The Verus Ethereum Bridge has been hacked again for $7.54 million following an exploit in May



Verus Ethereum Bridge suffered another exploit, with an attacker draining around $7.54 million in assets from the same contract signed in May.

summary

  • Verus Ethereum Bridge lost about $7.54 million in a new vulnerability targeting its import path.
  • Blockaid says the attack is similar to the May exploit, though the root cause is still under active investigation.
  • Three cryptocurrency exploits reported Thursday caused combined losses of about $35.55 million, according to Lookonchain.

Blockchain security company Blockaid discoverer The attack on Ethereum on July 23 said the attacker used a bridge import path to trigger payments that were not backed by matching assets on the issuer side.

The incident involved a different transaction and attacker-controlled wallet than the hack that occurred in May, according to Blockaid. The company said that the new attack used the same bridge node, entry path, and apparent error category. However, the exact root cause remained under investigation when the alert was posted.

The Verus Bridge exploit drains multiple assets

Onchain logs show that the exploit transaction interacted with the Verus Ethereum Bridge contract at 03:45 UTC on July 23. The transaction transferred approximately 1,137 ETH and several tokens to an address controlled by the attacker. Assets included tBTC, USDC, USDT, EURC, MKR and scrvUSD. Etherscan estimated the main bridge’s outflows at about $7.54 million at the time.

Blockaid said the attacker abused the bridge import process to produce payments not backed by Ethereum. The company identified the receiving address as 0xCFd0…2D54 and linked the withdrawal to the same bridge node involved in the previous Verus incident. It has not yet published a full technical report on the new deal.

Additionally, the latest exploit comes about two months after the Verus Ethereum Bridge lost approximately $11.58 million in a separate attack. Security researchers said the May attacker exploited a verification loophole that allowed a fake cross-chain import to pass verification even though the value committed by the issuer did not match payments issued on Ethereum.

Blockaid said the July attack “appears to be related to the previous Virus Ethereum Bridge incident in May 2026.” It also described the two incidents as involving “the same bridge nodes, the same entry path, and the same class of bugs,” although no confirmed technical cause for the latest exploit was revealed.

Such as crypto.news I mentioned In May, the first Verus Bridge attacker later returned 4,052.4 ETH, worth about $8.5 million at the time, after the project offered settlement terms. The attacker kept 1,350 ETH as a reward. The returned amount represents approximately 75% of the funds that the exploiter retained after converting the stolen assets into ETH.

Three exploits were reported within hours

The Verus attack formed part of a broader series of security incidents reported within hours. Onchain tracker Lookonchain said AFX Trade, Virus and B² Network suffered exploits with combined reported losses of about $35.55 million. The numbers included $24.15 million from AFX, about $7.55 million from Verus and about $3.86 million from B² Network.

Earlier today, a bridge operated by AFX was established Lost $24.15 million in USDC Before the attacker transferred the funds to Ethereum and converted them into 12,467 ETH. Offchain Labs said the incident did not affect the original Arbitrum bridge and originated from infrastructure operated by a third-party protocol.

These incidents add to the ongoing scrutiny of systems across the chain. Modern Explanation of crypto.news He noted that bridges must verify events across separate blockchains while controlling assets held in shared reserves. Errors in message validation, contract logic, or transaction access controls can allow assets to be released without performing a valid matching transfer.

Details of the root cause and recovery remain pending

Blockaid said the new Verus exploit appears to involve the same type of vulnerability seen in May, but stopped short of confirming that exactly the previous vulnerability caused the July drain. The May attack involved a loss of validation of the value committed to the source chain and the amount released on Ethereum, according to security analyses.

The latest transaction confirms that funds left the Verus Bridge for the attacker’s new wallet, but the sources reviewed did not confirm whether any assets have been frozen, returned, or recovered since then. They also did not provide a new treatment plan or timeline for changes to bridge operations.

More technical details can clarify whether the May vulnerability is still exploitable, whether there is a related vulnerability that caused the new incident, or whether the attacker is using another route through the same import process. Subsequent money movements can also show the attacker whether stolen assets have been transferred or transferred through other services.

The case is still a developing story.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *