Verus Ethereum Bridge Drained of $7.54M in Second Major Exploit
Key Takeaways
- •An attacker drained approximately $7.54 million from the Verus Ethereum Bridge by submitting a malicious import that triggered asset releases without corresponding deposits on the Verus network.
- •The stolen assets included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from the bridge's Ethereum reserves.
- •This is the second major breach of the Verus Ethereum Bridge in just over two months, bringing combined losses across both incidents to approximately $19 million.
- •Security firms Blockaid and PeckShield did not identify a private-key compromise or stolen validator credentials, attributing the attack to the bridge's handling of imported transfer instructions.
- •Verus had not issued a public response, confirmed the bridge's operational status, or announced a recovery timetable at the time of publication.

An attacker drained approximately $7.54 million from the Verus Ethereum Bridge on Thursday, exploiting the bridge's import path to trigger payouts that were not backed by actual assets on the Verus network.
The unauthorized withdrawals siphoned ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from the bridge's Ethereum reserves. Blockchain security firm PeckShield separately estimated the loss at roughly $7.5 million.
The exploit targeted the mechanism responsible for releasing assets on Ethereum once a cross-chain transfer is validated. A malicious import passed through the bridge's verification route and directed its contracts to disburse real reserves without any corresponding export or deposit on the Verus side.
Blockaid had not disclosed whether the attacker executed a single transaction or a series of imports. Downstream token swaps and the current balances of the receiving addresses remained under review at the time of reporting.
Verus Bridge Suffers Second Major Drain
The attack marks the second major loss involving the Verus Ethereum Bridge in just over two months, bringing combined losses across both incidents to approximately $19 million.
On May 17, a transaction removed 1,625.36 ETH, 103.56 tBTC, and 147,658 USDC from the bridge, placing the initial loss at approximately $11.56 million. The attacker converted those assets into roughly 5,402 ETH before returning 4,052 ETH under a recovery agreement and retaining 1,350 ETH as a bounty.
In the aftermath, Verus introduced tighter transaction proofs and prepared replacement Ethereum contracts as part of its bridge restoration process. The July exploit raises fresh questions about whether the latest withdrawals reached the upgraded contracts or another component of the import system.
Neither Blockaid nor PeckShield identified a private-key compromise or stolen validator credentials in their initial alerts. The known attack path centered on the bridge's handling of imported transfer instructions.
Protocol Exploits Accelerate Across DeFi
Cross-chain bridges, which lock assets on one blockchain to mint or release corresponding tokens on another, have repeatedly ranked among the most targeted components in decentralized finance due to the pooled reserves they hold.
The Verus drain followed a $24.15 million USDC withdrawal from AFX Trade's Arbitrum bridge, where an unauthorized transaction bypassed the bridge's validator approval and dispute process.
Hours later, an attacker sold 8.59 million B2 tokens taken from B² Network for 5,409 BNB, realizing approximately $3.01 million after slippage.
The series of attacks came one day after an oracle failure at 42DAO enabled an attacker to extract $915,000 and caused Balance Coin to collapse by more than 99%.
At the time of publication, Verus had not issued a public response, confirmed the bridge's operational status, or announced a recovery timetable.