Crypto
Verus-Ethereum Bridge's $7.5 Million Hack Reveals Critical Dev Failure
A second $7.5M hack in two months raises one uncomfortable question: did Verus actually fix anything after May?
4h ago 4,280
A second $7.5M hack in two months raises one uncomfortable question: did Verus actually fix anything after May?

A hacker drained $7.5 million from the Verus-Ethereum Bridge on July 23, 2026. It marks the second exploit on this bridge in under two months.
Blockaid confirmed the attacker reused the same vulnerability class exploited back in May. That repetition raises hard questions about who is responsible for closing the gap.
An attacker abused the bridge's import path on Wednesday, per Blockaid. This triggered unbacked payouts on the Ethereum side of the system. Assets drained included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
The stolen funds were converted into roughly 3,916 ETH afterward. Proceeds then moved into Tornado Cash, according to CertiK's tracking. This mirrors the laundering pattern seen after May's earlier breach.
The May 18 exploit drained about $11.5 million from the same bridge. That attacker later returned 4,052 ETH under a negotiated bounty deal. Verus claimed it had introduced tighter transaction proofs afterward.
Blockaid says this new attack used the same contract, entry path, and bug class as May. Only the attacker's wallet differed between the two incidents. This repetition strongly suggests the root flaw was never fully patched.
That pattern points to a troubling lack of urgency from developers. Fixing surface symptoms without addressing root causes invites exactly this outcome. Verus has not yet detailed what its post-May remediation actually covered.
Security researchers note that bridges are especially attractive repeat targets. Once an entry path proves exploitable, attackers often revisit it later. Wednesday's incident fits that broader pattern seen across DeFi this year.
VRSC fell roughly 14% within hours of Wednesday's hack. Most of that drop was recovered shortly afterward. Trading data showed buyers stepping in quickly to absorb the selling.
May's exploit told a starkly different story. VRSC crashed nearly 48% in a single day back then. The token has still not recovered those losses months later.

The contrast suggests market participants now view smaller exploits as less alarming. Repeated incidents can paradoxically dull investor reaction over time. That desensitization carries its own risks for long-term token holders.
This second exploit exposes deep gaps in Verus's security process. Based on Blockaid’s findings, three specific failures stand out clearly across both incidents.
First, inadequate input and logic validation persisted unaddressed since May. The bridge reportedly lacked proper source-amount checks on incoming imports. This lets attackers trigger payouts without any matching deposits.
Second, developers failed to remediate a known, previously flagged vulnerability. Blockaid explicitly linked this new attack to May's unresolved bug class. Patching one instance without fixing the underlying logic invited repetition.
Third, the bridge over-relied on proof messaging without sufficient guardrails. Transaction proofs alone couldn't stop a malicious, well-crafted import. Systems need extra checks beyond message verification to catch unbacked transfers reliably.
Together, these failures point to rushed fixes rather than genuine root-cause remediation. Cross-chain bridges demand rigorous validation given the enormous value they secure. Hacken's Q2 report already logged $32.78 million in bridge losses industry-wide.

Users and integrators now have far less reason to trust Verus's stated fixes. A single patch clearly wasn't enough to close the underlying gap. Comprehensive, independent audits appear overdue rather than incremental, reactive patching cycles.
The recovery in VRSC's price doesn't erase the deeper concern here. Confidence in bridge security depends on consistent engineering discipline, not luck. Verus now faces pressure to prove its infrastructure can be trusted.
Repeated exploits erode confidence faster than any single hack ever could. Until developers close these gaps for good, the bridge remains an obvious target. The next attacker may not need to wait two months.
No comments yet
Be the first to share your take when accounts launch.