EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Verus Ethereum Bridge was attacked again, stealing $7.54 million

2026-07-24 00:11:32
Bookmark
[TAG

On Thursday, an attacker stole about $7.54 million by using the import path of the Verus Ethereum Bridge to trigger payments that were not endorsed by Verus network assets.

This unauthorized withdrawal removed ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD from the bridge's Ethereum reserves. PeckShield also assessed the damage at approximately $7.5 million.

This attack targets the process of releasing assets on Ethereum after cross-chain transfer verification is complete. A malicious import message passed through the bridge's verification path, instructing its contract to pay the real reserve without requiring a corresponding export or deposit on the Verus network.

Blockaid has not disclosed whether the attacker used a single transaction or multiple imports, and the current balance at downstream redemption and receiving addresses is still being verified.

Verus Bridge suffers second major loss

This attack is the second major loss suffered by the Verus Ethereum Bridge in more than two months.

A transaction on May 17 extracted 1,625.36 ETH, 103.56 tBTC and 147,658 USDC from the bridge, with an initial loss of approximately US$11.56 million. The attackers exchanged the assets for approximately 5,402 ETH, then returned 4,052 ETH under the restoration agreement and retained 1,350 ETH as a bounty.

Verus subsequently introduced a more stringent proof of transaction and prepared an alternative Ethereum contract as part of its bridging recovery process. The attack in July raised new questions about whether the latest withdrawal touched an upgraded contract or imported other components of the system.

Neither Blockaid nor PeckShield found any private key disclosure or theft of verifier credentials in the preliminary alert. Known attack paths focus on how the bridge handles imported transfer instructions.

DeFi protocol attacks accelerate

Before the theft of Verus, a USDC withdrawal of US$24.15 million occurred on AFX Trade's Arbitrum Bridge, and an unauthorized transaction bypassed the bridge's validator approval and dispute resolution processes.

Hours later, an attacker sold 8.59 million B2 tokens stolen from the B² Network for 5,409 BNB, making a profit of approximately US$3.01 million after deducting slip points.

These attacks came a day after a 42DAO oracle failure caused an attacker to withdraw $915,000 and caused the Price of Balance Coin to plummet by more than 99%.

As of press time, Verus has not released a public response, confirmed the operating status of the bridge or announced a recovery schedule.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP