Verus Ethereum Bridge Drained of $7.54M in Repeat Exploit

Changelly


Set as Google Preferred SourceFollow on Google News

TLDR

  • An attacker drained about $7.54 million from the Verus Ethereum Bridge on July 23.
  • Blockaid said the exploit used the same contract and bug class as the May attack.
  • The stolen assets included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
  • The attacker swapped most funds into about 3,916 ETH before using Tornado Cash.
  • Verus had not announced a public recovery plan or official response at the time of reporting.

The Verus Ethereum Bridge lost about $7.54 million after an attacker used the same bug class linked to an $11.58 million exploit in May.

Attacker Drains Verus Bridge Reserves

The Verus Ethereum Bridge was exploited on July 23 after an attacker triggered unbacked payouts from the Ethereum-side bridge contract. Security firm Blockaid flagged the attack shortly after the drain at about 03:45 UTC.

The attacker used the bridge’s submitImports function, which processes cross-chain proofs from Verus and releases matching assets on Ethereum. Blockaid said the attacker used the import path to drain about $7.54 million from bridge reserves.

The stolen assets included 1,137.45 ETH, 71.50 tBTC v2, 149,275 USDC, 78,300 USDT, 31,475 EURC, 59.43 MKR, and 92,784 scrvUSD. Internal transfers also moved about 220,357 DAI during the exploit.

The attacker later swapped most assets into ETH. Cyvers reported that the wallet held about 3,916 ETH, worth roughly $7.52 million, before laundering activity began.

Funds Move Quickly Into Tornado Cash

The stolen funds moved into Tornado Cash within hours of the attack. On-chain activity showed deposits routed in batches, including 100 ETH and 10 ETH transactions.

By the time analysts reviewed the wallet, the attacker-controlled address held only about 0.09 ETH. No asset freeze, fund recovery, or refund plan had been reported at the time of writing.


Zuna


The exploit hit the Verus Ethereum bridge contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63. The funds were tracked to attacker wallet 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54.

Verus had not issued a public statement on the July exploit at the time of research. The team also had not announced a patch, recovery effort, insurance claim, or user compensation plan.

Same Bug Class Hit Bridge in May

Blockaid said the July exploit used the same bridge contract, same entry path, and same bug class as the May 2026 attack. That earlier exploit drained about $11.58 million from the same bridge system.

The May incident ended with a partial recovery after a bounty deal returned about 4,052 ETH, or roughly 75% of the stolen funds. The attacker kept about 1,350 ETH under that arrangement.

Security analysts said the weakness centered on missing validation between value locked on Verus and value released on Ethereum. Halborn’s Rob Behnke said, “The vulnerability was not a cryptographic failure, but a missing validation ensuring that the value committed on the Verus chain matched the value released on Ethereum.”

Merkle Science’s Mir Jalal gave a similar assessment. He said,

“The bridge failed to validate that the source value matched the destination payout, allowing an attacker to spend only minimal fees while withdrawing millions.”

SlowMist pointed to a weakness in the bridge’s proof logic. Its analysts said the system checked selected fields, including the transfer hash, but did not confirm that the source request locked or burned enough value.

That flaw allowed the attacker to connect a low-value request to a much larger Ethereum payout. Similar value-matching failures were also seen in past Wormhole and Nomad bridge attacks.



Source link

Coinbase

Be the first to comment

Leave a Reply

Your email address will not be published.


*