Loading prices…
STKR NewsSTKR News0 of 3 free this month
Markets

New Verus-Ethereum bridge attack drains $7.5 million through flaw used in May: Blockaid

A recurring vulnerability in the Verus-Ethereum bridge has led to a $7.5 million drain, highlighting a critical failure in cross-chain security and code remediation.

Originally on The Block
AB

Adrian Boysel

Contributor

Jul 23, 2026

4 min read

Photo illustration / STKR News

The Brutality of a Second Act

In the crypto space, losing money once to a vulnerability is a tragedy. Losing money twice to the same flavor of failure is a systemic warning sign. We just saw the Verus-Ethereum bridge get hit for $7.54 million, and the kicker is that this looks like a sequel to a movie we already watched in May.

Security firm Blockaid flagged this latest drain, and the numbers aren't small. Seven and a half million dollars might be a rounding error for a tier-one protocol, but for a specialized bridge, it’s a devastating blow to user trust. As builders, we have to look past the dollar amount and ask why the door was left unlocked a second time.

The Mechanics of the Repeat

Bridges have always been the weakest link in the chain. They are the bottlenecks where assets sit in limbo between security models. If you’re building in this space, you know that bridging logic is notoriously brittle. But what happened here wasn't a sophisticated zero-day attack that no one could have predicted. It was an exploit leveraging the same vulnerability class that was targeted earlier this year.

When an exploit happens, the standard operating procedure is simple: pause, audit, patch, and verify. Somehow, the bridge resumed operations or maintained a logic path that allowed attackers to circle back. It’s like a thief breaking into a store through a loose floorboard in May, and then coming back in October to find the floorboard was just covered with a rug rather than being replaced.

The Compliance and Security Gap

We often talk about the "move fast and break things" mentality of early-stage development. That works for a UI/UX layout or a social app. It does not work for cross-chain infrastructure. When you are managing millions in user deposits, movement must be deliberate.

The issue often lies in the complexity of the Ethereum Virtual Machine (EVM) interactions. Verus is trying to bridge a specific ecosystem with Ethereum, and that translation layer is where the friction is. Attackers aren't breaking the cryptography of the chains themselves; they are breaking the bookkeeping logic that tells the bridge how much collateral is actually held.

Why Builders Should Care

If you’re a founder or a lead dev, this story should make you paranoid about your own technical debt. Often, when we "fix" a bug, we fix the specific instance of it. We don't necessarily fix the underlying architectural flaw that allowed the bug to exist in the first place.

  • Patching vs. Re-architecting: If your code allows for unauthorized withdrawals under specific edge cases, patching that one edge case isn't enough. You need to verify if the entire permissioning system is sane.
  • The Audit Trap: Many teams treat an audit as a shield. They get the stamp of approval and stop thinking about security. But an audit only captures a moment in time. If you update the code post-audit to fix a minor issue, you might inadvertently re-open a major hole.
  • User Responsibility: There is a growing fatigue among users regarding bridge security. Each time a bridge like this fails, it pushes users back toward centralized exchanges or massive, monolithic chains. This hurts the vision of a decentralized, multi-chain future.

The Cost of Inaction

A $7.5 million loss is painful, but the loss of momentum is worse. For the Verus ecosystem, this bridge is a vital artery. When that artery is clogged or leaking, the entire ecosystem stagnates. Developers stop building because they can't guarantee liquidity, and users stop depositing because they don't want to be the next headline.

We have to stop treating these exploits as "part of the game." They are preventable failures of governance and oversight. If a vulnerability was identified in May, every line of related code should have been scrutinized under a microscope before the bridge was allowed to carry significant traffic again.

Moving Forward with Skepticism

I’ve always said that transparency is the only thing that saves us in this industry. We need a post-mortem that doesn't hide behind technical jargon. We need the Verus team and their security partners to explain, in plain English, why the May exploit wasn't a sufficient warning to harden the system against this specific class of attack.

"In decentralization, there is no one to call when the money is gone. This reality requires a level of diligence that most modern software teams simply aren't used to."

For those of us building the next wave of tools, let this be a reminder: your code is a moving target. The bad actors are watching your patches more closely than your users are. They are looking for the shortcuts you took to get back to market quickly.

The Takeaway

Don't trust a bridge just because it’s convenient. As a builder, vet the infrastructure you rely on. If a protocol has a history of repeating the same mistakes, that is a culture problem, not a code problem. Security isn't a feature you add; it is the foundation you build on. If the foundation is cracked, eventually the whole house comes down, regardless of how many times you paint the walls.


Read the original at The Block →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses