An attacker has stolen approximately $7.54 million from the Verus Ethereum bridge, marking the second successful exploit of the protocol within two months. The vulnerability, first discovered earlier this year, was not fully resolved, leaving the bridge exposed to a repeat attack that again targeted its cross-chain mechanism.
Cross-chain bridge risks persist
Cross-chain bridges, which allow users to lock digital assets on one blockchain and issue equivalent tokens on another, are designed to facilitate interoperability within the crypto ecosystem. However, these bridges often hold substantial liquidity in their pools, making them attractive targets for cybercriminals. A single error by validators can result in substantial losses.
Blockchain cybersecurity company Blockaid reported that the Verus attack demonstrated a recurring vulnerability common in several high-profile bridge hacks since 2022. The assailant exploited the bridge’s asset import feature to trigger Ethereum payouts that did not match actual values on the Verus blockchain.
The attacker targeted the Verus Ethereum bridge protocol contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63, transferring the stolen funds to wallet 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54. Assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD were among those affected.
Blockchain records, available on Etherscan, confirm the sequence of exploit transactions tied to the attacker’s wallet and the bridge contract.
Repeat exploit highlights unpatched vulnerability
The recent incident mirrors a similar attack from May 2026, when $11.58 million was siphoned from the same contract through a nearly identical method. Analysis from Blockaid found that the vulnerability exploited remained unaddressed, indicating persistent flaws in the bridge’s design and implementation.
Blockaid’s review found that both attacks exploited the identical import route on the same contract, revealing that the security gap went unpatched even after the initial hack.
Security firms Halborn and Merkle Science reached the same conclusion after investigating the earlier exploit. Rob Behnke of Halborn explained, “The vulnerability was not a cryptographic failure, but a missing validation ensuring that the value committed on the Verus chain matched the value released on Ethereum.”
Merkle Science identified an insufficient check in the bridge’s code, specifically within its checkCCEValues function, which allowed transactions to release assets on Ethereum far exceeding the actual value locked on the Verus side. This lapse enabled the attacker to leverage minimal transaction fees for disproportionately large rewards.
Merkle Science noted that the contract failed to validate that the source value matched the payout, permitting an attacker to spend only small fees while withdrawing millions.
The companies stated that the bridge’s cryptographic and proof systems had been functioning as designed, but the absence of proper value validation in the contract represented the root issue. Merkle Science also connected this validation failure to past exploits involving Wormhole and Nomad bridges in 2022.
Mini dictionary: Verus bridge — A cross-chain protocol that enables asset transfers between the Verus blockchain and Ethereum, allowing users to lock tokens on one chain and mint corresponding assets on the other. Vulnerabilities in such bridges can expose users’ funds on both networks to security risks.
| Bridge | Year of Major Exploit | Funds Lost | Root Cause |
|---|---|---|---|
| Verus | 2026 | $11.58M / $7.54M | Missing value validation |
| Wormhole | 2022 | $320M | Signature verification bug |
| Nomad | 2022 | $190M | Initialization vulnerability |
Broader bridge ecosystem and ongoing risks
While bridge attacks have historically accounted for a substantial share of losses in decentralized finance (DeFi), recent data signals a declining trend. Research by TRM Labs shows that, despite a record 207 attacks in the first half of 2026, total losses fell from $2.3 billion in 2025 to $972 million, and median hack amounts dropped to roughly $219,000.
A report from Immunefi supported this trend, noting bridge exploits accounted for 73% of DeFi losses in 2022, but only 3% in 2025, which suggests improved security through better audits and design standards in the sector.
Yet, the repeated Verus exploit demonstrates that broader progress does not compensate for specific, outstanding vulnerabilities in individual protocols. The flaw exploited in May remained unresolved, raising concerns about project maintenance and audit follow-through.
As of now, Verus has not published a post-mortem on the latest incident. Following May’s attack, Merkle Science advised users to avoid the bridge until its faulty validation was repaired and independently audited. Users are encouraged to wait for clear project confirmation before resuming activity on the bridge.




