Verus-Ethereum bridge loses $7.5 million to recurring exploit

Hackers just hit the Verus-Ethereum bridge for the second time in two months. This latest drainage cost the protocol $7.54 million, according to security firm Blockaid. It's a frustrating case of deja vu because the attackers targeted the exact same vulnerability class that led to a May exploit. Security researchers discovered that the flaw allows malicious actors to manipulate price calculations, effectively sucking liquidity out of the bridge. This isn't just a one-off glitch; it's a systemic failure to patch a known weakness after the first warning shot. While the bridge was supposed to offer a gateway between ecosystems, it's currently serving as an ATM for opportunistic hackers. The team hasn't yet confirmed if the stolen funds are recoverable or if a hard fork is on the table to prevent a third strike. Users are now left wondering if the bridge code is fundamentally broken or just poorly maintained.
Read full story at The Block →