Attackers steal approximately $7.54 million from Verus Ethereum Bridge
An attacker successfully stole approximately $7.54 million from the Verus Ethereum Bridge on Thursday. This is the second time in about two months that the bridge has been successfully used for an attack. It appears that the vulnerabilities discovered earlier this year have never been fully fixed. This suggests that some known vulnerabilities continue to threaten cross-chain systems.
Cross-chain bridges allow users to lock assets on one blockchain and issue equivalent tokens on another blockchain. However, most bridges contain extremely large pools of shared liquidity. As a result, a validator can cause millions of dollars in losses with just one small mistake. According to blockchain cybersecurity firm Blockaid, the same situation appears to have occurred with the Verus attack, with some of the largest cryptocurrency bridge attacks since 2022 being affected by similar vulnerabilities.
The same contract was attacked again
According to Blockaid, the attacker used the bridge's import mechanism to trigger Ethereum-related payments that were inconsistent with the actual value on the Verus chain. Hackers stole assets including ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD, with a total loss value of approximately US$7.54 million.
The attack targeted the Verus Ethereum Bridge protocol contract (address 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63), and the funds were traced to the hacker wallet (address 0xCFd0A2D0A2E3d 74C2A08C96A0A4aE7d58eF92D54). Blockchain evidence can be easily viewed on Etherscan, including bridge contracts, attacker wallets, and attack transactions.
This incident is particularly noteworthy because it is very similar to another incident that occurred in May 2026-when the Verus Bridge was attacked and $11.58 million was lost. Blockaid said both attacks targeted the same contract and were carried out through the same import path, which means the vulnerability has not been fixed yet.
Why vulnerabilities can leverage millions of dollars for a few cents
Security companies Halborn and Merkle Science came to the same conclusion after analyzing the previous attack.
"The vulnerability is not a cryptographic failure, but a lack of verification to ensure that the value committed on the Verus chain matches the value released on Ethereum."-- Rob Behnke, Halborn
According to Halborn, even if a transaction is worth only about 1 cent, all of the bridge's signatures and Merkel certification requirements can be used to subsequently trigger the Ethereum smart contract to execute the transaction and release millions of dollars worth of assets.
According to Merkle Science, the root cause of the problem lies in the checkCCEValues function in the bridge code.
"The bridge failed to verify that the source value matched the target payment, allowing an attacker to withdraw millions of dollars for a very small fee."-- Mir Jalal, Merkle Science
The company believes the problem stems from about 10 missing lines of Solidity verification code, which allowed attackers to convert VRSC transaction fees worth about $10 into a payment of $11.58 million.
The two companies made it clear that the bridge's cryptography and certification verification mechanisms themselves are working normally. However, the practical problem is that the contract does not verify whether the value released on Ethereum is supported by assets on the Verus chain. Merkle Science pointed out that the attacks on Wormhole and Nomad bridges in 2022 were also caused by the same type of verification failure.
What does it mean for markets that believe bridges are safer?
The Verus incident comes as other areas of the cryptocurrency community suffer less losses from bridge attacks.
According to data collected by TRM Labs, there were 207 cybersecurity attacks in the cryptocurrency field, the highest number recorded in six months. In contrast, total losses for the same period in 2025 dropped from $2.3 billion to $972 million, while the median hacking amount for the current period dropped to approximately $219,000.
Bridge safety has also improved in the past few years. According to a report by Immunefi, 73% of DeFi losses related to bridge attacks in 2022, but this figure has dropped to only 3% by 2025. This shows a significant improvement in the quality of audits and bridge designs on the market.
Still, Verus's vulnerability shows that progress across the industry cannot make up for existing unresolved vulnerabilities. Problems first exposed after the May attack appear to be exploited again, reinforcing the view that dealing with known vulnerabilities is far more important than assuming the risk no longer exists.
Verus has not yet released an official post-mortem analysis of Thursday's incident. After the May incident, Merkle Science had advised users to avoid using the bridge until problematic verifications were fixed and approved by independent auditors. Users should be cautious and avoid making bridge transfers until the project party confirms that the relevant work is completed.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
EURC