Verus Bridge Hit Again as $7.5M Vanishes in Repeat Hack

iconCrypto Economy
Share
AI summary iconSummary
Verus Bridge faced another exploit on July 23, 2026, with $7.54 million stolen from its Ethereum bridge. This follows a May incident where $11.58 million was drained using the same flaw. The vulnerability allowed Ethereum withdrawals without verifying Verus deposits. Security experts tied the issue to missing Solidity validation in the checkCCEValues function. Users are urged to avoid the bridge until fixes and an audit are confirmed. The incident raises concerns about compliance with MiCA and CFT measures.

TL;DR

  • Verus Bridge lost about $7.54 million in a second exploit roughly two months after an earlier $11.58 million attack targeted the same contract.
  • The vulnerability allowed Ethereum payouts without confirming that matching value had been committed on Verus, despite valid signatures and Merkle proofs.
  • Security firms linked the flaw to missing Solidity validation, while users were advised to avoid the bridge until repairs and an independent audit are confirmed publicly.

Verus Bridge has suffered a second major exploit in roughly two months, with an attacker draining about $7.54 million from its Ethereum bridge on Thursday. The incident appears to involve the same vulnerability used in May, when approximately $11.58 million was stolen from the same contract. The repeat breach suggests a known validation flaw remained unresolved after the first attack. Blockaid said the latest theft affected assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, reigniting concerns about how quickly bridge operators respond once a critical weakness becomes public across the wider DeFi market.

Missing validation exposes the same bridge contract

According to Blockaid, the attacker manipulated the bridge’s import mechanism to trigger Ethereum payouts that were not supported by equivalent value on the Verus blockchain. The bridge accepted the required signatures and Merkle proofs, yet failed to confirm that the amount released matched the value committed at the source. The problem was not broken cryptography, but a missing value check inside the contract. Halborn and Merkle Science reached similar conclusions after reviewing the May exploit, tracing the issue to the checkCCEValues function and roughly 10 missing lines of Solidity validation, despite appearing otherwise operational throughout.

Verus Bridge lost about $7.54 million in a second exploit

That omission created an almost absurd imbalance between cost and reward. Merkle Science said the earlier attacker could convert roughly $10 in VRSC transaction fees into a payout worth $11.58 million. Halborn noted that even a transaction valued near 1 cent could satisfy the bridge’s signature and proof requirements before prompting Ethereum to release assets worth millions. Minimal source value could therefore unlock an enormous destination payout. The latest incident reportedly targeted the same contract and import path, although it involved a different transaction, attacker wallet, and destination for the stolen funds with disturbing ease.

The timing is unsettling because bridge security has broadly improved across decentralized finance. Immunefi data cited in the report showed bridge hacks accounted for 73% of DeFi losses in 2022 but only 3% in 2025. Still, sector-wide progress cannot compensate for a publicly identified vulnerability left uncorrected. Verus had not released an official post-mortem for Thursday’s attack. Following the May incident, Merkle Science advised users to avoid the bridge until the faulty validation was fixed and independently audited, leaving caution as the only prudent response while confirmation remains absent for users and liquidity providers alike.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.