An attacker exploited the Verus-Ethereum Bridge on July 23 to drain approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD, according to security firm Blockaid. The stolen assets were converted to ETH and moved to a new wallet.

The exploit targeted the same vulnerability class and bridge contract entry path as an $11.5 million incident on May 18, but was executed by a different attacker. Blockaid's detection shows the bridge has now suffered two major drains through identical attack vectors within nine weeks, with no substantive fix deployed between them.

Rain total value locked, last 90 days
Rain total value locked, last 90 days · MSB Intel data desk

In the May incident, an attacker abused the bridge's import path to trigger unbacked Ethereum-side payouts. That attacker later returned 4,052.4 ETH after keeping a 25 percent white-hat bounty; Blockaid says those returned funds were redeposited into the bridge on July 8. The May attacker had initially stolen approximately 5,402.4 ETH worth of value before the partial return.

MSB Intel

The Verus-Ethereum Bridge facilitates cross-chain transfers between the Verus blockchain and Ethereum. Like other bridge protocols, it holds collateral on both sides to back issued tokens. The vulnerability allowed attackers to drain assets by manipulating how the bridge processes inbound transfers, creating a mismatch between tokens locked and tokens minted.

No official statement from Verus or the bridge operator has addressed the second exploit. The May incident preceded discussion of a white-hat bounty return, but the bridge remained operational with the same code path exposed. The July attack occurred just two weeks after redeposited funds returned to the bridge.

The $18.64 million in combined losses from both incidents represents the majority of bridge exploits attributed to single protocols in 2026. Blockaid separately reported that multiple protocols lost $35 million to attacks within hours on July 23.

A new attacker executed the second exploit using an unconnected wallet. Verus has not published a timeline for a fix or pause to the bridge. If the vulnerability remains unpatched and the bridge continues operating, a third exploitation using the same attack vector would indicate the operator either cannot remediate the flaw or has chosen not to halt the protocol.