Verus Ethereum Bridge drained of $7.54 million in second exploit
Security & Exploits ·
An attacker exploited the same bridge contract targeted in a May 2026 incident, this time siphoning roughly $7.54 million across seven asset types using an unbacked payout mechanism.
The Verus Coin Ethereum Bridge was hit by an attacker who manipulated its import path to force unbacked payouts on the Ethereum side, pulling ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD out of the bridge's reserves. Blockaid identified the exploit transaction and traced the outgoing funds to a wallet controlled by the attacker, separate from the bridge's own contract address, according to The Block. Blockaid also flagged that this incident shares the same contract, the same entry path, and the same underlying bug class as the bridge's May 2026 breach, though the transaction itself is new and involves a different attacker and a different destination wallet.
The repeat exposure raises questions about whether the underlying vulnerability was ever fully patched after the first incident. One observer responding to the news argued that bridges of this kind need built-in kill switches to halt suspicious withdrawals before losses compound, a point that underscores the gap between detection and prevention in cross-chain infrastructure.
The Verus breach did not happen in isolation. It form part of a broader cluster of attacks that drained a combined $35 million from multiple protocols within hours of each other, according to CoinDesk. Reporting on the wider spree lists AFX Trade losing $24.15 million in USDC and B² Network losing $3.86 million, alongside the Verus loss, all within a roughly 24-hour window, per CryptoPotato. Coverage of the cluster frames the incidents as stemming from a mix of compromised keys and validation failures across different cross-chain systems, rather than a single shared exploit path.
At least eight distinct sources have covered the cluster of attacks, reflecting the scale of attention drawn by same-day losses across separate bridge and protocol designs. What remains unresolved is whether Verus will implement a fix that closes the specific import-path weakness for good, whether any of the drained funds can be recovered or frozen, and how the other affected protocols named in the broader $35 million total plan to respond to their own breaches.