An attacker managed to steal approximately $7.54 million from the Verus Ethereum bridge on Thursday. This is the second time within about two months that an exploit was carried out successfully using this bridge. It seems that the vulnerability that was discovered earlier this year was never completely fixed. This shows how some known vulnerabilities continue to threaten cross-chain systems.
Cross-chain bridges allow users to lock assets on one blockchain and consequently issue equivalent tokens on another blockchain. However, most bridges contain extremely large shared liquidity pools. Therefore, just one small mistake by validators can cause losses worth millions of dollars. According to the blockchain cybersecurity company Blockaid, the same thing appears to have occurred in the Verus attack, with the same type of bug affecting some of the largest crypto bridge hacks since 2022.
According to Blockaid, the assailant exploited the mechanism for imports of the bridge in order to activate Ethereum-related payouts that didn’t correspond to actual values on the Verus blockchain. The hacker was able to steal assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, with total losses that reached about $7.54 million in value terms.
The attack was focused on the Verus Ethereum bridge protocol contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63 while the money was tracked to the hacker’s wallet 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54.
The blockchain evidence is readily accessible on Etherscan. This includes the bridge contract, attacker’s wallet as well as the exploit transaction.
The incident is particularly interesting because it is very similar to another incident that happened in May 2026, the Verus bridge hack where $11.58 million was drained. Blockaid stated that both attacks targeted the same contract through the same import route, meaning that the vulnerability has not been fixed.
Security companies Halborn and Merkle Science also reached the same conclusion based on their findings after analyzing the former attack.
“The vulnerability was not a cryptographic failure, but a missing validation ensuring that the value committed on the Verus chain matched the value released on Ethereum.” — Rob Behnke, Halborn
According to Halborn, a transaction worth even about 1 cent would still pass all of the bridge’s signatures and Merkle-proof requirements before the Ethereum smart contract is triggered to execute that transaction and release the assets worth millions of dollars.
According to Merkle Science, the cause of the issue was determined to be the checkCCEValues function in the bridge’s code.
“The bridge failed to validate that the source value matched the destination payout, allowing an attacker to spend only minimal fees while withdrawing millions.” — Mir Jalal, Merkle Science
The company believed that the problem stemmed from approximately 10 lines of missing Solidity validation, which allowed the attacker to convert about $10 worth of VRSC transaction fees into a payout of $11.58 million.
The two companies made it clear that the bridge’s cryptography and proof of validation were functioning as they should. The actual issue, however, was that the contract did not verify that the value being released on Ethereum was supported by the assets on the Verus chain. Merkle Science pointed out that the same type of validation failure was also responsible for the Wormhole and Nomad bridge exploits in 2022.
The Verus incident occurs at a time when other avenues in the cryptocurrency community have seen fewer losses from bridge attacks.
According to data collected by TRM Labs, there have been a total of 207 cybersecurity attacks on crypto, which is the highest seen in any six-month time span. On the contrary, total loss dropped from $2.3 billion to $972 million during the same timeframe in 2025, and median hack amount diminished to roughly $219,000 in the present period.
The security of bridges has also been boosted over the last few years. As indicated in a report from Immunefi, the percentage of DeFi losses related to bridge hacking in 2022 stood at 73%, but in 2025 that figure had dropped to only 3%. This indicates that the quality of audits and bridge designs in the market improved significantly.
Nonetheless, the breach at Verus reveals that advancements in the sector as a whole do not make up for existing unaddressed vulnerabilities. An issue that was first revealed after the May exploit seems to have been exploited again, propelling the narrative that dealing with known vulnerabilities is far more essential than assuming that they are no longer at risk.
Verus hasn’t published an official post-mortem for Thursday’s incident. In the wake of May’s incident, Merkle Science instructed users to refrain from using the bridge until the faulty validation was resolved and given the stamp of approval from a separate auditor. Users should exercise caution and stay clear of bridge transfers until the project is able to confirm that this work has been completed.
The smartest crypto minds already read our newsletter. Want in? Join them.