Bitcoin, Ethereum-linked protocols lose $35 million in attacks six hours apart
Protocols linked to Bitcoin and Ethereum lost a combined $35 million in several attacks over six hours. At least three bridges and cross-chain protocols were exploited. But the attackers did not crack the cryptography protecting BTC or ETH. They went around safeguards in applications built on those blockchains. That distinction matters. For investors, the real exposure sits in protocol design, key management and a basic question: can decentralized finance projects safely hold customer funds?

Blockchain data reviewed by CoinDesk and reports from security firms BlockAid and PeckShield put the combined losses above $35 million. Each attack involved faulty protocol rules or a compromised key that handed someone unauthorized control. None reportedly broke the blockchains’ underlying cryptography. Most explanations stop there and call the base chains secure. That’s only half right. Depositors will find little comfort in a technically sound blockchain when the application above it approves a fraudulent withdrawal.
The Verus-Ethereum bridge lost about $7.54 million after an attacker triggered payouts without providing assets of equal value. BlockAid detected the exploit early Thursday, July 23, 2026. The attacker drained ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD. Seven assets, all gone from the bridge reserves. These were not thinly traded curiosities; the theft reached Ethereum liquidity, tokenized bitcoin and stablecoins traders regularly post as collateral. I’ll be honest: that mix makes the incident harder to dismiss as a niche-token blowup.
“Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum. An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves.” – Blockaid, July 23, 2026
The flaw was in the bridge’s import path, which permitted payouts on Ethereum without proper backing on Verus. A bridge generally locks assets on one network, then issues matching claims on another. Every withdrawal should map to assets held elsewhere. Here, the contract reportedly released ETH, tBTC and stablecoins for a claim worth almost nothing. Why does that matter? Because the code apparently followed its rules. The rules themselves were broken.
Verus had reportedly suffered the same kind of failure before. The latest attacker reused the contract and entry path connected to an earlier hack that cost $11.5 million in May. Most of that money was later returned for a bounty. Onchain records compiled by security researchers show that Verus put the recovered assets back into the same bridge on July 8. Roughly two weeks later, someone drained it again. My take: calling that bad luck is a stretch.
The repeat failure may bring regulatory scrutiny to Ethereum-based finance products and the people who control them. To be precise, the July 23 source material mentions no action by the SEC or CFTC. Still, bridges holding customer assets are obvious targets for policymakers when their safety depends on upgrade keys and withdrawal checks. Governance decisions matter too. Counter to the usual framing, ETH’s normal settlement is not the end of the analysis. The harder question is whether businesses built around ETH can protect money as reliably as the financial services they copy.
Verus had already lost much of the market’s confidence before Thursday’s attack. DefiLlama reportedly listed close to $100 million in total value locked at the start of 2025. By Thursday, the figure was about $9 million—a decline of roughly 91%. That calculation uses the two reported amounts, but the direction is unmistakable. Money had been leaving for months. Then the latest $7.54 million loss gave depositors another reason to go.
The attacks give investors another reason to question assets moved across chains through synthetic claims. Bridges let people use BTC, ETH and stablecoins outside their native networks, but every issued token must stay backed and redeemable. On July 23, tBTC holders got a painful reminder that tokenized bitcoin carries risks native BTC does not. Is that merely a technical distinction? No. Bitcoin can keep producing valid blocks while a bridge-issued version loses its backing or becomes difficult to redeem.
Stablecoins face the same danger when they pass through a bridge. USDC, USDT, EURC and scrvUSD were reportedly removed from Verus reserves during the $7.54 million exploit. Traders commonly use them as portable collateral. Moving those assets between networks adds contracts and validators; private keys create another failure point. Any one can break even while the stablecoin remains solvent. I keep coming back to the same ugly dynamic: once users doubt the backing, withdrawing before reserves run out feels sensible to each person and dangerous to everyone left behind.
Investors should distinguish BTC or ETH market risk from the risks added by a protocol. Native Bitcoin is not economically identical to tBTC held through a bridge. ETH in a private wallet is likewise different from ETH deposited in a cross-chain contract. Extra yield or easier access means trusting another system. That system can fail. Thursday’s six-hour string of attacks showed how quickly separate projects can begin losing money.
BlockAid’s findings make Verus’s response to the May attack particularly hard to defend. Verus reportedly encountered the same class of bug in the same contract and entry path after losing $11.5 million in May. It then put the recovered funds back into that bridge on July 8. Yes, that sounds harsher than the technical account above. It should. The two-week gap is central to the story: what did Verus test, what did it tell users, and why did the bridge reopen?
What this means
The July 23 attacks show that cross-chain losses often start with bad verification rules or privileged access while Bitcoin and Ethereum continue working normally. Verus now has about $9 million in total value locked, down from close to $100 million at the start of 2025. That’s a roughly 91% collapse. Anyone holding ETH, tBTC, USDC, USDT, EURC, MKR or scrvUSD through a bridge must check two separate things: the asset’s solvency and the bridge’s ability to honor redemptions. I would not treat one as evidence of the other.
Pay attention to what Verus discloses after July 23, 2026, particularly its remaining reserves and whether it suspends the contract or proposes recovery terms. The $9 million TVL figure is the benchmark. A continued decline would show that depositors are still leaving after the $7.54 million exploit. Other bridge operators now have a concrete job: inspect similar import paths, then review who controls powerful keys. Is that overkill? Not after three or more protocols were exploited within six hours. Another cluster could push losses beyond individual applications and strain liquidity for tokenized BTC and ETH.
FAQ
Q: What is a cross-chain bridge?
A: A cross-chain bridge transfers assets or information between blockchain networks. It usually locks an asset on one chain, then issues a corresponding token or claim on another.
Q: What caused the $35 million loss?
A: The attackers reportedly exploited flaws in protocol logic and compromised keys. They did not break the cryptography protecting the underlying blockchains.
Q: Which assets were stolen in the Verus exploit?
A: Seven assets were included: ETH, tBTC, USDC, USDT, EURC, MKR and scrvUSD.
Q: How far did Verus’s total value locked fall?
A: Verus’s TVL fell about 91%, dropping from nearly $100 million at the start of 2025 to roughly $9 million on Thursday.
Q: Had Verus suffered a similar attack before?
A: Yes. Verus reportedly lost $11.5 million in May because of the same class of bug in the same contract and entry path.
Q: Why separate BTC or ETH price risk from protocol risk?
A: Native assets and bridge-issued versions carry different risks. A bridge adds its own code and keys. Its redemption process is another dependency, and each can fail even when Bitcoin or Ethereum remains secure.
Q: What does this mean for stablecoins used across chains?
A: A stablecoin can remain solvent while the bridge carrying it fails. Cross-chain use introduces contracts and validators, plus keys that may block withdrawals or leave issued tokens without sufficient backing.
Q: What is BlockAid?
A: BlockAid is the blockchain security firm that detected and reported the Verus-Ethereum bridge exploit.
Q: What is tBTC?
A: tBTC is a tokenized version of Bitcoin on Ethereum. Holders can use its bitcoin-linked value in decentralized finance applications on Ethereum.
Q: What should investors take from these attacks?
A: Bitcoin or Ethereum’s security tells only part of the story. Investors also need to examine the protocol holding their funds: its withdrawal rules and control of private keys, along with how it responded to earlier bugs. The base chain isn’t enough.
