Skip to content
Est. MMXXVIVol. VI · № 316RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 316Bridge Exploit

Verus-Ethereum Bridge Repeat Exploit

Just over two months after a May hack, the Verus-Ethereum bridge was drained again for ~$7.54M through the same unpatched import-verification path.

Date
Status
Funds Stolen

On July 23, 2026, the Verus-Ethereum bridge was drained of approximately $7.54 million — the second time in just over two months that the same bridge fell to the same class of flaw. The attacker abused the import/verification path that had already been weaponized in the protocol's May 2026 hack, lifting the combined two-incident loss to roughly $19.14 million.

What happened

Verus's cross-chain bridge relies on verification logic that binds a source-side export to the value released on the destination chain. In May, an attacker exploited a value-binding gap — submitting a near-worthless Verus-side export whose payload instructed the Ethereum side to release the full vault balance.

The July incident followed the same contract path and bug class:

  • The attacker again exploited the bridge's import-verification weakness rather than any newly discovered vulnerability.
  • Assets were siphoned directly from the bridge's Ethereum-side reserves.
  • Unlike May, the July drain ended in silence — there was no public negotiation and no bounty dialogue.

Because Verus published no statement, the incident was reconstructed entirely from on-chain traces and independent security firms rather than from the project itself.

Aftermath

  • Verus issued no public acknowledgement of the July exploit at the time of reporting.
  • The bridge's total value locked collapsed to under $5 million, down from roughly $90 million at the start of 2025 — a direct consequence of two exploits in quick succession.
  • The incident was logged on the REKT leaderboard as another entry in the year's long list of bridge failures.

Why it matters

The Verus repeat is a stark warning about incomplete post-incident remediation. A protocol that is exploited once and does not fully close the underlying flaw invites a second, near-identical attack — a dynamic seen across DeFi and echoed in the multi-exploit histories of protocols like Abracadabra Money.

It also arrived as the third of three key-and-verification failures in a single window: the AFX Trade validator-key theft and the B² Network upgrade-authority compromise struck the day before. Together they made July 22–23, 2026 a concentrated reminder that cross-chain infrastructure remains the most fragile surface in DeFi, and that patching the specific transaction of the first hack is not the same as fixing the vulnerability class behind it.

Sources & on-chain evidence

  1. [01]cryptotimes.iohttps://www.cryptotimes.io/2026/07/23/verus-ethereum-bridge-exploited-again-for-7-54m-in-repeat-attack/
  2. [02]coindesk.comhttps://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart
  3. [03]rekt.newshttps://rekt.news/veruscoin-rekt

Related filings