Verus Bridge Re-Hacked: $7.54 Million Lost — Same Vulnerability as in May

On July 23, the Verus cross-chain bridge was attacked again — the second time in the last two months. This time, the attacker exploited a vulnerability in the contract import mechanism, allowing them to initiate unbacked payouts on the Ethereum side. As a result, the hacker withdrew assets worth approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD.
An analysis of the incident conducted by Blockaid specialists shows that the attack was carried out through the same contract, using the same entry point and the same class of vulnerability as the hack on May 18, which caused $11.5 million in damages. This indicates that the protocol team did not fix the root problem in the security architecture, leaving the bridge open to repeated exploitation.
Why is this important?
The repeated hack of Verus is an alarming signal for the entire DeFi ecosystem. If a protocol that has already suffered a major attack fails to close a critical vulnerability, it calls into question not only the competence of its developers but also the overall reliability of cross-chain solutions. Investors and users must demand full audits and transparency from teams in fixing breaches; otherwise, such incidents will keep recurring.
My expert conclusion: Against the backdrop of growing consolidation in the DeFi market, repeated attacks on the same protocol are not a coincidence but a systemic failure. Without implementing "security by design" principles and mandatory use of formal contract verification, such bridges will remain easy prey for hackers. I recommend refraining from interacting with Verus until a full audit and a detailed report on vulnerability remediation are published.