NewsCryptoVerus Ethereum Bridge Exploited for $7.54 Million in Second Breach Since May

Verus Ethereum Bridge Exploited for $7.54 Million in Second Breach Since May

Author: CoinLineup·

Key Takeaways

  • The Verus Ethereum Bridge was exploited for approximately $7.54 million, representing its second security compromise in under three months.
  • The incident is part of a broader wave of attacks that collectively lost around $35 million across multiple protocols within hours of each other.
  • During the first breach in May 2026, the attacker returned $8.5 million in ETH while retaining a bounty, but it remains unconfirmed whether the current exploit will follow a similar trajectory.
  • All on-chain activity related to the exploit can be independently verified through two flagged Ethereum addresses on Etherscan.
  • The recoverability of affected user funds and the bridge's operational status remain undetermined until the Verus team issues official statements.
Verus Ethereum Bridge Exploited for $7.54 Million in Second Breach Since May

The Verus Ethereum Bridge has been exploited for approximately $7.54 million, representing the second compromise of the project's cross-chain infrastructure in under three months and intensifying scrutiny of bridge security across the cryptocurrency sector.

Cross-chain bridges like Verus's connect separate blockchain networks, enabling users to transfer assets between them by locking tokens on one chain and issuing corresponding representations on another. Because these systems must maintain large pooled reserves to back transfers, they have consistently ranked among the most lucrative targets in decentralized finance. Major bridge exploits — including the Ronin Network breach ($625 million, March 2022), the Wormhole attack ($325 million, February 2022), and the Nomad Bridge drain ($190 million, August 2022) — remain among the largest thefts in cryptocurrency history, establishing a pattern that the Verus incident now extends.

The incident forms part of a broader wave of attacks targeting Bitcoin- and Ethereum-linked protocols. According to CoinDesk, several projects collectively lost around $35 million across multiple incidents occurring within hours of each other.

On-chain activity tied to the Verus exploit can be traced via the flagged Ethereum address 0x65cb8b128bf6e690761044cceca422bb239c25f9 on Etherscan, where all transfers and balances remain publicly visible for independent verification. A second associated address, 0x71518580f36feceffe0721f06ba4703218cd7f63, can also be monitored to follow fund movements in real time.

Repeat Security Event Heightens Concerns

The latest breach is not an isolated incident for the Verus project. The bridge was first compromised in May 2026, an event documented in detail by blockchain security firm Halborn. During that earlier episode, the attacker ultimately returned $8.5 million in ETH while retaining a bounty — an outcome that influenced community perception of the project's incident response.

Whether the current exploit will follow a similar trajectory has not been confirmed. A repeat compromise within such a short period underscores persistent security challenges rather than a one-time failure, directly affecting user confidence in the protocol's ability to safeguard cross-chain transfers. It also raises questions about whether common bridge design patterns — including validator set management, multi-signature controls, and commit-reveal mechanisms — provide adequate resilience against increasingly sophisticated attack vectors.

Bridge Exploits Remain an Industry-Wide Problem

Cross-chain bridges continue to be a favored target for attackers across blockchain ecosystems. In a comparable incident, an AFX bridge exploit drained $24.15 million in USDC. Separately, a NIGHT bridge exploit affected the Cardano ecosystem. These events collectively highlight that bridge infrastructure vulnerabilities are not unique to any single project, and the clustering of incidents within short windows suggests attackers may be systematically probing bridge endpoints during periods of heightened network activity.

For affected users, the most actionable updates will come directly from the Verus team regarding the confirmed scope of losses and the current operational status of the bridge. Until official statements are published, the practical impact on users — including whether any deposited funds are recoverable — cannot be determined from available evidence.

Observers can independently verify developments by monitoring the referenced Ethereum addresses on-chain rather than relying on secondary reports.