The Verus Ethereum Bridge has been drained for the second time in just over two months, with an attacker siphoning roughly $7.54 million in assets on July 23, 2026, by abusing the same import path that was weaponized against the protocol in May.
Onchain security firm Blockaid flagged the incident in real time, and independent researcher exvulsec confirmed the exploit signature within minutes of the drain.
The stolen basket spans seven assets held in the bridge’s Ethereum-side reserves, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. According to an alert on X, the attacker used the bridge’s submitImports function to trigger Ethereum-side payouts that were never properly backed by matching value committed on the Verus source chain.
Onchain forensics: Transaction, contracts, and wallets
The exploit was executed in a single primary transaction at approximately 03:45 UTC on July 23. Etherscan records show the drain occurred through the following addresses, all of which have been circulated for downstream monitoring:
- Exploit transaction: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
- Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Attacker EOA: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
- Loot wallet: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
The single largest movement in that transaction was a transfer of 1,137 ETH from the bridge to the attacker-controlled loot wallet, alongside proportionate withdrawals of the tokenised BTC, stablecoin, and MKR reserves. Etherscan’s on-page valuation placed the aggregate outflow at approximately $7.54 million at the time of the block.
According to onchain data compiled after the drain, the attacker consolidated the stolen basket into 3,916 ETH through decentralised exchange routes and then began routing portions of it through Tornado Cash. The conversion pattern mirrors the laundering playbook seen in the May incident, where speed of asset consolidation was prioritised to reduce the window in which stablecoin issuers could freeze balances.
The bug class: Unbacked payouts through submitImports
Blockaid described the July exploit as belonging to the same bug class as the May 18 breach, with the attacker “using the bridge’s import path to trigger payouts that were not backed by matching assets on the source side.” In practical terms, the Ethereum-side contract released real reserves in response to an import claim that did not carry corresponding value locked on the Verus side.
This maps to the same architectural gap identified in May, when the post-mortem attributed the earlier $11.58 million loss to a missing source-amount validation in the bridge’s checkCCEValues verification routine.
The Ethereum contract at the time was correctly verifying the notarised Verus state root (with 8-of-15 valid notary signatures), the Merkle proof, and the transaction hash binding, but it never confirmed that the value committed on Verus matched the value being released on Ethereum. That gap belongs to the same structural family as the 2022 Wormhole and Nomad breaches, where source-to-destination economic-value binding was inadequately enforced.
The July 23 thread stated the new attack used the “same bridge contract, same entry path, and same bug class” as the May exploit, differing only in the attacker EOA and loot wallet.
A confirmed root-cause disclosure for the July incident has not yet been published, and it is unclear whether the reused entry path indicates an incomplete patch, a re-introduced regression, or a distinct code path with the same downstream effect.
As previously reported by The Crypto Times, the May attacker later returned 4,052.4 ETH worth around $8.5 million after Verus offered settlement terms, keeping 1,350 ETH as an agreed bounty.
Part of a wider $35 million day for cross-chain hacks
The Verus drain landed inside a six-hour window that saw at least three protocols compromised. Onchain tracker Lookonchain estimated aggregate losses across the incidents at roughly $35.55 million, with the breakdown as follows:
- AFX Trade (Arbitrum-based decentralised perpetuals venue): approximately $24.15 million in USDC. The exploit was detected at 21:30 UTC on July 22 and confirmed it targeted a bridge operated by AFX rather than Arbitrum’s native bridge. PeckShield reported the attacker moved the stolen USDC to Ethereum and swapped it for 12,467 ETH. Offchain Labs co-founder Steven Goldfeder clarified on X that “the Arbitrum native bridge has not been hacked or exploited in any way,” attributing the compromise to hot-validator signing keys on the third-party bridge.
- Verus Ethereum Bridge: approximately $7.54 million, as detailed above.
- B² Network: approximately $3.86 million after an attacker seized upgrade authority over the network’s staking contract, a permissions-based failure rather than a cryptographic one.
Blockaid framed the day’s clustered incidents as a continued shift in attacker focus toward bridge and off-chain infrastructure, where key management, permission scoping, and validation logic remain softer targets than the underlying smart contracts themselves. This pattern has now defined most of 2026’s largest DeFi losses, as previously covered in The Crypto Times’ bridge-exploit article, which recorded bridge-related theft exceeding $328 million even before the July drains.
Response and outstanding questions
VerusCoin has not issued a public statement on the July 23 exploit at the time of writing. Blockaid and exvulsec have asked exchanges, stablecoin issuers, and analytics providers to flag both the attacker EOA (0xBda7…855c) and the loot wallet (0xCFd0…2D54) for any downstream movement, including further Tornado Cash deposits or attempted centralised exchange offramps.
Three questions remain open as the investigation progresses. First, whether the May patch was reverted, incomplete, or bypassed through a distinct code path. Second, why bridge reserves were replenished to a level sufficient to support a $7.54 million second drain while the underlying entry path remained a known-abused vector. Third, whether the July attacker will be offered settlement terms similar to the May actor, or whether Verus will pursue tracing and freeze action instead.
For a protocol that historically marketed its Ethereum bridge as “trustless” and structurally resistant to the failure modes of Wormhole-era bridges, a repeat drain through the same import path is a materially damaging outcome, and the pressure on the Verus team to publish a full technical post-mortem, along with a credible fix, is now considerably higher than it was in May.
Also Read: Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens
