Verus Bridge Hit Again as $7.5M Vanishes in Repeat Hack

Verus Bridge loses $7.54M in a second exploit as an unresolved validation flaw appears to expose the same contract again.
Table of Contents

TL;DR

  • Verus Bridge lost about $7.54 million in a second exploit roughly two months after an earlier $11.58 million attack targeted the same contract.
  • The vulnerability allowed Ethereum payouts without confirming that matching value had been committed on Verus, despite valid signatures and Merkle proofs.
  • Security firms linked the flaw to missing Solidity validation, while users were advised to avoid the bridge until repairs and an independent audit are confirmed publicly.

Verus Bridge has suffered a second major exploit in roughly two months, with an attacker draining about $7.54 million from its Ethereum bridge on Thursday. The incident appears to involve the same vulnerability used in May, when approximately $11.58 million was stolen from the same contract. The repeat breach suggests a known validation flaw remained unresolved after the first attack. Blockaid said the latest theft affected assets including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD, reigniting concerns about how quickly bridge operators respond once a critical weakness becomes public across the wider DeFi market.

Missing validation exposes the same bridge contract

According to Blockaid, the attacker manipulated the bridge’s import mechanism to trigger Ethereum payouts that were not supported by equivalent value on the Verus blockchain. The bridge accepted the required signatures and Merkle proofs, yet failed to confirm that the amount released matched the value committed at the source. The problem was not broken cryptography, but a missing value check inside the contract. Halborn and Merkle Science reached similar conclusions after reviewing the May exploit, tracing the issue to the checkCCEValues function and roughly 10 missing lines of Solidity validation, despite appearing otherwise operational throughout.

Verus Bridge lost about $7.54 million in a second exploit

That omission created an almost absurd imbalance between cost and reward. Merkle Science said the earlier attacker could convert roughly $10 in VRSC transaction fees into a payout worth $11.58 million. Halborn noted that even a transaction valued near 1 cent could satisfy the bridge’s signature and proof requirements before prompting Ethereum to release assets worth millions. Minimal source value could therefore unlock an enormous destination payout. The latest incident reportedly targeted the same contract and import path, although it involved a different transaction, attacker wallet, and destination for the stolen funds with disturbing ease.

The timing is unsettling because bridge security has broadly improved across decentralized finance. Immunefi data cited in the report showed bridge hacks accounted for 73% of DeFi losses in 2022 but only 3% in 2025. Still, sector-wide progress cannot compensate for a publicly identified vulnerability left uncorrected. Verus had not released an official post-mortem for Thursday’s attack. Following the May incident, Merkle Science advised users to avoid the bridge until the faulty validation was fixed and independently audited, leaving caution as the only prudent response while confirmation remains absent for users and liquidity providers alike.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews