A fresh exploit has struck the Verus Ethereum Bridge, with attackers stealing approximately $7.54 million in digital assets in what security researchers describe as a repeat of the vulnerability exploited during the protocol’s May breach.
The incident occurred on July 23, affecting the Ethereum-side bridge that connects the Verus blockchain with Ethereum.
According to Blockchain security firms Blockaid and CertiK, the attacker abused the bridge’s import mechanism to trigger unauthorized payouts, draining ETH and multiple ERC-20 tokens before laundering the proceeds through privacy tools.
The latest attack comes just weeks after Verus suffered an $11.58 million exploit, intensifying concerns over the security of cross-chain infrastructure.
Second exploit mirrors May attack
Security analysts say the latest breach closely resembles the exploit disclosed in May, suggesting the underlying vulnerability class was not fully eliminated despite recovery efforts.
According to Blockaid, the attacker exploited the bridge’s import path to generate Ethereum-side payouts without depositing corresponding assets on the Verus network, effectively withdrawing funds backed by no collateral.
The stolen assets reportedly included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, all of which were rapidly converted into Ethereum before being transferred through Tornado Cash, a privacy protocol commonly used to obscure on-chain fund movements.
CertiK estimated losses at roughly $7.53 million closely matching Blockaid’s assessment.
Researchers noted that while the exploit followed the same technical pathway used during the May incident, the attacker operated from a new wallet indicating a different actor may have been responsible.
Security questions return for cross-chain bridges
The latest compromise once again places cross-chain bridges under the spotlight, a sector that has historically accounted for some of the largest losses in decentralized finance.
Verus had previously restored operations after the May attack, during which approximately 75% of the stolen funds were voluntarily returned by the exploiter following negotiations with the project.
The protocol subsequently implemented upgrades aimed at restoring bridge functionality and strengthening network security.
However, Thursday’s incident suggests that either similar attack vectors remained accessible or a related implementation flaw persisted.
“The latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path and vulnerability class.” Blockaid, security analysis shared following the incident.
Bridge exploits remain one of the most expensive categories of crypto attacks because they often hold large pools of collateral securing assets across multiple blockchains.
Academic research estimates that vulnerabilities in cross-chain bridges have contributed to billions of dollars in ecosystem losses over recent years, highlighting persistent architectural challenges.
Market impact remains limited despite security setback
Despite the multimillion-dollar theft, the broader cryptocurrency market showed little immediate reaction.
Bitcoin and Ethereum traded relatively steadily following news of the exploit, suggesting investors viewed the incident as protocol-specific rather than a systemic market event.
For crypto investors, however, the breach reinforces a familiar lesson: smart contract risk remains one of the largest threats within decentralized finance, particularly for cross-chain protocols that depend on complex verification mechanisms.
The incident also arrives as institutional interest in blockchain infrastructure continues to expand, increasing pressure on developers to demonstrate stronger security practices and faster vulnerability remediation.
As of publication, the Verus team had not issued a detailed public explanation of the latest exploit, while investigations by blockchain security firms remain ongoing.
Why investors should pay attention
Although the stolen amount is relatively small compared with the overall cryptocurrency market, the attack highlights a recurring concern for investors allocating capital to decentralized finance protocols.
Repeated exploitation of the same bridge within two months raises questions about software auditing, incident response, and governance following major security events.
For institutional and retail investors alike, the incident underscores why security infrastructure has become as important as protocol innovation in determining long-term project credibility.
As decentralized finance grows increasingly interconnected, attacks on bridges remain capable of disrupting liquidity, undermining user confidence, and exposing weaknesses that extend beyond individual protocols.