The Verus Ethereum Bridge was drained of roughly $7.54 million on July 23, after an attacker triggered unbacked payouts through the same vulnerability that cost the project $11.58 million just two months earlier. Security firm Blockaid flagged the attack at around 03:45 UTC, shortly after funds began moving out of the bridge contract.
The attacker abused the bridge's submitImports function, which is designed to process cross-chain proofs from Verus and release corresponding assets on Ethereum. By manipulating that import path, the attacker pulled out 1,137.45 ETH, 71.50 tBTC v2, 149,275 USDC, 78,300 USDT, 31,475 EURC, 59.43 MKR, and 92,784 scrvUSD. Internal transfers also shifted around 220,357 DAI during the same operation. Most of the haul was quickly swapped into ETH, leaving the attacker's wallet holding approximately 3,916 ETH, worth about $7.52 million, before laundering began.
Funds gone within hours
The ETH moved into Tornado Cash in batches, including transactions of 100 ETH and 10 ETH, within hours of the attack. By the time analysts reviewed the wallet at address 0xCFd0A2D0A2E3d74C2A08C96A0A4aE7d58eF92D54, it held just 0.09 ETH. No asset freeze or compensation plan had been announced at the time of reporting, and Verus had not published any public statement about the incident.
As Blockaid noted, the July attack hit the same bridge contract at 0x7151D8b4A487F3Fcf131fbfAAeD8A5A5F6b97f63 and followed the same entry path and bug class as the May exploit. Halborn's Rob Behnke put it plainly: "The vulnerability was not a cryptographic failure, but a missing validation ensuring that the value committed on the Verus chain matched the value released on Ethereum."
The May incident had a partial resolution: a bounty deal returned about 4,052 ETH, roughly 75% of what was taken, while the attacker kept around 1,350 ETH. No similar arrangement had emerged for the July drain by publication time.
This article is for informational purposes only and does not constitute financial or investment advice.



