Verus bridge hacked again for $7.54M as an old bug class keeps draining crypto

- An attacker stole about $7.54 million from the Verus Ethereum bridge, exploiting the same vulnerability used in an $11.58 million hack in May.
- The exploit stemmed from a missing validation check, allowing the bridge to release more assets on Ethereum than were backed on the Verus chain.
- The repeat attack highlights that unresolved vulnerabilities remain a major risk for cross-chain bridges, despite broader security improvements across DeFi.
An attacker managed to steal approximately $7.54 million from the Verus Ethereum bridge on Thursday. This is the second time within about two months that an exploit was carried out successfully using this bridge. It seems that the vulnerability that was discovered earlier this year was never completely fixed. This shows how some known vulnerabilities continue to threaten cross-chain systems.
Cross-chain bridges allow users to lock assets on one blockchain and consequently issue equivalent tokens on another blockchain. However, most bridges contain extremely large shared liquidity pools. Therefore, just one small mistake by validators can cause losses worth millions of dollars. According to the blockchain cybersecurity company Blockaid, the same thing appears to have occurred in the Verus attack, with the same type of bug affecting some of the largest crypto bridge hacks since 2022.
A repeat hit on the same contract
According to Blockaid, the assailant exploited the mechanism for imports of the bridge in order to activate Ethereum-related payouts that didn’t correspond to actual values on the Verus blockchain. The hacker was able to steal assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, with total losses that reached about $7.54 million in value terms.
The attack was focused on the Verus Ethereum bridge protocol contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63 while the money was tracked to the hacker’s wallet 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54.
The blockchain evidence is readily accessible on Etherscan. This includes the bridge contract, attacker’s wallet as well as the exploit transaction.
The incident is particularly interesting because it is very similar to another incident that happened in May 2026, the Verus bridge hack where $11.58 million was drained. Blockaid stated that both attacks targeted the same contract through the same import route, meaning that the vulnerability has not been fixed.
Why the bug pays out millions on pennies
Security companies Halborn and Merkle Science also reached the same conclusion based on their findings after analyzing the former attack.
“The vulnerability was not a cryptographic failure, but a missing validation ensuring that the value committed on the Verus chain matched the value released on Ethereum.” — Rob Behnke, Halborn
According to Halborn, a transaction worth even about 1 cent would still pass all of the bridge’s signatures and Merkle-proof requirements before the Ethereum smart contract is triggered to execute that transaction and release the assets worth millions of dollars.
According to Merkle Science, the cause of the issue was determined to be the checkCCEValues function in the bridge’s code.
“The bridge failed to validate that the source value matched the destination payout, allowing an attacker to spend only minimal fees while withdrawing millions.” — Mir Jalal, Merkle Science
The company believed that the problem stemmed from approximately 10 lines of missing Solidity validation, which allowed the attacker to convert about $10 worth of VRSC transaction fees into a payout of $11.58 million.
The two companies made it clear that the bridge’s cryptography and proof of validation were functioning as they should. The actual issue, however, was that the contract did not verify that the value being released on Ethereum was supported by the assets on the Verus chain. Merkle Science pointed out that the same type of validation failure was also responsible for the Wormhole and Nomad bridge exploits in 2022.
What it means for a market that thought bridges were safer
The Verus incident occurs at a time when other avenues in the cryptocurrency community have seen fewer losses from bridge attacks.
According to data collected by TRM Labs, there have been a total of 207 cybersecurity attacks on crypto, which is the highest seen in any six-month time span. On the contrary, total loss dropped from $2.3 billion to $972 million during the same timeframe in 2025, and median hack amount diminished to roughly $219,000 in the present period.
The security of bridges has also been boosted over the last few years. As indicated in a report from Immunefi, the percentage of DeFi losses related to bridge hacking in 2022 stood at 73%, but in 2025 that figure had dropped to only 3%. This indicates that the quality of audits and bridge designs in the market improved significantly.
Nonetheless, the breach at Verus reveals that advancements in the sector as a whole do not make up for existing unaddressed vulnerabilities. An issue that was first revealed after the May exploit seems to have been exploited again, propelling the narrative that dealing with known vulnerabilities is far more essential than assuming that they are no longer at risk.
Verus hasn’t published an official post-mortem for Thursday’s incident. In the wake of May’s incident, Merkle Science instructed users to refrain from using the bridge until the faulty validation was resolved and given the stamp of approval from a separate auditor. Users should exercise caution and stay clear of bridge transfers until the project is able to confirm that this work has been completed.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
How much was stolen in the Verus bridge attack?
Blockaid put the loss at roughly $7.54 million, taken in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from the bridge's reserves on Thursday.
Is this the same as the earlier Verus hack?
Blockaid says it appears related to the May 2026 Verus bridge incident, citing the same contract, entry path, and bug class, though this was a new transaction by a different attacker sending funds to a different wallet.
What caused the underlying flaw?
According to Halborn and Merkle Science, the bridge verified signatures and proofs correctly but never checked that the value committed on the Verus side matched the payout claimed on Ethereum, a missing validation Merkle Science located in the checkCCEValues function.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ashish Kumar
Ashish Kumar is a crypto and financial journalist with eight years of newsroom experience. He covers what’s happening with crypto markets, regulation, DeFi, and exchange ecosystems. He has worked with Coingape, Todayq, and Newsroompost. Ashish holds a PGDP in English Journalism from the IIMC. He has also interviewed industry figures including Arthur Hayes, Yat Siu, Austin Federa, and more.
















