakness stemmed from a missing value validation inside the smart contract rather than any failure of signature or proof systems.
Halborn and Merkle Science previously reached similar conclusions in their assessments of the May exploit, tracing the problem to the checkCCEValues function and roughly 10 missing lines of Solidity validation. Merkle Science said the earlier attacker could turn about $10 in VRSC transaction fees into a payout worth $11.58 million. Halborn noted that even a transaction valued near 1 cent could satisfy the bridge's signature and proof checks, then prompt Ethereum to release assets worth millions—allowing minimal source value to unlock an outsized destination payout.
Reports indicate Thursday's incident targeted the same contract and import path, though it involved a different transaction, attacker wallet, and destination for the stolen funds.
The recurrence comes as bridge security has generally improved across DeFi. Immunefi data cited in the report showed bridge hacks represented 73% of DeFi losses in 2022 but only 3% in 2025. Even so, broader industry progress offers little protection when a publicly identified vulnerability remains unaddressed.
Verus had not published an official postmortem for Thursday's exploit at the time of reporting. After the May incident, Merkle Science advised users to avoid the bridge until the validation flaw was fixed and independently audited. With no public confirmation of a completed remediation and audit, users and liquidity providers are again being urged to exercise caution.