Verus-Ethereum Bridge July 2026 import verification exploit
On July 23, 2026, the Verus-Ethereum Bridge was exploited through the Ethereum import path, causing unbacked payouts from bridge reserves. Reproducible Ethereum analysis and contemporaneous reporting place the drain at about $7.54 million across ETH, tBTC, USDC, USDT, MKR, scrvUSD, and EURC. Verus's August 1 security release explicitly references the latest Ethereum bridge hack while saying Ethereum contracts were not yet ready for upgrade. Recovery, reimbursement, and post-incident reopening remain unverified.
Incident facts
- Incident title
- Verus-Ethereum Bridge July 2026 import verification exploit
- Bridge
- Verus-Ethereum Bridge
- Incident date
- 2026-07-23
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Verus, Ethereum
- Affected assets
- ETH, tBTC, USDC, USDT, MKR, scrvUSD, EURC
- Attack category
- Message Verification Failure
- Reported loss
- about $7.54 million
- Amount confidence
- Medium
- Loss amount basis
- Mixed Sources
- Recovery
- Unknown
- Reimbursement
- Unknown
- Restart
- Paused
- Current outcome
- Paused Long Term
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-20
- Last verified
- 2026-08-20
Amount and valuation
Independent full-chain analysis and contemporaneous reporting converge on approximately $7.54 million drained from Ethereum-side bridge reserves.
The approximately $7.54 million figure is not a first-party exact accounting statement. Reproducible token outflows and contemporaneous reporting support the approximate total, whose USD value depends on valuation timing.
ETH, tBTC, USDC, USDT, MKR, scrvUSD, and EURC drained from Ethereum bridge reservesabout $7.54 million
Used as the approximate canonical display amount; individual token outflows remain independently reproducible.
Why this remains unresolved
- No admitted reviewed source establishes a completed July-specific attacker-fund recovery.
- No admitted reviewed source establishes July-specific user or protocol reimbursement.
- A dated post-July bridge or cross-chain reopening has not been established; the August 1 first-party release said Ethereum contracts were not yet ready for upgrade.
Timeline events
Verus-Ethereum Bridge exploited through Ethereum import path2026-07-23
A July 23 Ethereum transaction drained approximately $7.54 million in ETH, tBTC, USDC, USDT, MKR, scrvUSD, and EURC after an import-verification failure allowed unbacked payouts from bridge reserves. Verus later referenced the latest bridge hack in its August 1 security release; post-incident Ethereum bridge reopening remained unverified.
Safe high-level mechanism only. The May and July 2026 incidents remain separate, and May recovery/restoration figures are not imported into this event.
Evidence records
- Verus v1.2.17-3 — critical security upgradeVerusCoin · Tier 1 · High reliability · primary · 2026-08-01Claim scope: Incident Case
Stable first-party incident-specific authority explicitly referring to the latest Ethereum bridge hack and continuing hardening work while stating that Ethereum contracts were not yet ready for upgrade. It links the long-form Google Doc, which remains review authority only and is not admitted here.
- The missing check: a full-chain post-mortem of the $7.54M Verus bridge exploitSIRENBOW · Tier 2 · High reliability · secondary · 2026-07Claim scope: Incident Case
Independent reproducible full-chain analysis supporting the July 23 ~03:45 UTC transaction boundary, bridge/implementation/verification-contract identifiers, approximate $7.54 million total, affected ERC-20 outflows, and the high-level unbacked-import verification failure.
- Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apartCoinDesk · Tier 2 · High reliability · secondary · 2026-07-23Claim scope: Amount
Contemporaneous reporting corroborating the second July incident, approximate $7.54 million drain, affected asset classes, and separation from the earlier May exploit.
- Verus-Ethereum Bridge July 2026 exploit transactionEtherscan · Tier 2 · High reliability · secondary · 2026-07-23Claim scope: Incident Case
Direct Ethereum transaction reference for the July 23 drain. Used to anchor the on-chain incident boundary; aggregate USD valuation remains sourced through the reviewed technical/reporting package.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The first-party long-form security writeup remains review authority only because no admissible archive capture was found under BIR's existing risky-host preservation boundary; it is not added as canonical evidence in this application.
- Canonical displayed mechanism language is intentionally limited to the independently supported import-verification / unbacked-payout boundary rather than reproducing implementation-level details supported only by the unadmitted long-form source.
- The separate May 2026 exploit has its own recovery and restoration history and is not reused as evidence for July recovery, reimbursement, or restart.
- The exact USD valuation can vary with contemporaneous token prices even though the transaction and token outflows are reproducible.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.