A bridge is a blockchain-based tool that lets assets move between two networks that otherwise cannot interact with each other. It holds real tokens on one side and issues claims against them on the other, and its safety depends entirely on correctly verifying that every withdrawal is genuinely backed by assets locked on the other chain.
The Verus flaw let an attacker trigger payouts on the Ethereum side that were never properly backed on the Verus side, so the bridge released real money against a claim worth almost nothing.
The attacker returned most of the funds in exchange for a bounty after the May attack. Verus then redeposited the recovered money into the same bridge on July 8, according to onchain records compiled by security researchers, and the bridge was drained again two weeks later.
The cost of that trust is visible in the protocol’s own numbers. Verus held close to $100 million in total value locked at the start of 2025, according to DefiLlama. It holds about $9 million as of Thursday, a slow bleed punctuated by a fresh drop this week as the latest hack landed.

Such repeated failures do not just cost the money stolen in any single attack, but drain the confidence that keeps assets on the platform at all.

