The Verus Bridge has been attacked again: losses exceed $7.5 million
On July 23, the Verus cross-chain bridge fell victim to a hacker attack again — the second such incident in the last two months. The attacker exploited a vulnerability in the smart contract import path, allowing them to initiate unbacked payouts on the Ethereum side. The attack resulted in the theft of approximately $7.54 million in various assets: ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
Repetition of the May attack scenario
This hack bears a striking resemblance to the incident that occurred on May 18, when the protocol lost $11.5 million. Analysts note that the attack was carried out through the same contract, using the same entry point and the same class of vulnerability. This indicates that previous fixes were likely insufficient or did not address the root cause of the problem.
The Verus bridge, designed to transfer assets between different blockchains, came under attack due to insufficient verification of imported data. The hacker was able to manipulate the verification process, leading to the issuance of funds without corresponding backing on the source chain. Such vulnerabilities are typical of cross-chain solutions, where the complexity of interaction between different networks often leaves gaps.
Professional perspective
The repeated hacking of the same protocol with an identical attack vector is an alarming signal for the entire industry. This demonstrates that the Verus team either did not conduct a proper audit after the first incident or the implemented patches were superficial. For users, this is a reminder: even after high-profile hacks, one should not blindly trust restored protocols without a thorough security review. Personally, I recommend refraining from using bridges that have already been attacked until a full report on the problem resolution is published and an independent audit is conducted.