The Verus-Ethereum Bridge suffered its second exploit in two months, with attackers draining $7.3 million to $7.5 million in various digital assets.
Key Takeaways
On July 23, attackers exploited a flaw in the Verus-Ethereum Bridge, stealing $7.5M in digital assets.The breach underscores DeFi risks where cryptographic proofs pass but asset backing fails.Users should track Verus channels for updates, while protocols must fix state-check logic.Security analysts said the attack involved a maliciously crafted import from the Verus side that included an unbacked payout request on Ethereum. The bridge verified notary signatures, state roots, and Merkle proofs, but it failed to verify that the requested payout amount matched the assets locked or exported on the Verus side.
According to Backward Labs, the root cause was an authorization bypass and protocol-state assumption issue. The bridge accepted a proven import authorizing multi-asset reserve payouts, but critical upstream checks for creation, authorization, transfer hash, count, and economic backing were insufficient. One analysis noted:
“This time, the same root cause remained exploitable for 66 days.”
Several monitoring tools flagged the transaction with a critical score, citing state manipulation, arbitrary minting, and decentralized finance (DeFi) outflows.
The exploit highlights ongoing security challenges with cross-chain bridges, where cryptographic verification succeeds but business-logic validation for asset backing fails. Bridge exploits remain a recurring issue in DeFi, often leading to unrecoverable losses because blockchain transactions are immutable.


















