Koinlytics

Verus Redeposited $11.56M Into The Bridge That Just Got Drained. Two Weeks Later An Attacker Emptied It Again For $7.54M

Jul 23, 2026ETHUSDCUSDTTBTCMKRverusethereum-bridgeexploitblockaidrepeat-exploitbridge-security
Verus refunded its bridge on July 8 after the May exploit. Fourteen days later a different attacker drained $7.54M through the same forged import path bug class. Blockaid flagged the entry vector as identical. Post-incident review missed the class.

The Verus Ethereum bridge lost $7.54M in ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD at roughly 21:30 UTC on July 22, 2026. Blockaid flagged the drain in real time and stated the obvious in one line: same bridge contract, same entry path, same bug class as the May 17 incident that took 1,625.36 ETH, 103.56 tBTC and 147,658 USDC out the door for a combined $11.56M. Different attacker wallet. Different transaction. Same mechanic.

The interesting timeline is not the two months between exploits. It is the fourteen days between the redeposit and the second drain. Verus recovered funds from the May attacker, then on July 8 pushed those funds back into the same contract. Two weeks later, an unrelated wallet ran the same trick and walked with three quarters of the redeposited value.

The Bug Class, In One Paragraph

The Verus to Ethereum bridge accepts import proofs from the Verus network and releases the corresponding assets on Ethereum. The exploit forges the import path on the Verus side so the Ethereum contract believes an import has been posted and backed, then pays out assets that have no matching deposit on the origin chain. It is an unbacked payout, not a stolen deposit. The bridge does not verify that the claimed origin state actually exists. Fix the class and every forged path variant fails. Patch a single reproduction and the class survives.

What A Proper Review Would Have Caught

A post-incident review after May had two obligations. First, characterise the bug at the class level and produce a written invariant the bridge must enforce: no asset release on Ethereum without a validated, non-replayable, non-forgeable origin state proof. Second, test the invariant against every path that constructs or accepts an import proof, not only the one the May attacker used. If the July attacker was able to reach payout through a different transaction shape using the same class of forgery, the invariant was never encoded. What shipped was a patch to a specific reproduction, not a fix to the underlying acceptance logic. That is the difference between remediating an incident and remediating a bug.

The Redeposit Decision Is The Real Signal

Recovering funds from a May attacker is a good outcome. Redepositing those funds into the same contract, on July 8, without a public third party audit of the bug class fix, is the decision that produced the July 22 loss. Fourteen days is not enough time to audit a bridge under any serious methodology. It is not enough time to run adversarial fuzzing across the import proof surface, publish results, and let external reviewers replicate. The team either compressed the timeline, ran the review internally, or trusted that the specific patch closed the class. All three interpretations point to the same failure of discipline.

What This Says To A Holder

Repeat exploits of the same bug class are the highest signal event a portfolio holder can receive about a protocol. They separate teams that own their security posture from teams that respond to incidents. A protocol that ships a class level fix, publishes the invariant, and pays for external verification before restoring TVL is a different asset than one that patches, waits, and redeposits. The July 22 drain is not a story about a clever attacker. It is a story about what a two month gap was and was not used for.

What Koinlytics tracks: repeat exploit patterns at the bug class level, days between remediation and TVL restoration, presence of external audit sign off before redeposit, and the ratio of recovered to re lost funds across bridge incidents. When the same class ships twice, we downgrade the protocol before the third attempt.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics