Verus Ethereum Bridge Drained of $7.54 Million in Second Attack via Same Vulnerability

In the May breach, the attacker returned 4,052.4 ETH after keeping a 25% white-hat bounty, indicating partial recovery and ongoing negotiation around remediation.
The July 23 theft payload included about 1,137 ETH plus multiple tokens (tBTC, USDC, USDT, EURC, MKR, scrvUSD) sent to an attacker address, with the on-chain timestamp at 03:45 UTC and the receipt address identified as 0xCFd0…2D54.
The July attack also encompassed the same broad asset mix as the May breach (ETH, tBTC, USDC, USDT, EURC, MKR, scrvUSD) and, as reported, the stolen assets were converted into ETH on the attacker’s side.
Blockaid noted that the July attacker operated from a new wallet with no apparent connection to the May incident, suggesting a fresh actor rather than a direct repeat of the same individual.
Analysts and security researchers have highlighted the broader risk profile of cross-chain bridges, with some attributing such exploits to cross-chain verification weaknesses or proof-forgery mechanisms that can enable unauthenticated asset withdrawals even after patches.
The Verus–Ethereum Bridge has been drained for the second time in two months, with an attacker stealing roughly $7.54 million in crypto assets on July 23, according to The Block and Crypto Times. The theft happened at 03:45 UTC, when an attacker sent about 1,137 ETH plus multiple tokens — including tBTC, USDC, USDT, EURC, MKR, and scrvUSD — to a wallet identified as 0xCFd0…2D54.
Security firm Blockaid flagged the breach and confirmed it exploited the same vulnerability class used in May's attack, which drained roughly $11.5 million. Verus has not issued a public statement, and users are advised to avoid the bridge until further notice.
The July attacker abused the bridge's import path to trigger unbacked payouts on the Ethereum side, according to TradingView. This is the same method used in May. In simple terms, the bridge was tricked into sending out real assets without receiving valid backing assets in return.
Blockaid noted that the July attacker used a brand-new wallet with no clear link to the May incident, per Crypto Times. That suggests a different person carried out the second attack — not a repeat of the same individual. Yet the method was nearly identical, raising serious questions about whether the bridge's security fixes actually worked.
The May attack drained around $11.5 to $11.6 million. The May attacker later returned 4,052.4 ETH after keeping a 25% white-hat bounty, according to Coinfomania. A white-hat bounty is a reward paid to someone who finds and reports — or in this case exploits — a security flaw.
That returned ETH was redeposited into the bridge before the July attack hit. Analysts warn that partial recovery and an incomplete patch left the bridge exposed. The July theft erased much of what was returned, leaving users and the project in a worse position than before.
After the July attack, the stolen assets — ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD — were converted into ETH on the attacker's side, according to Global Crypto TV. Converting mixed tokens into a single asset like ETH is a common first step before laundering.
Analysts noted that laundering methods like Tornado Cash have been linked to similar bridge exploits. Tornado Cash is a tool that mixes crypto transactions to hide their origin. The use of such tools makes it much harder for investigators to trace and recover stolen funds.
Security researchers warn that cross-chain bridges carry deep structural risks, according to TradingView. These bridges connect separate blockchains, but that connection creates attack surfaces. Weaknesses in how the bridge verifies transactions — called cross-chain verification — can let attackers forge proof of deposits and withdraw assets they never actually sent.
The Verus incident is the latest in a long line of bridge hacks. Analysts say two attacks using the same flaw is a clear sign that patches were not fully effective. Until the root cause is fixed and independently audited, the bridge remains a risk for anyone holding assets on it, per Coinfomania.
Publishers
17
Articles
7
Reach
24