Verus Bridge Re-Hack: Hackers Withdrew $7.54 Million Again Through the Same Vulnerability

On July 23, the Verus cross-chain bridge was subjected to a targeted attack for the second time in two months. This time, the attacker exploited a vulnerability in the data import mechanism, allowing them to initiate unbacked payouts on the Ethereum side. As a result, approximately $7.54 million in assets were withdrawn from the protocol, including ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
My analysis shows that the incident is almost identical to the hack that occurred on May 18, when hackers stole $11.5 million. The critical vulnerability appears to be related to the same smart contract, the same entry point, and the same vulnerability class. This suggests that the Verus team either did not fully address the root cause of the problem or did not account for all possible attack vectors when redeploying the contracts.
Notably, the hacker specifically used the import path—a mechanism that was supposed to ensure secure data transfer between blockchains. An error in the validation of incoming messages allowed them to fabricate transactions that the system perceived as legitimate, even though there was no actual collateral on the other side of the bridge.
Expert Opinion
The repeated attack on Verus is an alarming signal for the entire cross-chain solutions segment. If the project team fails to radically overhaul the security architecture, trust in the protocol will be completely undermined. Under current conditions, investors should be extremely cautious about assets locked in bridges, especially if they have already demonstrated vulnerabilities of the same type.