What to know:
- Ethereum Bridge exploited again as attackers stole approximately $7.54 million by abusing Verus’ import verification process.
- Hackers drained ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD through unauthorized cross-chain withdrawals.
- The incident marks the second major Ethereum Bridge attack since May, despite security upgrades after the previous exploit.

The Verus Ethereum Bridge has once again been hit with a serious security breach in which hackers have stolen more than $7.54 million after hacking the system’s import verification protocol.
This comes barely more than two months since the same bridge was attacked in what became the first big hack to hit the Ethereum Bridge in recent times. Blockchain security firms Blockaid and PeckShield were among those who confirmed the breach, with PeckShield putting the losses at $7.5 million.
Also Read | ADA Surges as Cardano Network Activity Explodes 4,457%, What’s Next?
Ethereum Bridge Exploit Triggered Unauthorized Withdrawals
According to initial findings, the attacker tampered with the import function of the Ethereum Bridge in such a way that it resulted in fraudulent withdrawals from the Ethereum Bridge without any Verus deposits/exportation.
Stolen assets include ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, all of which were present in the liquidity pool of the Ethereum Bridge.
The exploit happened before the cross-chain transfer validation, where funds would be transferred out on the Ethereum blockchain. A malicious instruction for the import appears to have bypassed verification, allowing contracts to move funds that were never supposed to be unlocked.
Blockaid is yet to verify whether the attack was conducted within one transaction or many imports. Investigators are following the addresses of the hacker’s wallet to detect any transfer of funds.
Ethereum Bridge Faces Second Attack Since May
The recent hack is the second big attack on the Ethereum Bridge since May.
Attackers stole an estimated total of $11.56 million, which consisted of 1,625.36 ETH, 103.56 tBTC, and 147,658 USDC. These funds were converted to 5,402 ETH. The attacker gave back 4,052 ETH to the bridge as part of a recovery deal and kept 1,350 ETH as a bounty.
Following the hack, Verus implemented more robust transaction proof verification and improved Ethereum bridge contract security. The current exploit raises doubts about whether the attack was aimed at the updated contracts or somewhere else in the import process of the bridge.
Blockaid and PeckShield did not find any evidence of private key compromise or compromised validator credentials. Initial research reveals some vulnerability in the way imported transfer requests were processed.
DeFi Security Risks Continue to Grow
The Verus Ethereum Bridge hack has been reported in the wake of other DeFi hacks. In the past, the Arbitrum bridge of AFX Trade has seen theft of around $24.15 million worth of USDC following an unvalidated transaction. Meanwhile, B² Network’s 8.59 million B2 tokens have been sold for 5,409 BNB, amounting to about $3.01 million.
Only 24 hours before that, 42DAO was exploited through an oracle hack costing $915,000, whereas Balance Coin plunged by more than 99%. The newest Ethereum Bridge attack is yet another example of DeFi vulnerabilities, which have been increasingly targeted by hackers recently.
Also Read | SUI Staking Goes Live on Coinbase, Offering Automatic Rewards





Be the first to comment