
Verus Bridge Hack drains $7.54M after attackers exploit the Ethereum bridge import path, marking the project's second major breach in 2026.
Author: Kritika Gupta
23th July 2026- An attacker drained roughly $7.54 million from the Verus-Ethereum Bridge on July 23. The stolen funds were flowing into Tornado Cash within hours. Security firm Blockaid flagged the Verus Ethereum Bridge hack shortly after the on-chain drain at 03:45 UTC.
High Signal Summary For A Quick Glance
Wu Blockchain
@WuBlockchain
Verus–Ethereum Bridge Suffers Second Exploit in Two Months, $7.54M Drained Blockaid detected a new exploit targeting the Verus–Ethereum Bridge, with an attacker abusing the bridge’s import path to trigger unbacked Ethereum-side payouts and drain approximately $7.54 million in https://t.co/eNGo8EILT7

07:02 AM·Jul 23, 2026
crypto.news
@cryptodotnews
JUST IN: Verus Ethereum Bridge exploited again for 7.53 million dollars The attack used the same failure mode as the May exploit draining multiple assets https://t.co/k398pw50iE

07:02 AM·Jul 23, 2026
High attention and emotional sentiment detected.
The loss is not the shocking part. The same bug class has now drained this bridge contract twice in about two months. In May, a nearly identical attack took ~$11.58 million.
The attacker called a single function, submitImports, on the bridge contract on Ethereum. That function processes a proof from the Verus chain and then releases the matching reserves.
Because the proof looked valid, the contract paid out. According to Blockaid, the payout had no economic backing behind it. In short, the bridge released real assets against a request that locked almost nothing.
First, the attacker submitted a tiny cross-chain request on Verus, worth about 0.01 VRSC. That request generated a Cross-Chain Export commitment. Verus notaries accepted it, and the state root passed to Ethereum.
Then the attacker called submitImports with a payload whose transfer hash matched, yet whose totals did not cover the payout. As a result, the bridge drained its reserves to an attacker-controlled wallet.
The drain hit seven different reserve assets at once. On-chain data shows the loot wallet received a wide spread of tokens in the single exploit transaction.
The haul included 1,137.45 ETH, 71.50 tBTC v2, and 149,275 USDC. It also took 78,300 USDT, 31,475 EURC, 59.43 MKR, and 92,784 scrvUSD. Another 220,357 DAI moved in internal transfers.
Next, the attacker swapped almost everything into ETH. Cyvers reported roughly 3,916 ETH, worth about $7.52 million, before the laundering started.
Soon after, the funds moved into the Tornado Cash router in batches, including 100 ETH and 10 ETH deposits. By the time analysts checked, the loot wallet held only about 0.09 ETH. So far, no freezes or recoveries have been reported.
Key milestones related to the Verus Bridge exploit
The cross-chain bridge became operational. No confirmed date for its latest security audit was found.
The attacker used the Ethereum-side submitImports function to drain approximately $7.54 million from bridge reserves.
Blockaid publicly reported the attack and identified unbacked Ethereum-side payouts through the bridge import path.
The Verus team had not published a public statement addressing the July exploit at the time of research.
No fund recovery, insurance, compensation, or user-refund plan has been announced.
Blockaid was direct about the link. It said the attack used the same bridge contract, the same entry path, and the same bug class as the May 2026 incident. However, the July drain came from a different attacker and a different loot wallet.
The May exploit drained ~$11.58 million through the same missing validation. That time, the story ended better for users. A bounty deal returned about 4,052 ETH, roughly 75% of the funds, while the attacker kept around 1,350 ETH.
Verus also halted the network in May and shipped patches afterward. Yet the July attack suggests the core validation gap stayed open. Two months later, a fresh actor walked through the same door.
Per-asset breakdown of the $7.54M Verus Bridge drain
Security firm SlowMist pointed to a specific weakness in the bridge’s proof logic. Its analysts said the function VerusProof.checkExportAndTransfers verified selected fields, including the transfer hash, but skipped the export’s accounting.
In other words, the code checked that the transfers matched a hash. Still, it never confirmed that the source request actually locked or burned enough value to cover them. That gap let the attacker bind fake payouts to a cheap request.
This is the same class of flaw seen in the Wormhole and Nomad bridge hacks. Each one failed to tie the value released on one chain to the value locked on the other. Cross-chain bridges keep tripping over that exact link.
As of this writing, Verus has issued no public statement about the July exploit. Michael Toutonghi and the core team have not addressed it on the project’s official channels.
That silence stands out. In May, Verus pushed back on Blockaid’s framing and called that attack multi-step and sophisticated, rather than a simple balance spoof. For now, no similar response exists for the July Verus Ethereum Bridge hack.
Several open questions remain. Analysts still do not know the full swap paths, the attacker’s identity, or whether any notaries or Bridgekeeper nodes were touched. SlowMist also flagged a related contract at 0x54e03a...d4ce for review.
The immediate risk sits with bridged assets on Verus. Drained reserves can leave tokens like Bridge.vETH under-collateralized, which raises depeg risk. No specific chart has confirmed a depeg yet, so treat that as a watch item.
The broader lesson is harder. This drain was one of three bridge-related exploits in about 24 hours, together worth close to $35 million. Bridges remain the softest target in crypto, and repeat hits like this one show why.
For Verus, the next move matters. Users will watch for a statement, a patch that closes the validation gap for good, and any recovery plan. Until then, the Verus Ethereum Bridge hack reads as a fix that never held. None of this is financial advice.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Verus Ethereum Bridge Hack Drains $7.5M in Repeat Exploit
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
notnullOSX Malware Targets Mac Users With Crypto Wallets
Ostium Vault Exploit Drains $18M in USDC on Arbitrum
Verus Ethereum Bridge Hack Drains $7.5M in Repeat Exploit
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
notnullOSX Malware Targets Mac Users With Crypto Wallets
Ostium Vault Exploit Drains $18M in USDC on Arbitrum