Recurring Vulnerabilities: The Verus-Ethereum Bridge Faces Second Major Exploit
The security of cross-chain infrastructure is once again under the spotlight as the Verus-Ethereum Bridge fell victim to a massive exploit on July 23rd. This latest incident, which resulted in the loss of millions in digital assets, has reignited urgent concerns regarding the platform's architectural integrity and its ability to defend against persistent, targeted threats.
A $7.5 Million Breach
Blockchain security firm Blockaid identified the breach occurring at approximately 03:45 UTC, marking a significant blow to the bridge's liquidity. The attacker successfully manipulated the bridge’s import process, a maneuver that allowed them to release and withdraw funds without depositing any matching assets on the source chain. This sophisticated drainage resulted in the theft of roughly 1,137 ETH, alongside a variety of other tokens including USDC, USDT, tBTC, and MKR, with a total estimated value of $7.54 million at the time of the outflow.
Repeating Past Mistakes
What makes this attack particularly alarming is its striking similarity to a previous breach recorded in May, which saw over $11.5 million stolen. Security analysts noted that while the perpetrator utilized a different wallet and transaction path this time, they targeted the exact same bridge contract and a nearly identical bug category. This recurrence suggests that the underlying vulnerabilities were not fully mitigated after the first incident, raising serious questions about the bridge's safety protocols and the effectiveness of its previous security patches.