The Verus–Ethereum Bridge has been drained for the second time in roughly two months, raising uncomfortable questions about whether a vulnerability that was already exploited once was ever truly fixed. Security firm Blockaid detected the latest Verus Ethereum bridge exploit and confirmed that an attacker abused the bridge’s import path to trigger unbacked payouts on the Ethereum side, walking away with approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. All of the stolen assets were subsequently converted into ETH.
Summary
Key takeaways
- The Verus–Ethereum Bridge was exploited twice within two months, with the latest theft totaling approximately $7.54 million.
- Both attacks abused the same bridge import path and vulnerability class, triggering unbacked Ethereum-side payouts.
- The May exploit drained around $11.5 million; the attacker later returned 4,052.4 ETH after keeping a 25% white-hat bounty.
- Recovered funds were redeposited into the bridge on July 8 — and the bridge was drained again shortly after.
- The latest attack was carried out by a different attacker using a new wallet, according to Blockaid.
Second Exploit Hits Verus–Ethereum Bridge Within Two Months
What makes this incident particularly striking is not just the amount stolen, but the timing and the mechanics behind it. The bridge had only recently received back most of the funds taken in the May 18 exploit, which had drained around $11.5 million. Those recovered assets were redeposited into the same bridge on July 8. Within two weeks, a second attacker struck — using the same contract, the same entry path, and the same class of flaw.
According to Blockaid, the latest attacker operated from a new wallet and had no apparent connection to the May incident. The two exploits are linked not by actor, but by opportunity: an unresolved structural weakness that remained accessible to anyone who knew where to look.
Details of the Latest $7.54 Million Theft
The exploit followed the same mechanical logic as its predecessor. By manipulating the bridge’s import path, the attacker forced the Ethereum side of the bridge to release real assets against claims that carried little or no backing on the Verus side. The result was a multi-token drain — ETH, tokenized Bitcoin, a spread of stablecoins including USDC, USDT, and EURC, plus MKR and scrvUSD — all funneled out and quickly consolidated into ETH.
Blockaid flagged the attack in real time, noting explicitly that the vulnerability class was identical to the one exploited in May. The firm’s detection highlighted that the same bridge contract and entry path had been used, pointing to a flaw that persisted across both incidents.
Comparison with the May Exploit and Attackers Involved
The May event was larger in raw dollar terms, with losses of roughly $11.5 million. The stolen assets at that time were converted into approximately 5,402.4 ETH. What followed was unusual for the crypto security space: the attacker returned 4,052.4 ETH, keeping a 25% white-hat bounty as compensation for identifying the flaw. The Verus team accepted the arrangement, and the returned funds were redeployed back into the bridge on July 8.
That decision now looks costly. Reintroducing liquidity into an unpatched system effectively reset the target. The second attacker — a different person, a fresh wallet, but the same playbook — exploited the window before any structural fix was in place, according to available onchain data reported by CoinDesk.
Vulnerability in Bridge Import Path Enables Unbacked ETH Payouts
The core flaw is straightforward in concept, even if dangerous in execution. Both exploits worked because the bridge’s import path could be manipulated to authorize payouts on the Ethereum side without corresponding assets being properly locked on the Verus side. The bridge released real money against claims worth almost nothing.
This type of logic flaw — where the code executes as written but the rules themselves allow funds to exit — is distinct from a cryptographic break. No encryption was cracked. The system was tricked through its own internal logic.
Nature of the Exploit and Common Vulnerability Class
Blockaid confirmed that both attacks shared the same vulnerability class. This is significant: it means the flaw was not patched between May and July, and the redeposition of funds on July 8 effectively reloaded a bridge that still carried a known, documented weakness.
The broader implication for cross-chain infrastructure is hard to ignore. A bridge’s safety depends entirely on the integrity of its verification mechanism — the process that confirms every withdrawal on one side is genuinely backed by assets locked on the other. When that mechanism has a known flaw and funds are redeployed without a confirmed fix, the system is not recovering. It is waiting.
Impact of Unresolved Flaws on Bridge Security
According to data cited by CoinDesk from DefiLlama, Verus held close to $100 million in total value locked at the start of 2025. As of the time of the latest exploit, that figure had fallen to around $9 million — a slow erosion accelerated sharply by the two hacks.
That trajectory matters beyond the raw loss numbers. Each exploit does not only remove the stolen amount; it signals to liquidity providers and users that the system may not be safe to engage with. The drain on confidence compounds the drain on assets.
Recovery Efforts and Fund Redeployment
The May incident produced one of the more unusual outcomes in recent crypto security history. After draining the bridge and converting assets into roughly 5,402.4 ETH, the attacker returned 4,052.4 ETH — keeping 25% as a white-hat fee. The Verus team accepted this partial recovery, and the returned funds were formally redeposited into the bridge on July 8, according to onchain records compiled by security researchers.
White-hat arrangements of this kind are not uncommon in DeFi. They offer a pragmatic path to partial recovery when legal enforcement is difficult and attackers are anonymous. But they carry an implicit assumption: that the vulnerability identified by the attacker will be addressed before the recovered funds go back into the system.
In this case, that assumption appears to have been wrong. The same entry path and vulnerability class that enabled the May theft remained available after the funds were redeposited — and a second, unrelated attacker found it within two weeks.
What This Means for Ethereum Bridge Security
The Verus situation is an extreme illustration of a pattern that is widening across cross-chain infrastructure. In a six-hour window on the same day as the latest Verus exploit, at least two other protocols were also drained in separate incidents, for a combined total exceeding $35 million across all affected platforms, according to CoinDesk’s reporting on blockchain data assessed by BlockAid and Peckshield. None of these attacks broke underlying cryptography. Each was either a logic flaw or a compromised permission — categories of vulnerability that audits can miss and that often persist quietly until someone with the right knowledge acts.
The Verus case adds a harder lesson: recovering funds from one exploit and reinserting them into an unpatched system does not restore security. It restores exposure. For users and liquidity providers assessing cross-chain bridges, the question is no longer just whether a bridge has been audited, but whether identified flaws have been verifiably remediated before capital flows back in.
FAQ
What was the cause of the Verus–Ethereum Bridge exploits?
Both exploits abused the bridge’s import path, triggering unbacked Ethereum-side payouts due to the same vulnerability class. The bridge released real assets against claims that were not properly backed on the Verus side.
How much was stolen in the recent Verus–Ethereum Bridge exploit?
Approximately $7.54 million was drained in various tokens — including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD — and subsequently converted into ETH.
Were the funds from the previous hack fully lost?
No. The May attacker returned 4,052.4 ETH after keeping a 25% white-hat bounty. Those funds were redeposited into the bridge on July 8, before the second exploit occurred.
Is the current exploit carried out by the same attacker as before?
No. According to Blockaid, the latest attack was carried out by a different attacker using a new wallet, with no apparent connection to the May incident.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

