Why the Verus Ethereum Bridge Got Hacked Twice in Two Months, and What It Reveals About DeFi Security
The Verus Ethereum Bridge was exploited for the second time in two months on July 23, 2026, with attackers stealing approximately $7.54 million in digital assets including tBTC, USDC, USDT, EURC, MKR, and scrvUSD. What makes this incident particularly alarming is that the latest attack appears to have exploited the same type of vulnerability in the bridge's import mechanism that was used in a similar breach just two months earlier in May.
A bridge in blockchain terminology is a protocol that allows users to move assets from one blockchain network to another. For example, a bridge might let someone transfer Bitcoin to the Ethereum network, where it can be used in decentralized finance (DeFi) applications. The Verus bridge connects the Verus blockchain to Ethereum, making it a critical piece of infrastructure for users who want to move value between these two networks. When a bridge is compromised, it can drain millions in user funds because bridges often hold large pools of assets in custody.
How Did the Same Vulnerability Get Exploited Twice?
The root cause of the July exploit is still under investigation, but the pattern is troubling. Although the attacker used a different transaction and wallet address compared to the May incident, both breaches targeted the same bridge contract and exploited the same category of vulnerability. This suggests that either the bridge developers did not fully patch the underlying flaw after the first attack, or the fix was incomplete.
The Verus breach was not an isolated incident. On the same day, other protocols suffered major exploits. According to on-chain analytics platform Lookonchain, attacks affecting AFX Trade, Verus, and B² Network resulted in combined losses of around $35.55 million within a matter of hours. This clustering of attacks on the same day underscores how security vulnerabilities in one protocol can create a cascade of risk across the broader DeFi ecosystem.
What's Driving the Shift From Code Audits to Credential Theft?
The crypto industry has long relied on smart contract audits, which are third-party reviews of blockchain code designed to catch bugs before deployment. However, the threat landscape has fundamentally changed. Enterprise blockchain security experts now warn that the largest risks no longer come from flawed code alone, but from stolen private keys, compromised credentials, and poor identity management.
A private key is a cryptographic secret that proves ownership of digital assets and authorizes transactions. If an attacker obtains a private key, they can move funds instantly without needing to exploit any smart contract vulnerability. Unlike code-based exploits, which may take time to discover and execute, credential theft gives attackers immediate and valid access to blockchain resources. This is why cybercriminals are increasingly targeting employees, cloud infrastructure, and administrative systems rather than directly attacking blockchain protocols.
The shift reflects a broader reality: it only takes one compromised credential for an attacker to gain access to valuable assets. When administrator credentials, API tokens, SSH keys, or privileged identities become compromised, attackers have direct access to blockchain infrastructure, bypassing application security controls entirely.
Steps to Strengthen Enterprise Blockchain Security
- Implement Identity and Access Management (IAM): Enterprises must deploy robust IAM systems to control who has access to private keys, administrative functions, and cloud infrastructure. This includes multi-factor authentication, role-based access controls, and continuous monitoring of privileged accounts.
- Secure Cloud Environments: Misconfigured cloud environments, unsecured storage buckets, insecure Kubernetes clusters, or compromised virtual machines can create critical threats to blockchain platforms. Regular security audits and hardening of cloud infrastructure are essential.
- Monitor Supply Chain Security: Modern blockchain ecosystems rely on third-party libraries, CI/CD pipelines, software dependencies, and cloud services. Breaches in supply chains can introduce malicious code, illegally acquired digital signature certificates, or backdoors that compromise the entire system.
- Establish Private Key Management Policies: Organizations must implement strict policies for generating, storing, and rotating private keys. Hardware security modules (HSMs) and encrypted key vaults can reduce the risk of unauthorized access.
- Conduct Regular Penetration Testing: Beyond code audits, enterprises should perform regular penetration tests targeting credential theft, insider threats, and infrastructure vulnerabilities to identify weaknesses before attackers do.
The financial impact of compromised credentials is severe. Once a private key is stolen, criminals can sign transactions and move assets across multiple blockchain networks in seconds, giving security teams almost no time to respond. Unlike smart contract bugs, which can sometimes be patched or mitigated, a compromised private key is often irrevocable. Once a transaction is confirmed by the network, it becomes permanent, even if the owner did not authorize it.
The challenge is compounded by the fact that many organizations use the same identity infrastructure across multiple blockchain networks, wallets, validators, and decentralized applications. A single compromised private key or privileged account can leak assets across Ethereum, BNB Chain, Polygon, Solana, and other chains, resulting in massive financial and operational risk.
What Are Regulators Saying About DeFi Security?
The Financial Action Task Force (FATF), an international organization focused on combating money laundering and terrorist financing, recently released its seventh compliance report on cryptocurrency regulation. The findings reveal a significant gap between legislative progress and enforcement action. While 86% of the 147 jurisdictions assessed have completed virtual asset risk assessments, and 83% have implemented Travel Rule legislation, enforcement is lagging behind.
The FATF identified several emerging risks that regulators are struggling to address. These include industrial-scale fraud operations, such as Cambodia-based scam compounds that laundered at least $4 billion between 2021 and 2025; proprietary, freeze-resistant stablecoins becoming the preferred vehicle for illicit activity; and AI-assisted smart contract exploits that are scaling up cybercrime.
One of the most significant regulatory blind spots involves decentralized finance (DeFi) itself. DeFi refers to financial applications built on blockchains that operate without traditional intermediaries like banks. The FATF found that 93% of jurisdictions are yet to identify qualifying DeFi arrangements where an identifiable owner or operator is known, making it difficult to subject DeFi entities to virtual asset service provider (VASP) regulation. A VASP is any business that provides services related to virtual assets, such as exchanges or custodians.
The FATF recommends that firms strengthen transaction monitoring and wallet screening, and enhance due diligence when it comes to unhosted wallets, which are wallets not controlled by a regulated entity. It also advises firms to check their exposure to DeFi protocols, bridges, mixers, and cross-chain services, all of which have become common targets for attackers.
The repeated compromise of the Verus bridge underscores why these regulatory recommendations matter. Bridges are critical infrastructure in the DeFi ecosystem, yet they remain vulnerable to both code-based exploits and credential theft. Until the industry develops more robust security practices and regulators establish clearer oversight frameworks, bridges and other cross-chain services will continue to be attractive targets for attackers seeking to steal millions in user funds.
" }