Verus Ethereum Bridge Exploited Again, $7.54M Drained via Same Attack Route as May
AI مارکیٹ کا خلاصہ
Verus's Ethereum bridge was exploited again, draining ~$7.54M (including ~1,137 ETH and multiple stablecoins/tokens) via the same contract and entry path implicated in May. The repeat nature suggests unresolved validation/logic weaknesses in cross-chain import handling, reinforcing operational and smart-contract risk around bridges. Near-term, this can pressure bridge-related liquidity and risk appetite in DeFi, with heightened scrutiny on cross-chain security and potential contagion via asset flows.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT-2.19%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
The Verus Ethereum Bridge suffered another exploit on July 23, with about $7.54 million drained from the same bridge contract compromised in May.
Blockaid flagged suspicious activity on Ethereum at 03:45 UTC. Onchain data shows a transaction interacting with the Verus bridge contract that transferred roughly 1,137 ETH along with multiple tokens—tBTC, USDC, USDT, EURC, MKR and scrvUSD—to an attacker-controlled address. Etherscan priced the outflows at approximately $7.54 million at the time.
Key addresses
- Bridge contract: 0x71518580f36feceffe0721f06ba4703218cd7f63
- Recipient wallet: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 (0xCFd0…2D54)
- Exploit transaction (reported):
How the exploit worked
Blockaid said the attacker abused the bridge's import path to trigger payouts on Ethereum that were not backed by corresponding assets on the source chain. While the July drain used a different transaction and a different attacker-controlled wallet than the May incident, Blockaid characterized the two events as stemming from "the same bridge contract, same entry path, and same bug class."
A full technical write-up on the July exploit had not been released at the time of the alert. The root cause remained under investigation.
Earlier breach in May
The July incident marks the second major hit to the Verus bridge in recent months. In May, the Verus Ethereum Bridge lost about $11.58 million after what was described as a validation gap that allegedly allowed a forged cross-chain import to pass verification, releasing more funds on Ethereum than were committed on the source chain.
Following that exploit, the attacker returned 4,052.4 ETH (about $8.5 million at the time) under settlement terms, while keeping 1,350 ETH as a bounty—about 75% of the exploiter's ETH holdings after conversion.
Broader bridge losses the same day
The Verus exploit was one of several bridge-related incidents reported within hours. Also on July 23, AFX Trade reportedly lost about $24.15 million and B² Network about $3.86 million, bringing combined reported losses across the three events to roughly $35.55 million, according to onchain tracker Lookonchain. Lookonchain said the AFX incident involved USDC taken from infrastructure operated by a third-party protocol and later converted into ETH.
Why it matters
Cross-chain bridges must validate events and values across separate networks while managing shared reserves. Breakdowns in message validation, contract logic or access controls can enable payouts without a corresponding deposit on the originating chain.
Blockaid said the July exploit "appears related to the previous Verus Ethereum Bridge incident in May 2026," but did not confirm whether the same vulnerability was reused or whether a different route through the import process was exploited.
What to watch next
As of publication, sources confirmed the funds moved out of the Verus bridge to the new attacker wallet. There was no indication that assets had been frozen, returned or recovered, and no remediation timeline was provided. Further technical analysis is expected to clarify whether the May weakness remained exploitable or whether a distinct flaw was used, as well as to track any conversion or laundering of the stolen funds.
This remains a developing story and will be updated as Blockaid or Verus release additional technical details or recovery actions.