The Verus bridge has come under attack again: a second hack in two months has stolen $7.54 million.

On July 23, the Verus cross-chain bridge fell victim to attackers again — this is the second incident in the last two months. This time, the damage amounted to approximately $7.54 million. The attack was carried out through a vulnerability in the smart contract import path, allowing the hacker to initiate unbacked payouts on the Ethereum side.
As a result of the hack, the attacker withdrew funds in several assets: ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. It is important to note that the attack method and entry point turned out to be identical to those used in the protocol hack on May 18, when $11.5 million was stolen. Essentially, the exploit succeeded due to the same vulnerability in the contract that had not been fixed after the first incident.
Situation Analysis
The repeated hack of the same protocol using a similar attack vector is an alarming signal for the entire DeFi ecosystem. It indicates insufficient attention to security audits and the prompt fixing of critical vulnerabilities. In a context where bridges remain among the most vulnerable infrastructure elements, such incidents undermine user trust in cross-chain solutions.
Expert comment: The repeated attack on Verus demonstrates a systemic problem: many projects, after the first hack, limit themselves to a partial patch without conducting a full code review. Until teams implement multi-layered security systems and start practicing bug bounty programs with high rewards, such incidents will recur. The market must learn: security is not a one-time action, but a continuous process.