TL;DR
- Verus Bridge misplaced about $7.54 million in a second exploit roughly two months after an earlier $11.58 million assault focused the identical contract.
- The vulnerability allowed Ethereum payouts with out confirming that matching worth had been dedicated on Verus, regardless of legitimate signatures and Merkle proofs.
- Safety companies linked the flaw to lacking Solidity validation, whereas customers had been suggested to keep away from the bridge till repairs and an impartial audit are confirmed publicly.
Verus Bridge has suffered a second main exploit in roughly two months, with an attacker draining about $7.54 million from its Ethereum bridge on Thursday. The incident seems to contain the identical vulnerability utilized in Could, when roughly $11.58 million was stolen from the identical contract. The repeat breach suggests a recognized validation flaw remained unresolved after the primary assault. Blockaid stated the most recent theft affected belongings together with ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, reigniting issues about how rapidly bridge operators reply as soon as a vital weak spot turns into public throughout the broader DeFi market.
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
An attacker used the bridge import path to set off unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
Extra particulars in 🧵— Blockaid (@blockaid_) July 23, 2026
Lacking validation exposes the identical bridge contract
In response to Blockaid, the attacker manipulated the bridge’s import mechanism to set off Ethereum payouts that weren’t supported by equal worth on the Verus blockchain. The bridge accepted the required signatures and Merkle proofs, but failed to substantiate that the quantity launched matched the worth dedicated on the supply. The issue was not damaged cryptography, however a lacking worth verify contained in the contract. Halborn and Merkle Science reached related conclusions after reviewing the Could exploit, tracing the difficulty to the checkCCEValues operate and roughly 10 lacking traces of Solidity validation, regardless of showing in any other case operational all through.

That omission created an nearly absurd imbalance between value and reward. Merkle Science stated the sooner attacker might convert roughly $10 in VRSC transaction charges right into a payout value $11.58 million. Halborn famous that even a transaction valued close to 1 cent might fulfill the bridge’s signature and proof necessities earlier than prompting Ethereum to launch belongings value tens of millions. Minimal supply worth might due to this fact unlock an infinite vacation spot payout. The most recent incident reportedly focused the identical contract and import path, though it concerned a unique transaction, attacker pockets, and vacation spot for the stolen funds with disturbing ease.
The timing is unsettling as a result of bridge safety has broadly improved throughout decentralized finance. Immunefi information cited within the report confirmed bridge hacks accounted for 73% of DeFi losses in 2022 however solely 3% in 2025. Nonetheless, sector-wide progress can’t compensate for a publicly recognized vulnerability left uncorrected. Verus had not launched an official autopsy for Thursday’s assault. Following the Could incident, Merkle Science suggested customers to keep away from the bridge till the defective validation was fastened and independently audited, leaving warning as the one prudent response whereas affirmation stays absent for customers and liquidity suppliers alike.

