The Verus Ethereum Bridge, a cross-chain solution connecting the VerusCoin blockchain with Ethereum, faced a significant security breach on Thursday. Attackers successfully drained approximately $7.54 million worth of various cryptocurrencies directly from the bridge’s reserves on the Ethereum network.
Blockaid was among the first to detect the incident and reported that the attacker exploited the bridge’s import path. This allowed them to trigger unbacked payouts on the Ethereum side without corresponding assets on the Verus network. The stolen funds include a mix of major assets: ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. This latest breach adds to a growing list of high-profile incidents affecting DeFi protocols and bridges in recent weeks.
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum.
An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.
More details in 🧵— Blockaid (@blockaid_) July 23, 2026
Verus and the Ethereum Bridge Background
VerusCoin (VRSC) is a blockchain project that began in 2018, focusing on privacy, decentralization, and multi-chain functionality. It uses a hybrid consensus mechanism (Proof of Power combining PoW and PoS) and supports features like zero-knowledge privacy and the ability to launch custom public blockchains (PBaaS).
The Verus-Ethereum Bridge, fully operational since October 2023, is promoted as a non-custodial, trustless bridge. It enables asset transfers and conversions between Verus and Ethereum using cryptographic proofs verified by Verus miners and stakers, without relying on centralized custodians. The bridge aims for transparent, consensus-proven accounting of funds.
History and Post-May Exploit
The bridge suffered a major exploit in May 2026, where approximately $11.58 million was drained using a similar vulnerability in the import path and validation logic. In that incident, a significant portion of funds (about 75%) was later returned by the exploiter. Following the May hack, the project and bridge operators reviewed the incident and were expected to strengthen validation checks between the Verus and Ethereum sides.
Despite these steps, the July exploit occurred on the same bridge contract using a similar import path and bug class. This shows that the underlying validation issue had not been fully resolved.
Exploit Details
- Bridge Contract: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Loot Wallet: 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54
- Attacker Address (as reported): 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c
The attacker called the submitImports function, leading to payouts from bridge reserves without matching Verus-side backing. The core issue was the same as in May, insufficient verification that input amounts on one side matched the payout amounts on the Ethereum side.
There are no confirmed reports of fund recovery at the time of writing. The incident once again draws attention to the challenges of securing cross-chain bridges, even in projects with strong decentralization principles. Similar pressures have been visible in other recent exploits, such as the shutdown of SecondFi following a security breach and the sharp crash in Balance Coin after a protocol exploit. Users are advised to remain cautious with bridge interactions and monitor official Verus channels for any updates or patches.

















