Seven and a half million dollars left the Verus-Ethereum Bridge in under an hour, and nobody has yet confirmed whether the original vulnerability was ever properly fixed.

Blockchain security firm Blockaid picked up the attack at 03:45 UTC on July 23. The attacker drained roughly 1,137 ETH along with tBTC, USDC, USDT, EURC, MKR, and scrvUSD, all routed to a single attacker-controlled wallet. Etherscan put the total outflow at approximately $7.54 million at the time of the exploit.

The method was familiar. The attacker manipulated the bridge's import process to trigger payouts on the Ethereum side without depositing matching assets on the source chain. Blockaid traced the receiving address to 0xCFd0…2D54 and noted that while the wallet and transaction hash differed from the May incident, the targeted contract, entry path, and likely bug category were the same.

A Patch That May Not Have Held

The May breach cost the protocol around $11.58 million. That attacker used a forged cross-chain import to bypass a validation check. Verus later negotiated a partial return: 4,052.4 ETH came back, then worth about $8.5 million, while the attacker kept 1,350 ETH as a self-declared bounty. The July attack suggests the underlying flaw survived that settlement intact, though Blockaid says a complete technical post-mortem is still pending.

The Verus incident was not an isolated event that day. Onchain tracker Lookonchain estimated that three separate attacks on July 23, hitting AFX Trade, Verus, and BSquared Network, combined for roughly $35.55 million in losses. AFX took the biggest hit at $24.15 million in USDC, which the attacker swapped for 12,467 ETH. Arbitrum's native bridge was unaffected; the AFX breach originated from a third-party protocol's own infrastructure. BSquared Network reportedly lost another $3.86 million.

What This Means for Cross-Chain Security

Two exploits targeting the same contract and the same bug class within sixty days point to a specific problem: partial patches and negotiated settlements do not substitute for a full security audit and verified remediation. Bridges that process cross-chain imports without strict asset-matching checks on both sides remain an obvious target. The Verus case now adds to a growing list of repeated bridge attacks where a protocol suffered a second breach before the first was fully understood.

This article is for informational purposes only and does not constitute financial advice or an investment recommendation.