The Verus Ethereum Bridge lost $7.54 million to an exploit early Thursday, July 23, 2026, after an attacker used the same import-path flaw exploited in a May hack that drained $11.5 million from the same contract.
Blockaid detected the breach at 03:45 UTC, and CoinDesk reported that the stolen ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD were converted into roughly 3,916.1 ETH before landing in a Tornado Cash wallet. The repeat hit matters because Verus had redeposited funds recovered from the first attack into this same bridge only two weeks earlier.
The Import-Path Flaw That Wouldn’t Die
According to CoinDesk, the attacker abused the bridge’s import function, the mechanism meant to confirm that assets are locked on the Verus side before releasing matching payouts on Ethereum. That check failed again, letting the attacker trigger unbacked Ethereum-side payouts and pull real value out of the bridge’s reserves.
Security researchers confirmed the transaction and attacker wallet differ from May’s incident, but the underlying contract and bug class are identical. The May breach was serious enough that the Verus team said in a Discord message, reported by The Block, that the network had halted as nodes went offline in response.
Cointelegraph later reported that Blockaid traced the flaw to a missing validation check in the bridge’s transfer-verification code, a gap the firm said needed only a minor fix. The scale of the damage shows in Verus’ own numbers.
The protocol held close to $100 million in total value locked at the start of 2025, and CoinDesk’s review of onchain data puts that figure at about $9 million as of Thursday. The attacker had returned 4,052.4 ETH after keeping a 25% bounty in May, money Verus redeposited into the same bridge on July 8, two weeks before the second drain.
The Risk for Anyone Using Cross-Chain Bridges
Anyone holding funds on a cross-chain bridge should read this as a reminder that a public bounty return and a redeposit are not the same as a fix, and it’s worth checking our news hub before trusting a bridge that has already been drained once.
Whether Verus’ Remaining $9M Keeps Draining
Whether that remaining $9 million holds steady or keeps falling in the coming days will show if depositors are pulling out ahead of a third exploit, or if Verus can convince holders the import path is finally closed.
What This Means for You
If you use a bridge to move Bitcoin or Ethereum-based assets, this case shows that a security fix and a returned bounty do not guarantee a vulnerability is closed. Before bridging funds anywhere, check whether the project has published a technical post-mortem naming the specific bug, not just an announcement that funds were recovered. A bridge that has been drained twice through the same flaw is a signal to wait for that proof before depositing again.
This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.


