The Verus Ethereum Bridge misplaced $7.54 million to an exploit early Thursday, July 23, 2026, after an attacker used the identical import-path flaw exploited in a Could hack that drained $11.5 million from the identical contract.
Blockaid detected the breach at 03:45 UTC, and CoinDesk reported that the stolen ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD had been transformed into roughly 3,916.1 ETH earlier than touchdown in a Twister Money pockets. The repeat hit issues as a result of Verus had redeposited funds recovered from the primary assault into this similar bridge solely two weeks earlier.
The Import-Path Flaw That Wouldn’t Die
In line with CoinDesk, the attacker abused the bridge’s import perform, the mechanism meant to verify that belongings are locked on the Verus aspect earlier than releasing matching payouts on Ethereum. That examine failed once more, letting the attacker set off unbacked Ethereum-side payouts and pull actual worth out of the bridge’s reserves.
Safety researchers confirmed the transaction and attacker pockets differ from Could’s incident, however the underlying contract and bug class are similar. The Could breach was critical sufficient that the Verus staff stated in a Discord message, reported by The Block, that the community had halted as nodes went offline in response.
Cointelegraph later reported that Blockaid traced the flaw to a lacking validation examine within the bridge’s transfer-verification code, a spot the agency stated wanted solely a minor repair. The dimensions of the injury exhibits in Verus’ personal numbers.
The protocol held near $100 million in complete worth locked at first of 2025, and CoinDesk’s assessment of onchain information places that determine at about $9 million as of Thursday. The attacker had returned 4,052.4 ETH after retaining a 25% bounty in Could, cash Verus redeposited into the identical bridge on July 8, two weeks earlier than the second drain.
The Danger for Anybody Utilizing Cross-Chain Bridges
Anybody holding funds on a cross-chain bridge ought to learn this as a reminder {that a} public bounty return and a redeposit are usually not the identical as a repair, and it’s price checking our information hub earlier than trusting a bridge that has already been drained as soon as.
Whether or not Verus’ Remaining $9M Retains Draining
Whether or not that remaining $9 million holds regular or retains falling within the coming days will present if depositors are pulling out forward of a 3rd exploit, or if Verus can persuade holders the import path is lastly closed.
What This Means for You
In the event you use a bridge to maneuver Bitcoin or Ethereum-based belongings, this case exhibits {that a} safety repair and a returned bounty don’t assure a vulnerability is closed. Earlier than bridging funds wherever, examine whether or not the mission has revealed a technical autopsy naming the precise bug, not simply an announcement that funds had been recovered. A bridge that has been drained twice by the identical flaw is a sign to attend for that proof earlier than depositing once more.
This text is for informational functions solely and doesn’t represent monetary recommendation. Do your personal analysis earlier than making any funding choices.
