Verus-Ethereum Bridge Hack 2026 — $8M Exploit Analysis

A second, different attacker exploited the identical submitImports import-path flaw in the same Verus-Ethereum bridge contract that was hit on May 18, 2026 for ~$11.58M, releasing ~$7.54M at 03:45 UTC. Assets were consolidated into ~3,916 ETH and routed through Tornado Cash.

Details

Full Description

On July 23, 2026, a second, different attacker exploited the identical submitImports import-path flaw in the same Verus-Ethereum bridge contract (0x71518580f36feceffe0721f06ba4703218cd7f63) that was hit on May 18, 2026 for ~$11.58M. The attacker initiated a 0.01 VRSC export, then relayed notarizations containing malicious duplicate state-root entries that overwrote the genuine trusted root, submitting a fabricated import proof that released ~$7.54M across ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD at 03:45 UTC. Assets were consolidated into ~3,916 ETH via DEX swaps and routed through Tornado Cash. The May attacker had returned 4,052.4 ETH (keeping a 25% bounty), and those funds were redeposited into the unpatched contract on July 8, 2026. The cumulative two-event loss was ~$19.1M over 66 days. Blockaid and CertiK issued alerts.

Laundering Analysis

Assets were consolidated into ~3,916 ETH via DEX swaps and routed through the Tornado Cash mixer. The May attacker had returned 4,052.4 ETH (keeping a 25% bounty), and those funds were redeposited into the unpatched contract on July 8, 2026.

Sources

Related Hacks

Back to Browse