"The fact that the same vulnerability was exploited again is deeply troubling," a blockchain security analyst commented after the Verus Ethereum Bridge suffered its second major hack in just over two months. On July 23, an attacker drained roughly $7.54 million from the bridge’s Ethereum reserves by exploiting the submitImports function, a flaw allowing withdrawals without assets being locked on the Verus chain.

Incident reports from blockchain security firm Blockaid revealed that the attacker triggered unauthorized payouts across multiple tokens, including 1,137 ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. Within minutes, the stolen assets were swapped on decentralized exchanges and partially funneled through Tornado Cash, complicating efforts to track and recover the funds. The exploit struck at 03:45 UTC, exposing ongoing weaknesses in the bridge's code.

This breach mirrors an earlier attack in May that saw over 4,000 ETH stolen via the same vulnerability and entry point, but from a different wallet. Experts question whether the root cause of the first exploit was ever fully patched before Verus resumed bridge operations. As the pattern persists, it highlights risks faced by cross-chain bridges in decentralized finance, with attackers increasingly exploiting logical flaws in transaction validation processes.

Verus isn’t alone in facing these pressures. Other recent bridge attacks on platforms like AFX Trade and B² Network have led to combined losses exceeding $35 million, underscoring systemic challenges in securing interlinked blockchains. The repeated compromises demand heightened scrutiny of bridge security protocols, as the current measures evidently fall short in preventing sophisticated exploits.