Verus Ethereum Bridge Hit Again, $7.5M Stolen in Likely Repeat of May Exploit

iconChainGPT
Share
AI summary iconSummary
Ethereum news broke on July 23 as the Verus Ethereum Bridge was hit again, with attackers stealing around $7.54 million. The exploit reused the same contract and method as the May attack, moving 1,137 ETH and tokens to a controlled address. This follows a $11.58 million loss in May and comes as Ethereum price today remains under pressure. Blockaid confirmed the same bug class was used, but no technical report has been released. The attack occurred alongside two others that day, totaling $35.55 million in losses. No fix or timeline has been announced for the bridge.

The Verus Ethereum Bridge was hit again on July 23, with attackers siphoning roughly $7.54 million from the same bridge contract that was exploited in May. What happened - Blockchain security firm Blockaid flagged the attack on Ethereum at 03:45 UTC on July 23. Onchain traces show a transaction interacted with the Verus bridge contract (0x71518580f36feceffe0721f06ba4703218cd7f63) and moved about 1,137 ETH plus several tokens to an attacker-controlled address (0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54). Etherscan valued the outflows at about $7.54 million at the time. - Tokens transferred included tBTC, USDC, USDT, EURC, MKR and scrvUSD. - Blockaid says the attacker abused the bridge’s import path to trigger Ethereum-side payouts that were not backed by matching assets on the source chain — the same entry path and apparent bug class identified in the May incident. The new exploit involved a different transaction and a different attacker wallet than in May. A full technical root-cause report has not yet been published. Context and fallout - This is the second major drain on the same Verus bridge in roughly two months. In May the bridge lost about $11.58 million after researchers said a validation gap allowed a forged cross-chain import to pass verification, releasing more funds on Ethereum than were committed on the source chain. - After the May incident, the original exploiter returned 4,052.4 ETH (about $8.5M at the time) under settlement terms and retained roughly 1,350 ETH as a bounty — about 75% of the exploiter’s remaining holdings post-conversion. - The July Verus exploit came amid a cluster of attacks that same day. Onchain tracker Lookonchain reported combined reported losses of roughly $35.55 million across three incidents: AFX Trade ($24.15M), Verus ($7.55M) and B² Network ($3.86M). The AFX loss involved USDC on bridge infrastructure run by a third party and was later converted into 12,467 ETH, with Offchain Labs clarifying it did not affect Arbitrum’s native bridge. Why this matters - Cross-chain bridges remain high-risk because they must validate events across disparate blockchains while safeguarding pooled assets. Failures in message validation, contract logic or access controls can enable unbacked payouts like those seen here. - Blockaid has described the July attack as “appears related to the previous Verus Ethereum Bridge incident in May,” noting the same contract, entry path and bug class, but it has not confirmed that the exact same vulnerability was re-exploited. Current status - At publication, sources confirm the funds left the Verus bridge for the new attacker wallet, but it is not clear whether any stolen assets have been frozen, returned or recovered. No remediation timeline or updated bridge operations plan has been released. - Further technical analysis is needed to determine whether the May flaw was left unpatched, whether a related weakness was used, or if the attacker exploited a different route through the import process. The attacker’s subsequent moves (conversions, mixers, or withdrawals) will be monitored for signs of fund laundering or recovery opportunities. Key links - Target bridge contract: https://etherscan.io/address/0x71518580f36feceffe0721f06ba4703218cd7f63 - Attacker address: https://etherscan.io/address/0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 This story is developing; we will update with technical reports or recovery news as they become available.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.