Verus Bridge Protocol was attacked again, losing US$7.54 million
An attacker stole approximately US$7.54 million from the Verus Ethereum Bridge Protocol, the second time the protocol has been successfully attacked in two months. The vulnerability was first discovered earlier this year but was not fully fixed, causing the bridging protocol to be attacked again and its cross-chain mechanism to be targeted again.
Cross-chain bridge risks persist
Cross-chain bridges allow users to lock digital assets on one blockchain and issue equivalent tokens on another chain, aiming to promote interoperability within the crypto ecosystem. However, these bridging agreements often hold large amounts of liquidity in their pools, making them attractive targets for cybercriminals. One mistake by the validator can lead to huge losses.
Blockaid, a blockchain security company, reported that the Verus attack exposed a recurring vulnerability common in multiple major bridging attacks since 2022. The attacker used the asset import function of the bridge protocol to trigger Ethereum payments that did not match the actual value on the Verus blockchain.
The attacker targeted the Verus Ethereum Bridge Protocol contract located at address 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63 and transferred the stolen funds to the wallet address 0xCFd0A2D0A2E3d 74C2A08C96A0A4aE7d58eF92D54. Assets affected include ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.
Blockchain records on Etherscan confirm an attack transaction sequence related to the attacker's wallet and bridge protocol contract.
Repeated attack reveals unfixed vulnerability
The recent incident is similar to a similar attack in May 2026, when approximately $11.58 million was stolen from the same contract through almost the same method. Blockaid's analysis found that the exploited vulnerabilities remained unresolved, indicating persistent flaws in the design and implementation of the bridging protocol.
A review by Blockaid found that both attacks utilized the same import path on the same contract, indicating that the security vulnerability was not fixed even after the first attack.
Security companies Halborn and Merkle Science came to the same conclusion after investigating early attacks. Halborn's Rob Behnke explained: "The vulnerability is not a cryptographic failure, but a lack of verification to ensure that the value committed on the Verus chain matches the value released on Ethereum."
Merkle Science found a lack of inspection in the bridge protocol code, specifically in its checkCCEValues function, which allows transactions to release assets on Ethereum that far exceed the actual locked value on the Verus side. This vulnerability allows attackers to take advantage of extremely low transaction fees to achieve disproportionately large gains.
Merkle Science pointed out that the contract failed to verify whether the source value matched the amount paid, allowing an attacker to withdraw millions of dollars for a small fee.
The companies said the bridge protocol's cryptography and certification systems work as designed, but the lack of proper value verification in the contract is a fundamental problem. Merkle Science also linked the verification failure to a past attack in 2022 involving the Wormhole and Nomad bridging protocols.
Explanation of terms: Verus Bridge Protocol
A cross-chain protocol that supports asset transfers between the Verus blockchain and Ethereum, allowing users to lock tokens on one chain and minte corresponding assets on another chain. Vulnerability in such bridging protocols could expose funds to security risks on both networks.
Historical attack cases
Bridge protocol| Main attack years| lost funds| Root cause
Verus| 2026 |US$11.58 million/US$7.54 million| Lack of value verification
Wormhole| 2022 |$320 million| Signature verification vulnerability
Nomad| 2022 |$190 million| Initialization vulnerabilities
Bridging protocol ecosystems and ongoing risks
Although bridging attacks have historically accounted for a large proportion of decentralized finance (DeFi) losses, recent data suggests this trend is declining. Research by TRM Labs shows that despite a record of 207 attacks in the first half of 2026, total losses dropped from $2.3 billion in 2025 to $972 million, and the median attack amount dropped to approximately $219,000.
A report from Immunefi supports this trend, noting that bridging attacks will account for 73% of DeFi losses in 2022, but will only account for 3% by 2025, indicating improved security in the area through better auditing and design standards.
However, repeated attacks by Verus suggest that overall progress does not address specific and prominent vulnerabilities in individual protocols. The vulnerability that was exploited in May remains unresolved, raising concerns about project maintenance and audit follow-up.
As of now, Verus has not released a post-mortem analysis report on the latest incident. After the May attack, Merkle Science advised users to avoid using the bridging protocol until its flawed verification feature was fixed and independently audited. Users are advised to wait for clear confirmation of the project before resuming bridging activities.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
EURC