Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    The Robinhood Chain Paradox Built for Tokenized Stocks, Dominated by Memecoins
    The Robinhood Chain Paradox: Built for Tokenized Stocks, Dominated by Memecoins
    Senators to Brief Trump on CLARITY Act Path - Here's What to Expect
    Senators to Brief Trump on CLARITY Act Path – Here’s What to Expect
    CLARITY Act 5 Fights Still Unresolved Before the Merged Draft Drops
    CLARITY Act: 5 Fights Still Unresolved Before the Merged Draft Drops
  • Opinion
    OpinionShow More
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack

Blockaid and exvulsec confirmed the exploit after an attacker abused Verus Bridge's submitImports function to drain $7.54 million across seven assets, including 1,137 ETH, into attacker-controlled wallets.

Written By Dishita Malvania
Edited by Divya Mistry
Published 1 hour ago·Updated 51 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Share
Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack

The Verus Ethereum Bridge has been drained for the second time in just over two months, with an attacker siphoning roughly $7.54 million in assets on July 23, 2026, by abusing the same import path that was weaponized against the protocol in May.

AI Summary
Show
Verus Ethereum Bridge’s second major exploit in two months exposes broader industry vulnerabilities in cross-chain infrastructure
Recurring attacks on bridges and off-chain systems highlight key management and validation logic as softer targets for hackers
July’s $7.54 million drain underscores the need for improved security measures and robust post-mortem analysis to prevent repeated exploits

Onchain security firm Blockaid flagged the incident in real time, and independent researcher exvulsec confirmed the exploit signature within minutes of the drain.

🚨 ALERT: @exvulsec detected a new exploit targeting the @VerusCoin Ethereum Bridge on Ethereum.

The attacker used the bridge import path (`submitImports`) to trigger Ethereum-side payouts, draining ~$7.54M from bridge reserves across ETH, tBTC, USDC, USDT, EURC, MKR, and…

— ExVul (@exvulsec) July 23, 2026

The stolen basket spans seven assets held in the bridge’s Ethereum-side reserves, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. According to an alert on X, the attacker used the bridge’s submitImports function to trigger Ethereum-side payouts that were never properly backed by matching value committed on the Verus source chain.

Onchain forensics: Transaction, contracts, and wallets

The exploit was executed in a single primary transaction at approximately 03:45 UTC on July 23. Etherscan records show the drain occurred through the following addresses, all of which have been circulated for downstream monitoring:

  • Exploit transaction: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
  • Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
  • Attacker EOA: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
  • Loot wallet: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

The single largest movement in that transaction was a transfer of 1,137 ETH from the bridge to the attacker-controlled loot wallet, alongside proportionate withdrawals of the tokenised BTC, stablecoin, and MKR reserves. Etherscan’s on-page valuation placed the aggregate outflow at approximately $7.54 million at the time of the block.

Exploit tx:
https://t.co/XPN25gbZp4
Target bridge contract: 0x71518580f36feceffe0721f06ba4703218cd7f63

Funds were transferred from the bridge to attacker-controlled wallet:
0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

— Blockaid (@blockaid_) July 23, 2026

According to onchain data compiled after the drain, the attacker consolidated the stolen basket into 3,916 ETH through decentralised exchange routes and then began routing portions of it through Tornado Cash. The conversion pattern mirrors the laundering playbook seen in the May incident, where speed of asset consolidation was prioritised to reduce the window in which stablecoin issuers could freeze balances.

The bug class: Unbacked payouts through submitImports

Blockaid described the July exploit as belonging to the same bug class as the May 18 breach, with the attacker “using the bridge’s import path to trigger payouts that were not backed by matching assets on the source side.” In practical terms, the Ethereum-side contract released real reserves in response to an import claim that did not carry corresponding value locked on the Verus side.

This maps to the same architectural gap identified in May, when the post-mortem attributed the earlier $11.58 million loss to a missing source-amount validation in the bridge’s checkCCEValues verification routine. 

The Ethereum contract at the time was correctly verifying the notarised Verus state root (with 8-of-15 valid notary signatures), the Merkle proof, and the transaction hash binding, but it never confirmed that the value committed on Verus matched the value being released on Ethereum. That gap belongs to the same structural family as the 2022 Wormhole and Nomad breaches, where source-to-destination economic-value binding was inadequately enforced.

The July 23 thread stated the new attack used the “same bridge contract, same entry path, and same bug class” as the May exploit, differing only in the attacker EOA and loot wallet. 

A confirmed root-cause disclosure for the July incident has not yet been published, and it is unclear whether the reused entry path indicates an incomplete patch, a re-introduced regression, or a distinct code path with the same downstream effect. 

As previously reported by The Crypto Times, the May attacker later returned 4,052.4 ETH worth around $8.5 million after Verus offered settlement terms, keeping 1,350 ETH as an agreed bounty.

Part of a wider $35 million day for cross-chain hacks

The Verus drain landed inside a six-hour window that saw at least three protocols compromised. Onchain tracker Lookonchain estimated aggregate losses across the incidents at roughly $35.55 million, with the breakdown as follows:

  • AFX Trade (Arbitrum-based decentralised perpetuals venue): approximately $24.15 million in USDC. The exploit was detected at 21:30 UTC on July 22 and confirmed it targeted a bridge operated by AFX rather than Arbitrum’s native bridge. PeckShield reported the attacker moved the stolen USDC to Ethereum and swapped it for 12,467 ETH. Offchain Labs co-founder Steven Goldfeder clarified on X that “the Arbitrum native bridge has not been hacked or exploited in any way,” attributing the compromise to hot-validator signing keys on the third-party bridge.
  • Verus Ethereum Bridge: approximately $7.54 million, as detailed above.
  • B² Network: approximately $3.86 million after an attacker seized upgrade authority over the network’s staking contract, a permissions-based failure rather than a cryptographic one.

Blockaid framed the day’s clustered incidents as a continued shift in attacker focus toward bridge and off-chain infrastructure, where key management, permission scoping, and validation logic remain softer targets than the underlying smart contracts themselves. This pattern has now defined most of 2026’s largest DeFi losses, as previously covered in The Crypto Times’ bridge-exploit article, which recorded bridge-related theft exceeding $328 million even before the July drains.

Response and outstanding questions

VerusCoin has not issued a public statement on the July 23 exploit at the time of writing. Blockaid and exvulsec have asked exchanges, stablecoin issuers, and analytics providers to flag both the attacker EOA (0xBda7…855c) and the loot wallet (0xCFd0…2D54) for any downstream movement, including further Tornado Cash deposits or attempted centralised exchange offramps.

Three questions remain open as the investigation progresses. First, whether the May patch was reverted, incomplete, or bypassed through a distinct code path. Second, why bridge reserves were replenished to a level sufficient to support a $7.54 million second drain while the underlying entry path remained a known-abused vector. Third, whether the July attacker will be offered settlement terms similar to the May actor, or whether Verus will pursue tracing and freeze action instead.

For a protocol that historically marketed its Ethereum bridge as “trustless” and structurally resistant to the failure modes of Wormhole-era bridges, a repeat drain through the same import path is a materially damaging outcome, and the pressure on the Verus team to publish a full technical post-mortem, along with a credible fix, is now considerably higher than it was in May.

Also Read: Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto HackEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Yet Another Corporate Bitcoin Sale: Smarter Web Repays $11.69M TOBAM Debt by Selling 178 BTC
Yet Another Corporate Bitcoin Sale: Smarter Web Repays $11.69M TOBAM Debt by Selling 178 BTC
Circle Says Korea Can Lead With Second-Mover Crypto Rules 
Circle Says Korea Can Lead With Second-Mover Crypto Rules 
SpaceX’e Tokenized Stock Adds 25% Holders in a Month While Volume Drops 31%
SpaceX’s Tokenized Stock Adds 25% Holders in a Month While Volume Drops 31%
Crypto's 'Hackers' Day' AFX Trade Hit for $24M, Losses Reach $35.55M
Crypto’s ‘Hackers’ Day’: AFX Trade Hit for $24M, Losses Reach $35.55M
Seven Democrats Say CLARITY Act Text 'Falls Short' as Thune Eyes Floor Vote
Seven Democrats Say CLARITY Act Text ‘Falls Short’ as Thune Eyes Floor Vote

Find Us on Socials

You may also like

Crypto Wrench Attacks Exposed $124M in H1 2026 CertiK Report

Crypto Wrench Attacks Exposed $124M in H1 2026: CertiK Report

Robinhood Chain Tops Base as TVL Climbs Above $305M

Robinhood Chain Tops Base as TVL Climbs Above $305M

Ostium to Resume Trading on July 23 After $18M Arbitrum Exploit

Ostium to Resume Trading on July 23 After $18M Arbitrum Exploit

SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft

SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information