Crypto News

VerusCoin Ethereum Bridge Exploited Again, Draining $7.54M

Published: Jul 23, 2026By Aleksandar Dukic

Key Analysis

A second VerusCoin bridge exploit drained about $7.54M in unbacked tokens via forged payouts on July 23, 2026, repeating a pattern seen in an earlier attack.

VerusCoin Ethereum Bridge Exploited Again, Draining $7.54M

Listen To This Article

VerusCoin Ethereum Bridge Exploited Again, Draining $7.54M

4m 35s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

A VerusCoin Ethereum bridge was exploited for roughly $7.54 million on July 23, 2026, according to a Cointelegraph alert posted the same morning. The attacker drew out value through unbacked payouts, a method that matches an earlier exploit against the same protocol. It is the second time the bridge has been drained the same way.

Cross-chain bridges move value between blockchains that cannot talk to each other directly. A user locks a token on one chain, and the bridge issues a matching claim on the other chain that is supposed to be backed one-to-one by the locked collateral. The whole design rests on that accounting holding. When a bridge issues payouts that are not backed by real deposits, the tokens minted on the receiving side are claims against a reserve that was never there.

The mechanics of an unbacked payout

The reported attack path centers on payouts the protocol released without matching collateral. In practice, that means the bridge credited the Ethereum side with tokens it had no locked assets to support. The attacker then converted those unbacked tokens into liquid value and exited, leaving the reserve short by the drained amount.

This is different from a stolen private key or a phishing drain of individual wallets. The failure is in the bridge logic itself, the part that decides how much to release and whether a claim is legitimate. Once that check can be tricked, an attacker does not need to break any single user's security. They mint value that the system treats as real.

The repeat nature is the part that should worry users. A protocol getting exploited once is common. Getting exploited a second time through the same class of flaw suggests the first incident was not fully patched, or that the fix addressed the symptom rather than the underlying validation gap. Blockchain security researcher Charles Hoskinson warned this month that AI tooling is speeding up how fast attackers find and reuse these bridge weaknesses across protocols.

Bridges keep failing the same test

The VerusCoin drain lands in a stretch of bridge incidents. Cardano's NIGHT bridge lost around $515 million earlier in the month, and an AFX bridge exploit drained $24.15 million in USDC. Allbridge Core paused its bridge after a $1.65 million flash loan attack. Each has its own bug, but the shared theme is that the bridge held pooled assets and the accounting that protected them broke.

The dollar figure here is smaller than the headline bridge hacks of the month, but the pattern is the same. Pooled collateral plus a single validation weakness equals a total-loss event for the reserve. A retail user who moved funds through the bridge does not get to opt out of that risk. Their claim is only as good as the pool behind it.

The bridge risk most users underprice

The practical takeaway is not that all bridges are unusable, but that bridge exposure is a specific risk that most users underprice. Moving assets across chains means trusting a smart contract to hold collateral correctly, and that contract is a concentrated target. When it fails, individual caution does not help.

For anyone spending crypto rather than farming yield across chains, the lesson points toward reducing how often funds have to cross a bridge at all. Cards that draw directly from a wallet you control, the kind covered on our self-custody card options page, avoid parking balances in a pooled custodian or routing them through a bridge before they can be spent. Fewer hops means fewer places where someone else's broken accounting can become your loss. Custodial products carry a related counterparty exposure: if the provider holding your balance fails, your funds can be frozen regardless of your own security.

As of July 23, 2026, the wider market was quiet, with Bitcoin at $65,734, down 0.5% on the day, and the Fear & Greed index reading 39, in fear territory. The VerusCoin drain did not move prices. That is often how these repeat exploits land: too small to shift the market, large enough to wipe out the reserve behind the bridge.

Overview

A VerusCoin Ethereum bridge was drained of about $7.54 million on July 23, 2026, through unbacked payouts, the same method used in an earlier attack on the protocol. The repeat exploit points to an unresolved validation flaw in the bridge logic rather than a one-off breach. It fits a month of bridge failures where pooled collateral met a single accounting weakness and the reserve was emptied. For users, the sharpest defense is limiting how often funds pass through a bridge or a custodian at all.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.