BLOCKINSIDERLoading
Live
↗BTC$94,210(+2.4%)|↗ETH$3,820(+1.8%)|↗SOL$218.40(+4.2%)|↗BNB$712.30(+0.6%)|↗BTC$94,210(+2.4%)|↗ETH$3,820(+1.8%)|↗SOL$218.40(+4.2%)|↗BNB$712.30(+0.6%)|
BlockInsiderBLOCKINSIDER
NEWS
MARKETS
ORIGINALS
EMERGING TECH
RWA & DEFI
LEARN
TOOLS
ABOUT
Sponsored slot · leaderboard
HomeCryptoVerus-Ethereum Bridge's $7.5 Million Hack Reveals Critical Dev Failure
Crypto

Verus-Ethereum Bridge's $7.5 Million Hack Reveals Critical Dev Failure

A second $7.5M hack in two months raises one uncomfortable question: did Verus actually fix anything after May?

4h ago 4,280
CryptoAnalysisBlockchain
On this page
  • Key Insights:
  • The Second Exploit in Two Months
  • VRSC Price Reaction Diverges Sharply From May
  • Developer Failures Behind the Repeat Breach
Verus-Ethereum Bridge's $7.5 Million Hack Reveals Critical Dev Failure
Aaryamann Shrivastava
Aaryamann Shrivastava
Crypto Journalist
VIEW PROFILE
Share

Key Insights:

  • Verus-Ethereum Bridge lost $7.5 million on July 23, its second exploit in under two months.
  • Attacker reused May's exact vulnerability class, exposing unresolved validation flaws in bridge contracts.
  • VRSC fell 14% and recovered fast, unlike May's 48% crash that still hasn't rebounded.

A hacker drained $7.5 million from the Verus-Ethereum Bridge on July 23, 2026. It marks the second exploit on this bridge in under two months.

Blockaid confirmed the attacker reused the same vulnerability class exploited back in May. That repetition raises hard questions about who is responsible for closing the gap.

The Second Exploit in Two Months

An attacker abused the bridge's import path on Wednesday, per Blockaid. This triggered unbacked payouts on the Ethereum side of the system. Assets drained included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

The stolen funds were converted into roughly 3,916 ETH afterward. Proceeds then moved into Tornado Cash, according to CertiK's tracking. This mirrors the laundering pattern seen after May's earlier breach.

The May 18 exploit drained about $11.5 million from the same bridge. That attacker later returned 4,052 ETH under a negotiated bounty deal. Verus claimed it had introduced tighter transaction proofs afterward.

View tweet

Blockaid says this new attack used the same contract, entry path, and bug class as May. Only the attacker's wallet differed between the two incidents. This repetition strongly suggests the root flaw was never fully patched.

That pattern points to a troubling lack of urgency from developers. Fixing surface symptoms without addressing root causes invites exactly this outcome. Verus has not yet detailed what its post-May remediation actually covered.

Security researchers note that bridges are especially attractive repeat targets. Once an entry path proves exploitable, attackers often revisit it later. Wednesday's incident fits that broader pattern seen across DeFi this year.

VRSC Price Reaction Diverges Sharply From May

VRSC fell roughly 14% within hours of Wednesday's hack. Most of that drop was recovered shortly afterward. Trading data showed buyers stepping in quickly to absorb the selling.

May's exploit told a starkly different story. VRSC crashed nearly 48% in a single day back then. The token has still not recovered those losses months later.

VSRC Price | Source: CoinMarketCap
VSRC Price | Source: CoinMarketCap

The contrast suggests market participants now view smaller exploits as less alarming. Repeated incidents can paradoxically dull investor reaction over time. That desensitization carries its own risks for long-term token holders.

Developer Failures Behind the Repeat Breach

This second exploit exposes deep gaps in Verus's security process. Based on Blockaid’s findings, three specific failures stand out clearly across both incidents.

First, inadequate input and logic validation persisted unaddressed since May. The bridge reportedly lacked proper source-amount checks on incoming imports. This lets attackers trigger payouts without any matching deposits.

Second, developers failed to remediate a known, previously flagged vulnerability. Blockaid explicitly linked this new attack to May's unresolved bug class. Patching one instance without fixing the underlying logic invited repetition.

Third, the bridge over-relied on proof messaging without sufficient guardrails. Transaction proofs alone couldn't stop a malicious, well-crafted import. Systems need extra checks beyond message verification to catch unbacked transfers reliably.

Together, these failures point to rushed fixes rather than genuine root-cause remediation. Cross-chain bridges demand rigorous validation given the enormous value they secure. Hacken's Q2 report already logged $32.78 million in bridge losses industry-wide.

Vulnerability and Losses Across DeFi in Q2 2026 | Source: Hacken
Vulnerability and Losses Across DeFi in Q2 2026 | Source: Hacken

Users and integrators now have far less reason to trust Verus's stated fixes. A single patch clearly wasn't enough to close the underlying gap. Comprehensive, independent audits appear overdue rather than incremental, reactive patching cycles.

The recovery in VRSC's price doesn't erase the deeper concern here. Confidence in bridge security depends on consistent engineering discipline, not luck. Verus now faces pressure to prove its infrastructure can be trusted.

Repeated exploits erode confidence faster than any single hack ever could. Until developers close these gaps for good, the bridge remains an obvious target. The next attacker may not need to wait two months.

How does this read?
Share

Comments · 0

Sign in to comment. Accounts coming soon.

No comments yet

Be the first to share your take when accounts launch.

Related reading

CRYPTO

Here's Why Grayscale's Bitcoin Bear Market Call May Be Wrong

@aaryamann-shrivastava6h ago
CRYPTO

AFX Hack: $24M Bridge Exploit Sparks Arbitrum Security Fears

@rizwan-ansari15h ago
CRYPTO

Stablecoin Activity Dips 50% in 2026: Crypto Losing Its Primary Fuel?

@rizwan-ansari1d ago
ETH · 7-day
Ethereum
$1,797
+1.57%
VIEW ETH PAGE

Live market data via CoinGecko. Updated every 30 minutes.

Sponsored slot · native
More from this desk
  • Here's Why Grayscale's Bitcoin Bear Market Call May Be Wrong6h ago
  • Could AMD's $5B Deal With Anthropic Push It Past $1 Trillion?1d ago
  • More Americans Now Own Bitcoin Than Gold, But There's a Catch1d ago
  • Andrew Cuomo To Lead NYSE-OKX Tokenized Stocks Venture2d ago
BlockInsiderBLOCKINSIDER© 2026 BlockInsider.
AboutThe InsidersAdvertiseCareersTermsPrivacy
Sponsored slot · native