Attackers drained the Verus Ethereum bridge again on Thursday, walking away with roughly $7.54 million in crypto assets. The method was identical to a May 2026 exploit that cost the protocol $11.58 million, suggesting the underlying vulnerability was never properly patched after the first incident.

Cross-chain bridges work by locking assets on one blockchain and minting equivalent tokens on another. That design concentrates enormous liquidity in a single contract, so a validator oversight or a missing input check can translate directly into eight-figure losses. Blockaid, the blockchain security firm that analyzed the attack, placed this incident in the same bug class responsible for some of the largest bridge hacks since 2022.

How the attacker pulled it off

According to Blockaid, the hacker abused the bridge's import mechanism to trigger Ethereum-side payouts that had no real backing on the Verus chain. The missing validation check let the contract release more assets than were actually locked, a gap that should have been sealed after May. The stolen funds included ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.

On-chain data published to Etherscan ties the exploit to the bridge protocol contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63. Stolen funds moved to the attacker's wallet at 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54, where they remain visible in the public transaction history. Combined with the May incident, the same contract has now leaked over $19 million in under two months.

This article is for informational purposes only and does not constitute financial advice or an investment recommendation.