Verus Ethereum Bridge Drained Again as Suspected Repeat Exploit Nets About $7.5M

AI Market Summary
Verus's Ethereum bridge was exploited again, with ~1,137 ETH and multiple tokens drained (~$7.5M) via an unbacked cross-chain import path similar to May's incident. The repeat breach reinforces persistent bridge validation risk and may pressure liquidity and confidence around bridged assets and related DeFi venues. With no confirmed remediation or recovery, traders may reassess smart-contract and bridge counterparty exposure in the near term.
Impact level
● Medium
Affected assets
ETH/USDT-0.02%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
The Verus Ethereum Bridge suffered another major loss on July 23, after attackers pulled roughly $7.54 million from the same bridge contract compromised in May. Blockaid flagged suspicious activity on Ethereum at 03:45 UTC. On-chain data shows a transaction interacting with the Verus bridge contract (0x71518580f36feceffe0721f06ba4703218cd7f63) and transferring about 1,137 ETH along with multiple tokens to an attacker-controlled address (0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54). Etherscan priced the outflows at around $7.54 million at the time. Assets moved included tBTC, USDC, USDT, EURC, MKR, and scrvUSD. According to Blockaid, the attacker abused the bridge's import path to trigger Ethereum-side payouts without corresponding backing on the source chain. The firm said the entry path and apparent bug class match those identified in the May incident, though this latest exploit used a different transaction and a different attacker wallet. A full technical root-cause report has not been released. The July drain marks the second major incident affecting the Verus bridge in roughly two months. In May, the bridge lost about $11.58 million after researchers pointed to a validation gap that allowed a forged cross-chain import to pass verification, releasing more funds on Ethereum than were committed on the origin chain. Following that event, the original exploiter returned 4,052.4 ETH (about $8.5 million at the time) under settlement terms and kept roughly 1,350 ETH as a bounty, described as about 75% of the exploiter's remaining holdings after conversion. The Verus exploit occurred amid multiple attacks reported the same day. Lookonchain cited roughly $35.55 million in combined losses across three incidents: AFX Trade ($24.15 million), Verus ($7.55 million), and B² Network ($3.86 million). The AFX incident involved USDC on third-party bridge infrastructure and was later converted into 12,467 ETH. Offchain Labs said the AFX issue did not impact Arbitrum's native bridge. Cross-chain bridges remain a frequent target because they must validate events across different blockchains while holding pooled assets. Breakdowns in message validation, contract logic, or access controls can lead to unbacked payouts. Blockaid described the July event as "appears related to the previous Verus Ethereum Bridge incident in May," citing the same contract, entry path, and bug class, while stopping short of confirming a direct re-exploitation of the exact same vulnerability. As of publication, the funds have left the Verus bridge for the new attacker wallet. It remains unclear whether any assets have been frozen, returned, or recovered, and no remediation timeline or updated operational plan has been announced. Further analysis is needed to determine whether the May flaw went unpatched, whether a related weakness was used, or whether the attacker found a different route through the import process. Observers will track subsequent movements for signs of swaps, mixer use, withdrawals, or recovery opportunities. Key links Target bridge contract: Attacker address: This story is developing and will be updated as technical findings or recovery information becomes available.