{"id":75818,"date":"2026-07-23T17:05:00","date_gmt":"2026-07-23T17:05:00","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/verus-bridge-suffers-second-exploit-in-66-days-as-flaw-pushes-total-losses-to-19-1m\/"},"modified":"2026-07-23T17:05:00","modified_gmt":"2026-07-23T17:05:00","slug":"verus-bridge-suffers-second-exploit-in-66-days-as-flaw-pushes-total-losses-to-19-1m","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/verus-bridge-suffers-second-exploit-in-66-days-as-flaw-pushes-total-losses-to-19-1m\/","title":{"rendered":"Verus Bridge Suffers Second Exploit in 66 Days as Flaw Pushes Total Losses to $19.1M"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">On July 23, attackers exploited a flaw in the Verus-Ethereum Bridge, stealing $7.5M in digital assets.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">The breach underscores DeFi risks where cryptographic proofs pass but asset backing fails.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Users should track Verus channels for updates, while protocols must fix state-check logic.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>Flawed Logic Behind the Breach<\/h2>\n<p>The Verus-Ethereum Bridge smart contract was exploited again on Thursday, with attackers draining $7.3 million to $7.5 million in different digital assets, according to blockchain security researchers. The incident marks the second breach of the same contract and vulnerability in two months. On May 17, <a href=\"https:\/\/news.bitcoin.com\/binance-research-april-defi-exploits-13-billion-outflows\/\">attackers stole approximately $11.6 million<\/a> using a similar method, bringing total losses to about $19.1 million.<\/p>\n<p>Security analysts said the attack involved a maliciously crafted import from the Verus side that included an unbacked payout request on Ethereum. The bridge verified notary signatures, state roots, and Merkle proofs, but it failed to verify that the requested payout amount matched the assets locked or exported on the Verus side.<\/p>\n<p>According to Backward Labs, the root cause was an authorization bypass and protocol-state assumption issue. The bridge accepted a proven import authorizing multi-asset reserve payouts, but critical upstream checks for creation, authorization, transfer hash, count, and economic backing were insufficient. One analysis noted:<\/p>\n<blockquote>\n<p>\u201cThis time, the same root cause remained exploitable for 66 days.\u201d<\/p>\n<\/blockquote>\n<p>Assets drained from the bridge\u2019s reserves included Ether, tBTC, MKR, USDC, Tether, EURC, and scrvUSD. For DAI, the bridge interacted with a <a href=\"https:\/\/news.bitcoin.com\/defi-giant-makerdao-rebrands-as-sky-introduces-usds-stablecoin-and-sky-token\/\">Sky (formerly MakerDAO)<\/a> collateral position to mint roughly 220,357 DAI to fulfill the fraudulent request.<\/p>\n<p>Several monitoring tools flagged the transaction with a critical score, citing state manipulation, arbitrary minting, and decentralized finance (DeFi) outflows.<\/p>\n<p><a href=\"https:\/\/x.com\/backwardlabs\/status\/2080253758739734658\" target=\"_blank\" rel=\"noopener noreferrer\">Backward Labs published a report<\/a> and proof-of-concept highlighting the broken invariant: \u201cEthereum bridge reserves may be released only for source-chain reserve transfers whose CCE creation, authorization, transfer hash, count, and economic backing are all proven under the expected bridge lifecycle.\u201d<\/p>\n<p>The exploit highlights ongoing security challenges with cross-chain bridges, where cryptographic verification succeeds but business-logic validation for asset backing fails. Bridge exploits remain a recurring issue in DeFi, often leading to unrecoverable losses because blockchain transactions are immutable.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/verus-bridge-suffers-second-exploit-in-66-days-as-flaw-pushes-total-losses-to-19-1m\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways On July 23, attackers exploited a flaw in the Verus-Ethereum Bridge, stealing $7.5M in digital assets. The breach underscores DeFi risks where cryptographic proofs pass but asset backing fails. Users should track Verus channels for updates, while protocols must fix state-check logic. Flawed Logic Behind the [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":75819,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/75818"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=75818"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/75818\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/75819"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=75818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=75818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=75818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}