EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Verus Bridge was hacked again, losing $7.54 million, and old vulnerabilities continue to steal crypt

2026-07-24 00:32:55
Bookmark

Attackers steal approximately $7.54 million from Verus Ethereum Bridge

An attacker successfully stole approximately $7.54 million from the Verus Ethereum Bridge on Thursday. This is the second time in about two months that the bridge has been successfully used for an attack. It appears that the vulnerabilities discovered earlier this year have never been fully fixed. This suggests that some known vulnerabilities continue to threaten cross-chain systems.

Cross-chain bridges allow users to lock assets on one blockchain and issue equivalent tokens on another blockchain. However, most bridges contain extremely large pools of shared liquidity. As a result, a validator can cause millions of dollars in losses with just one small mistake. According to blockchain cybersecurity firm Blockaid, the same situation appears to have occurred with the Verus attack, with some of the largest cryptocurrency bridge attacks since 2022 being affected by similar vulnerabilities.

The same contract was attacked again

According to Blockaid, the attacker used the bridge's import mechanism to trigger Ethereum-related payments that were inconsistent with the actual value on the Verus chain. Hackers stole assets including ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD, with a total loss value of approximately US$7.54 million.

The attack targeted the Verus Ethereum Bridge protocol contract (address 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63), and the funds were traced to the hacker wallet (address 0xCFd0A2D0A2E3d 74C2A08C96A0A4aE7d58eF92D54). Blockchain evidence can be easily viewed on Etherscan, including bridge contracts, attacker wallets, and attack transactions.

This incident is particularly noteworthy because it is very similar to another incident that occurred in May 2026-when the Verus Bridge was attacked and $11.58 million was lost. Blockaid said both attacks targeted the same contract and were carried out through the same import path, which means the vulnerability has not been fixed yet.

Why vulnerabilities can leverage millions of dollars for a few cents

Security companies Halborn and Merkle Science came to the same conclusion after analyzing the previous attack.

"The vulnerability is not a cryptographic failure, but a lack of verification to ensure that the value committed on the Verus chain matches the value released on Ethereum."-- Rob Behnke, Halborn

According to Halborn, even if a transaction is worth only about 1 cent, all of the bridge's signatures and Merkel certification requirements can be used to subsequently trigger the Ethereum smart contract to execute the transaction and release millions of dollars worth of assets.

According to Merkle Science, the root cause of the problem lies in the checkCCEValues function in the bridge code.

"The bridge failed to verify that the source value matched the target payment, allowing an attacker to withdraw millions of dollars for a very small fee."-- Mir Jalal, Merkle Science

The company believes the problem stems from about 10 missing lines of Solidity verification code, which allowed attackers to convert VRSC transaction fees worth about $10 into a payment of $11.58 million.

The two companies made it clear that the bridge's cryptography and certification verification mechanisms themselves are working normally. However, the practical problem is that the contract does not verify whether the value released on Ethereum is supported by assets on the Verus chain. Merkle Science pointed out that the attacks on Wormhole and Nomad bridges in 2022 were also caused by the same type of verification failure.

What does it mean for markets that believe bridges are safer?

The Verus incident comes as other areas of the cryptocurrency community suffer less losses from bridge attacks.

According to data collected by TRM Labs, there were 207 cybersecurity attacks in the cryptocurrency field, the highest number recorded in six months. In contrast, total losses for the same period in 2025 dropped from $2.3 billion to $972 million, while the median hacking amount for the current period dropped to approximately $219,000.

Bridge safety has also improved in the past few years. According to a report by Immunefi, 73% of DeFi losses related to bridge attacks in 2022, but this figure has dropped to only 3% by 2025. This shows a significant improvement in the quality of audits and bridge designs on the market.

Still, Verus's vulnerability shows that progress across the industry cannot make up for existing unresolved vulnerabilities. Problems first exposed after the May attack appear to be exploited again, reinforcing the view that dealing with known vulnerabilities is far more important than assuming the risk no longer exists.

Verus has not yet released an official post-mortem analysis of Thursday's incident. After the May incident, Merkle Science had advised users to avoid using the bridge until problematic verifications were fixed and approved by independent auditors. Users should be cautious and avoid making bridge transfers until the project party confirms that the relevant work is completed.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP