Register and share your invite link to earn from video plays and referrals.

SunSec
@1nf0s3cpt
CISO @xrexinc | Founder @DeFiHackLabs Web3 Security Community | AiSecLabs | Contributor @SEAL_911
Joined November 2010
1.4K Following    14.2K Followers
🚨 The Verus–Ethereum Bridge has been exploited again. Same contract. Same vulnerability. Same attack method. • May 17: ~$11.6M stolen • July 23: ~$7.5M stolen The same root cause remained exploitable for 66 days, bringing the combined loss to approximately $19.1M. How did the attack work? The attacker submitted a maliciously crafted Verus-side import containing an unbacked payout request. The bridge successfully verified the notary-signed state root, Merkle proof, and transaction hashes—but failed to confirm that the amount requested on Ethereum matched the amount actually exported or locked on Verus. In other words, the cryptography worked, but it authenticated the wrong thing: It proved that the import had been notarized—not that the payout was fully backed. Once the crafted import passed verification, the bridge treated it as legitimate and released assets from its own reserves, including ETH, tBTC, MKR, USDC, USDT, EURC, and scrvUSD. The DAI path went even further: the bridge accessed its MakerDAO collateral position and minted approximately 220,357 DAI to satisfy the fraudulent payout. The attack flow was: Malicious Verus import → Valid notary and proof verification → Missing source-amount validation → Unbacked Ethereum payout → Bridge reserves drained Victim contract: 0x71518580f36feceffe0721f06ba4703218cd7f63 Attacker: 0xbda71b58cec0b1c20a8f87ccd52fa0679747855c Payout recipient: 0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54 TX: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
Show more