The Verus Ethereum cross-chain bridge has suffered another security incident. Blockaid, an on-chain security company, stated that attackers exploited the bridge's import path on July 23 to transfer approximately $7.54 million in assets from the same bridge contract as the one involved in the May incident.
The attack path is similar to that in May.
Blockaid stated that the attack occurred on the Ethereum side, where the attacker triggered a payment not backed by assets on the source chain via the bridge's import path. According to them, the incident used different transactions and attacker-controlled addresses, but involved the same bridge contract, the same entry path, and what appears to be a similar type of vulnerability.
However, Blockaid has not yet released a full technical report, and the exact cause of the vulnerability is still under investigation.
Multiple assets were transferred out
On-chain records show that the attacking transaction occurred at 03:45 UTC on July 23, interacting with the Verus Ethereum Bridge contract. The transaction transferred approximately 1,137 ETH and various other tokens to an address controlled by the attacker.
- Approximately 1,137 ETH were transferred out.
- Involves assets such as tBTC, USDC, and USDT.
- At the time, it was valued at approximately US$7.54 million.
Blockaid marked the receiving address as 0xCFd0…2D54 and confirmed that the withdrawal came from the same bridging contract involved in the May incident.
Three attacks occurred within hours.
According to the on-chain tracking account Lookonchain, AFX Trade, Verus, and B² Network reported security incidents within hours of each other, with a combined loss of approximately $35.55 million.
- AFX: Approximately US$24.15 million
- Verus: Approximately $7.55 million
- B² Network: Approximately US$3.86 million
Earlier that day, a bridge operated by AFX suffered a theft of approximately $24.15 million USDC. The attackers then transferred the funds to Ethereum and converted them into 12,467 ETH. Offchain Labs stated that the incident did not involve the Arbitrum native bridge, but rather stemmed from infrastructure operated by a third-party protocol.
Some funds were recovered in May.
Verus also suffered a bridging attack in May. According to previous reports, the first attacker returned 4,052.4 ETH (worth approximately $8.5 million at the time) after the project offered a settlement. The attacker kept 1,350 ETH as a bounty.
Cross-chain bridges need to verify messages across different blockchains and manage assets in a shared reserve. If issues arise with message verification, contract logic, or access control, assets may be released without corresponding transfers. Currently, the specific cause of the vulnerability and the progress of subsequent recovery efforts have not been disclosed.












