Loading prices…
🩸BEARISH

Verus Ethereum Bridge drained for $7.5M in repeat exploit

The same failure mode that hit Verus before just cost users another seven-figure sum across ETH, USDC, USDT, tBTC and three more reserve assets, raising fresh questions about bridge security.

The Verus Ethereum Bridge was exploited for roughly $7.53 million on July 23, according to on-chain security firm Blockaid, marking the second major incident against the same bridge using the same underlying failure mode.

Why it matters

Blockaid reported that the attacker targeted the bridge's import mechanism to trigger unbacked payouts, draining a broad basket of reserve assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. A repeat exploit on the same code path is the worst possible signal for a bridge: it means the original fix either was incomplete or was never deployed, and it puts every other cross-chain bridge built around similar import-style liquidity designs back under the microscope.

Market impact

The seven-figure loss lands in a single transaction rather than spread over time, which is what makes bridge exploits disproportionately painful for liquidity providers. With at least seven distinct reserve assets drained, the contagion surface is wide: any wrapped or bridged representation of these tokens that depended on Verus reserves now sits on a weaker backing claim. Expect auditors and risk teams at competing bridges to re-test import-style flows in the days ahead.

Related tokens
$ETH

Frequently asked questions

  1. What happened to the Verus Ethereum Bridge on July 23?

    Blockaid reported that the Verus Ethereum Bridge was exploited for roughly $7.53 million via its import mechanism, which was abused to trigger unbacked payouts in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

  2. Is this the same exploit that hit Verus before?

    Yes. Blockaid said the attacker used the same failure mode as a prior incident against the bridge, meaning the original fix was either incomplete or never deployed.

  3. Which assets were drained from the Verus bridge?

    On-chain reporting identified seven reserve assets taken in the exploit: ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

  4. How does a bridge import mechanism get exploited?

    An import-style bridge accepts messages from a counterparty chain and mints or releases liquidity on the destination side. If the import validation is weak, an attacker can forge or replay a valid-looking message and trigger payouts that are not backed by locked funds on the source side.

  5. What is the broader impact on other Ethereum bridges?

    A repeat exploit on the same code path puts competing bridges built around similar import-style liquidity designs back under scrutiny, and any wrapped or bridged asset that depended on Verus reserves now sits on a weaker backing claim.

Source attribution
Aggregated from Crypto News · Verified · Last refreshed 55m ago
Open original →