July 23, 2026 ChainGPT

Verus Ethereum Bridge Hit Again - $7.5M Stolen in Likely Repeat of May Exploit

Verus Ethereum Bridge Hit Again - $7.5M Stolen in Likely Repeat of May Exploit
The Verus Ethereum Bridge was hit again on July 23, with attackers siphoning roughly $7.54 million from the same bridge contract that was exploited in May. What happened - Blockchain security firm Blockaid flagged the attack on Ethereum at 03:45 UTC on July 23. Onchain traces show a transaction interacted with the Verus bridge contract (0x71518580f36feceffe0721f06ba4703218cd7f63) and moved about 1,137 ETH plus several tokens to an attacker-controlled address (0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54). Etherscan valued the outflows at about $7.54 million at the time. - Tokens transferred included tBTC, USDC, USDT, EURC, MKR and scrvUSD. - Blockaid says the attacker abused the bridge’s import path to trigger Ethereum-side payouts that were not backed by matching assets on the source chain — the same entry path and apparent bug class identified in the May incident. The new exploit involved a different transaction and a different attacker wallet than in May. A full technical root-cause report has not yet been published. Context and fallout - This is the second major drain on the same Verus bridge in roughly two months. In May the bridge lost about $11.58 million after researchers said a validation gap allowed a forged cross-chain import to pass verification, releasing more funds on Ethereum than were committed on the source chain. - After the May incident, the original exploiter returned 4,052.4 ETH (about $8.5M at the time) under settlement terms and retained roughly 1,350 ETH as a bounty — about 75% of the exploiter’s remaining holdings post-conversion. - The July Verus exploit came amid a cluster of attacks that same day. Onchain tracker Lookonchain reported combined reported losses of roughly $35.55 million across three incidents: AFX Trade ($24.15M), Verus ($7.55M) and B² Network ($3.86M). The AFX loss involved USDC on bridge infrastructure run by a third party and was later converted into 12,467 ETH, with Offchain Labs clarifying it did not affect Arbitrum’s native bridge. Why this matters - Cross-chain bridges remain high-risk because they must validate events across disparate blockchains while safeguarding pooled assets. Failures in message validation, contract logic or access controls can enable unbacked payouts like those seen here. - Blockaid has described the July attack as “appears related to the previous Verus Ethereum Bridge incident in May,” noting the same contract, entry path and bug class, but it has not confirmed that the exact same vulnerability was re-exploited. Current status - At publication, sources confirm the funds left the Verus bridge for the new attacker wallet, but it is not clear whether any stolen assets have been frozen, returned or recovered. No remediation timeline or updated bridge operations plan has been released. - Further technical analysis is needed to determine whether the May flaw was left unpatched, whether a related weakness was used, or if the attacker exploited a different route through the import process. The attacker’s subsequent moves (conversions, mixers, or withdrawals) will be monitored for signs of fund laundering or recovery opportunities. Key links - Target bridge contract: https://etherscan.io/address/0x71518580f36feceffe0721f06ba4703218cd7f63 - Attacker address: https://etherscan.io/address/0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 This story is developing; we will update with technical reports or recovery news as they become available. Read more AI-generated news on: undefined/news