đ¨ The VerusâEthereum Bridge has been exploited again.
Same contract. Same vulnerability. Same attack method.
⢠May 17: ~$11.6M stolen
⢠July 23: ~$7.5M stolen
The same root cause remained exploitable for 66 days, bringing the combined loss to approximately $19.1M.
How did the attack work?
The attacker submitted a maliciously crafted Verus-side import containing an unbacked payout request. The bridge successfully verified the notary-signed state root, Merkle proof, and transaction hashesâbut failed to confirm that the amount requested on Ethereum matched the amount actually exported or locked on Verus.
In other words, the cryptography worked, but it authenticated the wrong thing:
It proved that the import had been notarizedânot that the payout was fully backed.
Once the crafted import passed verification, the bridge treated it as legitimate and released assets from its own reserves, including ETH, tBTC, MKR, USDC, USDT, EURC, and scrvUSD.
The DAI path went even further: the bridge accessed its MakerDAO collateral position and minted approximately 220,357 DAI to satisfy the fraudulent payout.
The attack flow was:
Malicious Verus import
â Valid notary and proof verification
â Missing source-amount validation
â Unbacked Ethereum payout
â Bridge reserves drained
Victim contract:
0x71518580f36feceffe0721f06ba4703218cd7f63
Attacker:
0xbda71b58cec0b1c20a8f87ccd52fa0679747855c
Payout recipient:
0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54
TX:
0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099