Cross-chain infrastructure has once again proven to be one of the most vulnerable surface areas in decentralized finance. The Verus-Ethereum Bridge has suffered a devastating second exploit in roughly two months [cite: The Verus-Ethereum Bridge has suffered a second exploit in just about two months after an attacker drained roughly $7.54 million in crypto assets on Wednesday by exploiting the same vulnerability class used in the protocol’s May breach, according to blockchain security firm Blockaid]. On Wednesday, an attacker successfully drained approximately $7.54 million in various cryptocurrency assets from the protocol [cite: The Verus-Ethereum Bridge has suffered a second exploit in just about two months after an attacker drained roughly $7.54 million in crypto assets on Wednesday by exploiting the same vulnerability class used in the protocol’s May breach, according to blockchain security firm Blockaid].
What makes the security failure particularly alarming is that the hacker utilized the exact same vulnerability class and entry path that was previously exploited during the bridge’s massive breach back in May [cite: Verus-Ethereum Bridge has suffered a second exploit in just about two months after an attacker drained roughly $7.54 million in crypto assets on Wednesday by exploiting the same vulnerability class used in the protocol’s May breach, according to blockchain security firm Blockaid. Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path, and vulnerability class, while noting the transaction was carried out by a different attacker using a new loot wallet.]. The incident serves as a stark reminder of the extreme risks associated with unpatched smart contract code across cross-chain bridges.
Mechanics of the Hack: Exploiting the Import Path
According to forensic data shared by blockchain security firm Blockaid, the hacker targeted the bridge’s internal import path mechanics. By abusing this specific contract function, the attacker was able to trick the smart contract into approving and executing unbacked payouts directly on the Ethereum side of the bridge [cite: In a post on X, Blockaid said the attacker abused the bridge’s import path to trigger unbacked Ethereum-side payouts, draining ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves before converting the stolen assets into ETH].
This allowed the exploiter to systematically siphon a wide spectrum of high-value reserve tokens out of the bridge contract, including the following:
- Major Cryptocurrencies: Ethereum (ETH) and tBTC [cite: In a post on X, Blockaid said the attacker abused the bridge’s import path to trigger unbacked Ethereum-side payouts, draining ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves before converting the stolen assets into ETH.].
- Stablecoins: Circle’s USDC, Tether’s USDT, EURC, and scrvUSD.
- Governance Tokens: Maker (MKR).
Once the assets were drained from the bridge reserves, the attacker immediately consolidated the loot [cite: In a post on X, Blockaid said the attacker abused the bridge’s import path to trigger unbacked Ethereum-side payouts, draining ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves before converting the stolen assets into ETH]. Blockchain security firm CertiK also flagged the exploit, estimating losses at approximately $7.53 million. Security firm CertiK noted that the exploiter swapped the stolen multi-asset basket into 3,916.1 ETH [cite: Blockchain security firm CertiK also flagged the exploit, estimating losses at approximately $7.53 million.] The firm said the attacker withdrew the funds through the Verus-Ethereum bridge, later swapped the stolen assets for 3,916.1 ETH, and deposited the proceeds into Tornado Cash. The proceeds were then promptly deposited into the privacy mixer Tornado Cash to launder the stolen capital and sever the onchain paper trail.
A History of Unaddressed Security Failures
Security analysts at Blockaid highlighted that this latest attack is directly linked to an earlier security breach disclosed on May 18 [cite: Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path and vulnerability class, while noting the transaction was carried out by a different attacker using a new loot wallet., The previous exploit on May 18 drained roughly $11.6 million from the bridge after the attacker converted the stolen assets into about 5,402 ETH.
In that May exploit, a hacker drained $11.6 million from the exact same bridge contract [cite: Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path and vulnerability class, while noting the transaction was carried out by a different attacker using a new loot wallet., The previous exploit on May 18 drained roughly $11.6 million from the bridge after the attacker converted the stolen assets into about 5,402 ETH. That initial incident ended on a somewhat positive note: after swapping the funds into 5,402 ETH, the original hacker agreed to keep a 25% white-hat bug bounty and safely returned 4,052 ETH back to the protocol [cite: The previous exploit on May 18 drained roughly $11.6 million from the bridge after the attacker converted the stolen assets into about 5,402 ETH]. The attacker later returned 4,052 ETH after retaining a 25% white-hat bounty.
However, despite receiving a high-profile warning shot in May, the underlying logic flaw within the bridge contract remained exposed [cite: Verus-Ethereum Bridge has suffered a second exploit in just about two months after an attacker drained roughly $7.54 million in crypto assets on Wednesday by exploiting the same vulnerability class used in the protocol’s May breach, according to blockchain security firm Blockaid]. Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path, and vulnerability class while noting the transaction was carried out by a different attacker using a new loot wallet. On-chain analysis confirms that Wednesday’s attack was carried out by an entirely new actor using a fresh wallet, who simply recognized that the previously exposed entry path was still vulnerable to abuse [cite: Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path, and vulnerability class, while noting the transaction was carried out by a different attacker using a new loot wallet].
The Unforgiving Nature of Smart Contracts
The second draining of the Verus-Ethereum Bridge brings total losses across both exploits past the $19 million mark [cite: The Verus-Ethereum Bridge has suffered a second exploit in just about two months after an attacker drained roughly $7.54 million in crypto assets on Wednesday by exploiting the same vulnerability class used in the protocol]. May breach, according to blockchain security firm Blockade: The previous exploit on May 18 drained roughly $11.6 million from the bridge after the attacker converted the stolen assets into about 5,402 ETH. It highlights a fundamental truth about public blockchain security: open-source smart contracts are continuously monitored by malicious actors.
When a protocol suffers an exploit, simply negotiating with an attacker or patching a surface symptom is never enough. If the core vulnerability class in the underlying smart contract isn’t completely rewritten or paused, it is only a matter of time before another hacker takes advantage of the opening [cite: The Verus-Ethereum Bridge has suffered a second exploit in just about two months after an attacker drained roughly $7.54 million in crypto assets on Wednesday by exploiting the same vulnerability class used in the protocol’s May breach, according to blockchain security firm Blockaid]. Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path, and vulnerability class, while noting the transaction was carried out by a different attacker using a new loot wallet. As the Verus development team assesses the damage, the broader Web3 ecosystem is left with another sobering lesson on the critical need for immediate, comprehensive contract audits after any protocol breach [cite: Meanwhile, Blockaid said the latest exploit appears related to the Verus-Ethereum bridge attack disclosed in May, citing the same bridge contract, entry path, and vulnerability class while noting the transaction was carried out by a different attacker using a new loot wallet. The Block has reached out to the Verus team for comment on the latest attack.
