Loading market data...

Verus-Ethereum Bridge Hit by Second Exploit in 66 Days, $7.4 Million Drained

Verus-Ethereum Bridge Hit by Second Exploit in 66 Days, $7.4 Million Drained

The Verus-Ethereum bridge has been exploited for the second time in just over two months. Attackers drained roughly $7.4 million in various digital assets from the cross-chain protocol, the team confirmed Friday. The incident marks another blow to a bridge that had already been patched after a similar exploit in May.

Second exploit in 66 days

The latest attack hit the Verus-Ethereum bridge on July 23, 2026. According to the project's post-mortem, the exploit stemmed from a flaw in the smart contract logic — the same type of vulnerability that led to the first breach on May 18. That earlier attack cost the bridge about $4.2 million. Combined, the two exploits have drained roughly $11.6 million from the protocol.

The Verus team said it paused the bridge immediately after detecting the suspicious activity. Withdrawals were halted for roughly six hours while the team assessed the damage and deployed an emergency fix. The bridge has since resumed normal operations.

Flawed logic, same bridge

The attacker exploited a bug in the bridge's verification logic, allowing them to mint tokens on Ethereum without depositing the corresponding collateral on Verus's side. The team's initial analysis suggests the vulnerability was introduced during a routine upgrade in early July — a change meant to improve throughput. That upgrade inadvertently reintroduced a similar bug to the one patched in May.

Verus has not named the attacker or any specific exchange where the stolen funds may have been moved. The team said it is working with blockchain analytics firms and law enforcement, but declined to provide further details.

What users saw

Users on both sides of the bridge reported failed transactions and long delays during the outage. Some took to social media to complain about the lack of communication in the first few hours. The Verus team posted an initial alert on X roughly 90 minutes after the exploit began, then followed up with a more detailed update three hours later.

For those who had funds stuck in transit, the bridge's resumption meant their transactions eventually cleared — though some had to manually retry. The team said no user funds were permanently lost beyond the stolen amount, which came from the bridge's liquidity pool.

The Verus team has committed to a third-party audit of the entire bridge codebase, with results expected within four weeks. They've also said they will implement a timelock on future upgrades to give users and security researchers time to review changes before they go live.

Whether that will be enough to restore user confidence is an open question. The bridge has now been exploited twice in a span of 66 days, and the second bug was introduced by the team's own upgrade. Verus's native token, VRSC, dropped about 12% in the hours after the news broke, though it has since recovered some of those losses.

The team has not announced a specific compensation plan for the stolen funds, but said it is exploring options. A more detailed post-mortem is expected next week.