Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack

Blockaid and exvulsec confirmed the exploit after an attacker abused Verus Bridge's submitImports function to drain $7.54 million across seven assets, including 1,137 ETH, into attacker-controlled wallets.

Written By Dishita Malvania
Edited by Divya Mistry
Published 2026-07-23·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack

The Verus Ethereum Bridge has been drained for the second time in just over two months, with an attacker siphoning roughly $7.54 million in assets on July 23, 2026, by abusing the same import path that was weaponized against the protocol in May.

AI Summary
Show
Verus Ethereum Bridge’s second major exploit in two months exposes broader industry vulnerabilities in cross-chain infrastructure
Recurring attacks on bridges and off-chain systems highlight key management and validation logic as softer targets for hackers
July’s $7.54 million drain underscores the need for improved security measures and robust post-mortem analysis to prevent repeated exploits

Onchain security firm Blockaid flagged the incident in real time, and independent researcher exvulsec confirmed the exploit signature within minutes of the drain.

🚨 ALERT: @exvulsec detected a new exploit targeting the @VerusCoin Ethereum Bridge on Ethereum.

The attacker used the bridge import path (`submitImports`) to trigger Ethereum-side payouts, draining ~$7.54M from bridge reserves across ETH, tBTC, USDC, USDT, EURC, MKR, and…

— ExVul (@exvulsec) July 23, 2026

The stolen basket spans seven assets held in the bridge’s Ethereum-side reserves, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. According to an alert on X, the attacker used the bridge’s submitImports function to trigger Ethereum-side payouts that were never properly backed by matching value committed on the Verus source chain.

Onchain forensics: Transaction, contracts, and wallets

The exploit was executed in a single primary transaction at approximately 03:45 UTC on July 23. Etherscan records show the drain occurred through the following addresses, all of which have been circulated for downstream monitoring:

  • Exploit transaction: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
  • Target bridge contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
  • Attacker EOA: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
  • Loot wallet: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

The single largest movement in that transaction was a transfer of 1,137 ETH from the bridge to the attacker-controlled loot wallet, alongside proportionate withdrawals of the tokenised BTC, stablecoin, and MKR reserves. Etherscan’s on-page valuation placed the aggregate outflow at approximately $7.54 million at the time of the block.

Exploit tx:
https://t.co/XPN25gbZp4
Target bridge contract: 0x71518580f36feceffe0721f06ba4703218cd7f63

Funds were transferred from the bridge to attacker-controlled wallet:
0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54

— Blockaid (@blockaid_) July 23, 2026

According to onchain data compiled after the drain, the attacker consolidated the stolen basket into 3,916 ETH through decentralised exchange routes and then began routing portions of it through Tornado Cash. The conversion pattern mirrors the laundering playbook seen in the May incident, where speed of asset consolidation was prioritised to reduce the window in which stablecoin issuers could freeze balances.

The bug class: Unbacked payouts through submitImports

Blockaid described the July exploit as belonging to the same bug class as the May 18 breach, with the attacker “using the bridge’s import path to trigger payouts that were not backed by matching assets on the source side.” In practical terms, the Ethereum-side contract released real reserves in response to an import claim that did not carry corresponding value locked on the Verus side.

This maps to the same architectural gap identified in May, when the post-mortem attributed the earlier $11.58 million loss to a missing source-amount validation in the bridge’s checkCCEValues verification routine. 

The Ethereum contract at the time was correctly verifying the notarised Verus state root (with 8-of-15 valid notary signatures), the Merkle proof, and the transaction hash binding, but it never confirmed that the value committed on Verus matched the value being released on Ethereum. That gap belongs to the same structural family as the 2022 Wormhole and Nomad breaches, where source-to-destination economic-value binding was inadequately enforced.

The July 23 thread stated the new attack used the “same bridge contract, same entry path, and same bug class” as the May exploit, differing only in the attacker EOA and loot wallet. 

A confirmed root-cause disclosure for the July incident has not yet been published, and it is unclear whether the reused entry path indicates an incomplete patch, a re-introduced regression, or a distinct code path with the same downstream effect. 

As previously reported by The Crypto Times, the May attacker later returned 4,052.4 ETH worth around $8.5 million after Verus offered settlement terms, keeping 1,350 ETH as an agreed bounty.

Part of a wider $35 million day for cross-chain hacks

The Verus drain landed inside a six-hour window that saw at least three protocols compromised. Onchain tracker Lookonchain estimated aggregate losses across the incidents at roughly $35.55 million, with the breakdown as follows:

  • AFX Trade (Arbitrum-based decentralised perpetuals venue): approximately $24.15 million in USDC. The exploit was detected at 21:30 UTC on July 22 and confirmed it targeted a bridge operated by AFX rather than Arbitrum’s native bridge. PeckShield reported the attacker moved the stolen USDC to Ethereum and swapped it for 12,467 ETH. Offchain Labs co-founder Steven Goldfeder clarified on X that “the Arbitrum native bridge has not been hacked or exploited in any way,” attributing the compromise to hot-validator signing keys on the third-party bridge.
  • Verus Ethereum Bridge: approximately $7.54 million, as detailed above.
  • B² Network: approximately $3.86 million after an attacker seized upgrade authority over the network’s staking contract, a permissions-based failure rather than a cryptographic one.

Blockaid framed the day’s clustered incidents as a continued shift in attacker focus toward bridge and off-chain infrastructure, where key management, permission scoping, and validation logic remain softer targets than the underlying smart contracts themselves. This pattern has now defined most of 2026’s largest DeFi losses, as previously covered in The Crypto Times’ bridge-exploit article, which recorded bridge-related theft exceeding $328 million even before the July drains.

Response and outstanding questions

VerusCoin has not issued a public statement on the July 23 exploit at the time of writing. Blockaid and exvulsec have asked exchanges, stablecoin issuers, and analytics providers to flag both the attacker EOA (0xBda7…855c) and the loot wallet (0xCFd0…2D54) for any downstream movement, including further Tornado Cash deposits or attempted centralised exchange offramps.

Three questions remain open as the investigation progresses. First, whether the May patch was reverted, incomplete, or bypassed through a distinct code path. Second, why bridge reserves were replenished to a level sufficient to support a $7.54 million second drain while the underlying entry path remained a known-abused vector. Third, whether the July attacker will be offered settlement terms similar to the May actor, or whether Verus will pursue tracing and freeze action instead.

For a protocol that historically marketed its Ethereum bridge as “trustless” and structurally resistant to the failure modes of Wormhole-era bridges, a repeat drain through the same import path is a materially damaging outcome, and the pressure on the Verus team to publish a full technical post-mortem, along with a credible fix, is now considerably higher than it was in May.

Also Read: Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Smartphone screen displaying the Kalshi logo against a bright green background.
Kalshi Loses Emergency Injunction Bid in Utah Gambling Case
Gold Bitcoin coin with handcuffs, an FBI jacket, and a laptop showing financial charts in the background.
FBI Uses Crypto Tracing to Link Jacksonville Brothers to Darknet Opioid Case
Compound logo on a dark wall.
Compound Launches Institutional Market for DeFi Lending
XRP Faces Key $1.43 Test After 28.5% August Rally
XRP Faces Key $1.43 Test After 28.5% August Rally
Hand holding a smartphone displaying Circle Internet Group stock chart with the Circle logo on a wall in the background
Circle Stock Declines 5% Following Tazapay Announcement

Find Us on Socials

You may also like

Physical silver Ethereum coin sitting on a wooden desk next to a laptop displaying an upward-trending candlestick chart.

Ethereum Price Prediction September 2026: Can ETH Reach $2,800?

European Union-themed euro coins and an Ethereum symbol displayed in front of a blue MiCA binder and EU flag buildings.

37 European Banks Plan MiCA-Compliant Euro Stablecoin on Ethereum 

Etherscan logo displayed on a blue gradient background with subtle wave graphics.

Etherscan Launches Etherscan Flow for Visual Transaction Tracing

Smartphone displaying Tectonic crypto app in front of glowing Cronos logo

Cronos Rewound 10,961 Blocks to Reverse Tectonic Hack, $9.19M Still Missing

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information