Logo Daily Crypto Briefs
Open menu

Verus Bridge Hit Again: $7.5M Exploit Reuses May Flaw

7 min read
Breaking News
Large official blue Verus wordmark and V emblem on an off-white editorial plaque beside a greyscale damaged cross-chain bridge control console with a blank incident document.

TL;DR

  • The Verus-Ethereum bridge lost about $7.54 million on July 23, its second major exploit since May.
  • Blockaid said the attacker used the bridge's import path to trigger unbacked Ethereum-side payouts, a route connected to the previous incident's vulnerability class.
  • The two reported attacks total roughly $19.1 million before any recoveries, putting the July bridge restoration under fresh scrutiny.
  • VRSC was listed near $0.61 with a market capitalization near $49 million on CoinGecko's latest available data.

CASABLANCA, July 24, 2026

The Verus-Ethereum bridge was exploited for about $7.54 million on July 23, its second major loss in roughly two months, after an attacker used an import route that security firm Blockaid linked to the same vulnerability class flagged in May.

The incident drained ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD from the bridge’s Ethereum-side reserves, according to Blockaid’s July 23 incident coverage. It is a bridge failure, not evidence that Ethereum’s base layer was compromised, but it again puts the security of the contract that connects Verus with Ethereum under scrutiny.

The two reported events now amount to about $19.12 million before any recoveries or later reconciliation. CoinDesk reported the May loss at roughly $11.58 million and the new loss at $7.54 million, while Blockaid said the latest attacker reached the same import path and used a new loot wallet.

VRSC was listed near $0.61 with a market capitalization around $49 million on CoinGecko’s latest available Verus page. Its historical data showed a close of about $0.42 on July 3, $0.57 on July 10, $0.59 on July 14 and $0.61 on July 19, though thin trading means those readings should not be treated as a full measure of bridge-user losses.

Blockaid said the attacker used the bridge’s import path to trigger “unbacked Ethereum-side payouts.” In plain terms, the bridge released assets held on Ethereum without a matching, valid transfer being proved from the other side of the system, the security firm’s description indicates.

The timing makes the episode especially consequential for users assessing bridge risk. Verus’s own Ethereum Bridge page presents the service as a way to move assets between the networks, and Verus had recently carried out recovery and restoration work after the May breach. A bridge that is reopened after a security event must not only restore connectivity but also show that its withdrawal checks and operational controls withstand the specific route used in the first attack.

Verus

VRSC
June 24 to July 24, 2026
$0.6095
+58.7%
Jun 24 - Jul 24 | High $0.6095 Low $0.374

Verus Bridge Exploit Reopens the May Security Failure

A cross-chain bridge is a specialized custody and verification system. It commonly locks an asset on one network and releases or issues a corresponding asset on another. That makes the bridge’s validation logic, its upgrade controls and the keys that govern it a concentrated point of risk even when the networks it connects remain intact.

The July attack was not an isolated headline in an otherwise quiet market. CoinDesk counted at least three bridge or cross-chain protocol drains within about six hours, totaling more than $35 million, including a separate AFX Trade incident and a B² Network staking-contract compromise. The circumstances differed, but the cluster pointed to a familiar problem: a system can fail through a flawed verification rule or through a compromised authority without any break in the cryptography of Bitcoin or Ethereum.

For Verus, the repeat event is more specific. Blockaid’s characterization connects the July withdrawal route to the contract, entry path and vulnerability class associated with the May incident. The firm did not identify the attacker, and it was not immediately clear whether every affected asset holder would be made whole or whether the bridge would be paused again.

That distinction is important. An exploit involving unbacked payouts can leave an asset on one network without the reserves that were meant to support it on the other. It is not enough for a bridge to resume normal-looking transfers; users need clear information about reserves, the exact fix and whether the checks that failed have been independently reviewed.

The episode echoes the June Taiko bridge exploit, where a chain paused block production and bridge functions after a proof-validation failure. In both cases, the security question sits at the connection between systems, rather than at the consensus rules of a major base chain.

$19.1M in Reported Verus Losses Tests the Recovery Plan

The reported arithmetic is stark. The May incident was estimated at around $11.58 million, and the July attack at about $7.54 million. Together, that is approximately $19.12 million. The figure is a reported gross-loss measure, not a final accounting, because asset recoveries, valuations at different times and later claims processes can change the net result.

After the first breach, Verus published software and bridge-recovery updates aimed at restoring cross-chain functionality. Its community release notes described a mandatory upgrade and a more constrained transaction proof intended to make valid exports easier to distinguish from data that only resembles an export. The latest exploit means the status of those changes, and of the Ethereum-side contracts used after restoration, will be central to any post-mortem.

The practical risk is not confined to people who trade VRSC. Bridge reserves included several external assets, and the reported mix ranged from ether and tokenized bitcoin to dollar stablecoins. Anyone who used the bridge or holds representations issued through it may need to distinguish the value of a token from the availability of the reserves that are supposed to back redemption.

The broader security backdrop has been worsening in frequency even when aggregate losses fluctuate. TRM Labs’ H1 report counted 207 crypto hacks in the first half of 2026, a record number of incidents in its dataset. The firm said infrastructure and operational compromises formed a small share of incidents but a much larger share of stolen value, a warning relevant to bridge contracts and their administrative safeguards.

What Verus Users Need to See Before the Bridge Returns

Verus has not, in the sources reviewed, published a full public technical post-mortem for the July 23 event. That leaves several material questions unanswered: whether the affected contract was paused, which contracts and reserves are affected, whether the same code path remains callable, and what recovery or compensation process will apply.

Users should treat bridge status notices, wallet prompts and social-media messages cautiously while those answers are pending. A legitimate update should lead back to Verus’s official channels and identify the relevant network, contract and software version. It should not ask a user to move assets to a new address or enter a recovery phrase.

The incident also draws a line between bridge availability and bridge assurance. Cross-chain transfers may be convenient, but the value of a bridged asset rests on the quality of the verification process and the safeguards around it. Until Verus gives a detailed explanation of the July exploit and the remedial work, the reported repeat loss is a reason for users to prioritize confirmation over speed.

Fear & Greed Index

July 24, 2026
28 Fear

The Crypto Fear and Greed Index read 28, classified as Fear, on July 24. It does not measure the Verus incident, but it underscores a cautious market setting for bridge users deciding whether to take new cross-chain exposure.

The next test is Verus’s incident response: a contract-level explanation, a clear statement on reserves and user claims, and evidence that the route used in both episodes can no longer produce an unbacked withdrawal. Without those details, users cannot independently assess whether bridge service has returned with a materially stronger security posture.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

What happened to the Verus-Ethereum bridge on July 23?

Blockaid said an attacker used the bridge's import path to trigger unbacked payouts on Ethereum, draining about $7.54 million in ETH, tBTC, stablecoins and other assets from bridge reserves.

Was this the first Verus bridge exploit?

No. The July incident followed a May attack that was reported at about $11.58 million. Reporting from Blockaid and CoinDesk linked the latest attack to the same bridge contract, import path and vulnerability class.

Did the exploit compromise Ethereum itself?

No evidence indicates that Ethereum's base layer was compromised. The reported issue involved the application-specific Verus-Ethereum bridge, which holds assets and verifies cross-chain transfers.

How much did the two reported Verus bridge attacks total?

The reported May loss of about $11.58 million and the July loss of about $7.54 million add to roughly $19.12 million before taking account of any asset recoveries or later reconciliations.

What should Verus bridge users watch next?

Users should rely on the project’s official channels for bridge status, contract and upgrade information, and should not assume a bridge is safe to use until the team provides a clear incident response and restoration update.