---
title: "Verus Ethereum Bridge Exploit Drains $7.54 Million"
date: 2026-07-23
author: "Kathleen Kinder"
featured_image: "https://coinlaw.io/wp-content/uploads/2026/07/verus-ethereum-bridge-exploit-drains-7-54-million.jpg"
categories:
  - name: "Cryptocurrency"
    url: "/crypto.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Verus Ethereum Bridge Exploit Drains $7.54 Million

Verus’s Ethereum Bridge suffered a July 23, 2026 exploit that drained roughly $7.54 million from its reserves after an attacker used the bridge’s import path to trigger unbacked payouts, according to Blockaid.

## Key Takeaways

- Verus’s Ethereum Bridge lost about $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD on July 23, 2026, Blockaid said.
- The attacker used the same bridge contract, entry path, and bug class blamed for a May 2026 drain, per Blockaid.
- That earlier exploit stole about $11.58 million, and roughly 75% of the stolen ETH was later returned by the attacker.
- Blockaid confirms the July transaction came from a different attacker and a different loot wallet than May’s exploit.
- Both attacks moved funds out of the same bridge contract address, tying the two incidents to a shared point of failure.

## What Happened?

Blockaid, trusted by platforms including Coinbase to detect and protect against fraud, scams, and exploits in real time, is the security firm that caught the exploit. **Verus’s Ethereum Bridge**, the contract that moves assets between the Verus chain and [Ethereum](https://coinlaw.io/ethereum-statistics/), was the target of the exploit.

Blockaid detected the exploit at **4:08 a.m. UTC** and said the attacker used the bridge’s import path to trigger unbacked Ethereum-side payouts, draining bridge reserves. A bridge import path is the mechanism that is supposed to confirm a deposit on one chain before releasing matching funds on the other, and a spoofed check lets an attacker pull real assets out against a deposit that never happened.

The exploit transaction moved funds out of bridge contract **0x71518580f36feceffe0721f06ba4703218cd7f63** to an attacker controlled wallet, **0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54**. The stolen assets spanned **ETH**, **tBTC**, **USDC**, **USDT**, **EURC**, **MKR**, and **scrvUSD**, a seven-token spread that reflects the mix of reserves the bridge held.

> 🚨 Blockaid detected a [@VerusCoin](https://x.com/VerusCoin?ref_src=twsrc%5Etfw) Ethereum Bridge exploit on Ethereum.  
> An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.  
> More details in 🧵
> 
> — Blockaid (@blockaid\_) [July 23, 2026](https://x.com/blockaid_/status/2080143099561496896?ref_src=twsrc%5Etfw)

 ## How This Compares to May’s Bridge Drain?

“**This appears related to the previous Verus Ethereum Bridge incident in May 2026: same bridge contract, same entry path, and same bug class.**” Blockaid, in a post on X.

Blockaid added that the transaction came from a different attacker and a different loot wallet than the one used in May. Blockaid’s own May 18, 2026 alert had put that earlier drain at roughly **$11.58 million**, a larger sum than the one lost this time.

In the May incident’s aftermath, Verus confirmed that the exploiter returned **4,052.4 ETH**, around 75% of the stolen funds, to a funds return address now controlled by members of the Verus community, the project said in an update it pinned to its official X account.

Whether the same pattern repeats is unknown. A new wallet and transaction make May’s return a precedent, not a rule.

## Why the Repeat Matters for Bridge Security?

Blockaid’s own language, calling this exploit part of the “**same bug class**” as May’s, points to a shared weakness in how the bridge verifies deposits before it authorizes a payout, rather than two unrelated attacks that happened to hit the same contract.

A fix that patches one exploit path without closing the underlying flaw leaves an opening for the next attacker. Bridges concentrate reserves in a single contract that both chains trust, which is why a compromised import check can drain funds belonging to every user of the bridge at once, unlike a typical [self-custody wallet](https://coinlaw.io/self-custody-wallet-statistics/) breach tied to one account’s keys.

## CoinLaw’s Takeaway

A second exploit against the identical contract and entry path undercuts the assumption that May’s incident was fully remediated. A different attacker rules out a copycat, not a still-open flaw. The **$7.54 million** lost this time is smaller than May’s total, but the repeat itself is the more important number for anyone still trusting this bridge.

May’s recovery, where most of the stolen ETH came back through a negotiated return, does not guarantee these funds follow suit.

Definition of Cross-Chain. Link to full glossary entry follows the description.**Cross-Chain**Cross-chain is the ability to move data or assets between separate blockchains via bridges, messaging protocols, or interoperability networks.

[Read more](https://coinlaw.io/glossary/cross-chain/)