BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Second Heist Raises Alarms Over DeFi Security

You can also read this news on BH NEWS: Second Heist Raises Alarms Over DeFi Security A notorious attacker has managed to siphon off approximately $7.54 million from the Verus Ethereum bridge

AnonymousCryptoCompass newsroom
July 23, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

You can also read this news on BH NEWS: Second Heist Raises Alarms Over DeFi Security

A notorious attacker has managed to siphon off approximately $7.54 million from the Verus Ethereum bridge, marking the protocol’s second hacking incident in just two months. This most recent exploit highlights a recurring vulnerability in the bridge’s cross-chain mechanism, which previously suffered a similar breach but remained unaddressed.

What are cross-chain bridges?

These bridges, designed to facilitate seamless cryptocurrency transactions across different blockchains, have become prime targets for cyber intrusions. Cross-chain bridges amass significant liquidity, thus enticing attackers to exploit them. A solitary mistake by validators can lead to huge financial losses for stakeholders involved.

Blockaid, a blockchain cybersecurity company, noted that such vulnerabilities have been a common theme across various bridge hacks since 2022, including this latest Verus incident. The attack capitalized on a flaw within the asset import feature of the bridge, enabling unwarranted Ethereum payouts.

The malicious actor manipulated the Verus Ethereum bridge protocol at a specific contract address, redirecting pilfered assets to another wallet. Several virtual currencies were impacted in this breach, adding to the growing list of affected digital assets.

Have the issues been fixed?

No, the duplicative nature of these attacks highlights the bridge’s unpatched security gaps. The vulnerability previously exploited, as analyzed by Blockaid, continued to persist, showing negligence in fortifying the bridge’s defenses.

Blockaid’s review found that both attacks exploited the identical import route on the same contract, revealing that the security gap went unpatched even after the initial hack.

A deeper examination by security firms, including Halborn and Merkle Science, reinforced these findings, pinpointing flaws in the value verification steps of the bridge’s contract. Rob Behnke from Halborn emphasized improper checks in the system as the crux of the vulnerability.

  • Both attacks used the same import loophole on the Verus bridge.
  • There was no verification of value alignment between Verus and Ethereum.
  • Similarities exist with past exploits on other bridges, like Wormhole.

Though the decentralized finance sector has seen an overall improvement in security, exemplified by fewer losses and more rigorous audits, the Verus incidents underscore the importance of addressing specific vulnerabilities. As vulnerabilities persist, complete security across individual protocols remains elusive.

Verus has yet to release a comprehensive analysis following this recent breach. Considering the past advisories from Merkle Science, users should exercise caution and await upgrades and independent verifications before further engaging with the bridge platform.

Continue Reading: Second Heist Raises Alarms Over DeFi Security