Incident case

Verus-Ethereum Bridge July 2026 import verification exploit

On July 23, 2026, the Verus-Ethereum Bridge was exploited through the Ethereum import path, causing unbacked payouts from bridge reserves. Reproducible Ethereum analysis and contemporaneous reporting place the drain at about $7.54 million across ETH, tBTC, USDC, USDT, MKR, scrvUSD, and EURC. Verus's August 1 security release explicitly references the latest Ethereum bridge hack while saying Ethereum contracts were not yet ready for upgrade. Recovery, reimbursement, and post-incident reopening remain unverified.

reviewedcurrent

Incident facts

Incident title
Verus-Ethereum Bridge July 2026 import verification exploit
Bridge
Verus-Ethereum Bridge
Incident date
2026-07-23
Incident type
Exploit
Major incident
Yes
Affected chains
Verus, Ethereum
Affected assets
ETH, tBTC, USDC, USDT, MKR, scrvUSD, EURC
Attack category
Message Verification Failure
Reported loss
about $7.54 million
Amount confidence
Medium
Loss amount basis
Mixed Sources
Recovery
Unknown
Reimbursement
Unknown
Restart
Paused
Current outcome
Paused Long Term
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-08-20
Last verified
2026-08-20

Amount and valuation

Independent full-chain analysis and contemporaneous reporting converge on approximately $7.54 million drained from Ethereum-side bridge reserves.

The approximately $7.54 million figure is not a first-party exact accounting statement. Reproducible token outflows and contemporaneous reporting support the approximate total, whose USD value depends on valuation timing.

Why this remains unresolved

Timeline events

  • Verus-Ethereum Bridge exploited through Ethereum import path2026-07-23

    A July 23 Ethereum transaction drained approximately $7.54 million in ETH, tBTC, USDC, USDT, MKR, scrvUSD, and EURC after an import-verification failure allowed unbacked payouts from bridge reserves. Verus later referenced the latest bridge hack in its August 1 security release; post-incident Ethereum bridge reopening remained unverified.

    Exploit OccurredHigh

    Safe high-level mechanism only. The May and July 2026 incidents remain separate, and May recovery/restoration figures are not imported into this event.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.