
The Verus–Ethereum bridge was drained of $7.54M in July 2026 — the second exploit in two months using the same flaw. Here's what a bridge hack is, why they keep happening, and the practical lessons for UK users who move crypto across chains.
Important Risk Warning
This is not financial advice. Cryptocurrency investments are highly volatile. The value of your investment can go down as well as up, and you could lose all the money you invest. Don't invest unless you're prepared to lose all the money you put in.
In July 2026 the Verus–Ethereum bridge was exploited for around $7.54 million across ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD — the second attack in two months using the same vulnerability that cost $11.5 million in May. A "bridge" is the plumbing that moves crypto between blockchains, and it's become one of the most repeatedly hacked pieces of the whole crypto system. For UK users dabbling in DeFi, the incident is a blunt reminder: bridges concentrate risk, and using them means trusting code that has, again and again, proven breakable. There's no FSCS to call when a bridge is drained.
What stings about this one is that it's a repeat — the same flaw, exploited twice, months apart. That pattern tells you something important about DeFi security, and it isn't reassuring.
A bridge is software that lets you move crypto from one blockchain to another, and hacks happen because bridges lock up large pools of assets that attackers target. Because different blockchains can't natively talk to each other, bridges "lock" your coins on one chain and issue an equivalent on another. That design means bridges hold big reserves of crypto in smart contracts — huge, tempting honeypots. If there's a flaw in the code, attackers can drain those reserves, as happened to the Verus–Ethereum bridge.
The especially troubling detail here is that the July exploit reused the same vulnerability as May's $11.5M hack — meaning the flaw wasn't fully fixed after the first attack. Bridges have historically been among the biggest single sources of crypto losses, with billions stolen across the sector over the years. Our KelpDAO bridge exploit piece covers another example, and our what is DeFi guide explains the wider ecosystem.
Because bridges are complex, hold concentrated value, and any code flaw is instantly exploitable for huge sums. Smart-contract code is unforgiving: a single bug can be worth millions to whoever finds it first, and there's no bank to reverse the theft. Bridges are especially exposed because they're technically intricate and sit at the junction of two chains, doubling the attack surface. And as the Verus case shows, patching one hole doesn't guarantee the whole thing is secure.
There's also no safety net. DeFi is "decentralised" — often no company is clearly responsible, funds are usually unrecoverable, and there's no regulator-backed compensation. That's the flip side of DeFi's openness: you get permissionless access and, with it, permissionless risk. UK users need to internalise that using a bridge means accepting you could lose everything you move through it if the code fails. This is exactly the sort of risk the FCA warns about with crypto generally.
Treat bridges as high-risk, move only what you can afford to lose, and don't assume "fixed" means safe. Practical lessons from the Verus hack:
If you're a beginner, honestly, the safest approach is to steer clear of bridges and complex DeFi entirely until you understand the risks. There's no shame in keeping things simple. Our best wallets guide and self-custody guide cover safer ways to hold crypto.
What is a crypto bridge hack? It's when attackers exploit a flaw in a bridge — software that moves crypto between blockchains — to drain the assets it holds. Because bridges lock up large pools of crypto, a single code vulnerability can let hackers steal millions, as in the Verus–Ethereum bridge exploit.
How much was stolen in the Verus–Ethereum bridge hack? Around $7.54 million across multiple tokens including ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD. It was the second exploit in two months using the same vulnerability that caused a $11.5 million loss in May 2026.
Why do bridge hacks keep happening? Bridges are complex, hold concentrated value, and any code flaw is instantly exploitable for large sums with no bank to reverse it. They sit between two blockchains, doubling the attack surface, and patching one bug doesn't guarantee overall security — as the repeated Verus exploit showed.
Can I get my money back after a bridge hack? Usually not. DeFi typically has no company clearly responsible, no regulator-backed compensation, and no FSCS protection. Stolen bridge funds are often unrecoverable. This lack of recourse is a core risk of moving crypto through bridges and using DeFi generally.
Is it safe to use crypto bridges? Bridges are among the highest-risk parts of crypto. Even audited, established bridges have been hacked. If you use one, move only what you can afford to lose, prefer reputable options, and avoid recently-exploited protocols. Beginners are often safest avoiding bridges entirely.
If you use DeFi, adopt a hard rule after the Verus hack: never move more through a bridge than you'd accept losing outright, and steer clear of any protocol recently exploited — a flaw hit twice in two months is a warning, not a dip to buy. If you're a beginner, it's perfectly sensible to avoid bridges altogether. This isn't financial advice; DeFi carries no FSCS protection. Our what is DeFi guide covers the basics safely.
We use cookies to enhance your experience. By clicking "Accept", you agree to our use of cookies for analytics. See our Privacy Policy.