A new exploit targeting the Verus-Ethereum Bridge drained roughly $7.54 million in crypto assets, according to blockchain security firm Blockaid. The firm said the attack reused the same bridge contract, entry path and vulnerability class as a May exploit on the protocol, but came from a different attacker operating out of a fresh wallet.
Why it matters
Re-exploitation of the same bridge contract is the worst-case outcome for a security patch. It means either the fix shipped too late, the on-chain remediation was incomplete, or the original report did not cover the full vulnerability class. Bridges have been the single largest source of crypto loss for three consecutive years, and the pattern here, patch then drain, is precisely what institutional risk teams flag when underwriting cross-chain exposure.
Market impact
Verus-side liquidity is thin and the asset does not trade at deep CEX depth, so the immediate price reaction is muted. The signal that travels is reputational: any project still referencing the May patch as resolved now has to answer why the same path drained again. Watch for a Verus team postmortem and any cross-chain bridges sharing the same verifier or relayer architecture.
Frequently asked questions
-
How much was drained from the Verus-Ethereum Bridge?
Roughly $7.54 million in crypto assets, according to blockchain security firm Blockaid.
-
Was this the same attacker as the May Verus exploit?
No. Blockaid said the attack used the same bridge contract, entry path, and vulnerability class as the May exploit, but came from a different attacker using a new wallet.
-
Why is a second exploit on the same contract significant?
It implies the May patch was late, incomplete, or did not cover the full vulnerability class, which is the worst-case outcome for any bridge security fix.
-
Did Verus market price react to the news?
Verus liquidity is thin and the asset lacks deep CEX depth, so the immediate price reaction was muted. The bigger signal is reputational for cross-chain bridge security broadly.
-
What should investors watch next?
A Verus team postmortem, confirmation of which contract was exploited, and whether any other bridges share the same verifier or relayer architecture.
TheBlock