
The Verus Ethereum Bridge has suffered another significant exploit, with attackers draining approximately $7.54 million in assets from the same contract that was previously compromised in May 2026. According to blockchain security firm Blockaid, the attack occurred on July 23, 2026, when an attacker used the bridge's import process to release funds without depositing matching assets on the source chain. The incident involved a different transaction and attacker-controlled wallet from the May breach, though the exact root cause remains under active investigation. As reported by AMBCrypto, this marks the second time the bridge has been drained using the same unbacked payout method, suggesting an unresolved validation flaw rather than a one-off breach.
Onchain records show the exploit transaction interacted with the Verus Ethereum Bridge contract at 03:45 UTC on July 23, 2026. The transaction transferred approximately 1,137 ETH and several tokens including tBTC, USDC, USDT, EURC, MKR and scrvUSD to an attacker-controlled address. Etherscan valued the main bridge outflows at roughly $7.54 million at the time of the transaction. Blockaid identified the receiving address as 0xCFd0...2D54 and linked the withdrawal to the same bridge contract involved in the earlier Verus incident. The attacker converted the unbacked tokens into liquid value and exited, leaving the reserve short by the drained amount, demonstrating how the bridge's accounting failure created claims against a reserve that was never there.
The Verus attack formed part of a series of security incidents reported within hours, with Lookonchain tracking a total of $35.55 million in combined losses across three exploits. The figures included $24.15 million from AFX Trade, approximately $7.55 million from Verus, and roughly $3.86 million from B² Network. Earlier in the day, an AFX-operated bridge lost $24.15 million in USDC before the attacker moved the funds to Ethereum and converted them into 12,467 ETH. As reported by Cointelegraph, the wider market was quiet on July 23, 2026, with Bitcoin at $65,734, down 0.5% on the day, and the Fear & Greed index reading 39 in fear territory. The VerusCoin drain did not move prices significantly, a pattern common with repeat exploits that are too small to shift markets but large enough to wipe out bridge reserves.
The latest exploit comes approximately two months after the Verus Ethereum Bridge lost roughly $11.58 million in a separate attack in May 2026. According to security researchers, the May attacker exploited a validation gap that allowed a forged cross-chain import to pass verification even though the value committed on the source side did not match the payout released on Ethereum. As reported by crypto.news in May, the first attacker later returned 4,052.4 ETH, worth about $8.5 million at the time, after the project offered settlement terms, while keeping 1,350 ETH as a bounty. The repeat nature of the July exploit suggests the first incident was not fully patched, or that the fix addressed the symptom rather than the underlying validation gap. Blockaid noted that although the attacker used a different wallet and transaction, they still targeted the same bridge contract, entry path, and likely bug category as in the May breach.
The Verus exploit has raised fresh security concerns across the cryptocurrency ecosystem, even though Ethereum's core network remained secure throughout the incident. According to market analysis, repeated exploits across projects in Ethereum's ecosystem have weakened market confidence, with most losses coming from vulnerable off-chain components rather than broken cryptography. Ethereum currently trades at $1,935 at press time, well below optimistic long-term forecasts that suggest potential targets of $7,500 by year-end according to Standard Chartered, or between $10,000 and $20,000 according to Arthur Hayes. The base case points to sideways trading while markets digest the latest security news, with traders watching whether buyers can defend support around current levels. A steady recovery would reinforce confidence that recent ecosystem exploits have not damaged the network's long-term outlook.