The Verus-Ethereum Bridge suffered its 2nd exploit successful 2 months, with attackers draining $7.3 cardinal to $7.5 cardinal successful assorted integer assets.
Key Takeaways
- On July 23, attackers exploited a flaw successful the Verus-Ethereum Bridge, stealing $7.5M successful integer assets.
- The breach underscores DeFi risks wherever cryptographic proofs walk but plus backing fails.
- Users should way Verus channels for updates, portion protocols indispensable hole state-check logic.
Flawed Logic Behind the Breach
The Verus-Ethereum Bridge astute declaration was exploited again connected Thursday, with attackers draining $7.3 cardinal to $7.5 cardinal successful antithetic integer assets, according to blockchain information researchers. The incidental marks the 2nd breach of the aforesaid declaration and vulnerability successful 2 months. On May 17, attackers stole astir $11.6 million utilizing a akin method, bringing full losses to astir $19.1 million.
Security analysts said the onslaught progressive a maliciously crafted import from the Verus broadside that included an unbacked payout petition connected Ethereum. The span verified notary signatures, authorities roots, and Merkle proofs, but it failed to verify that the requested payout magnitude matched the assets locked oregon exported connected the Verus side.
According to Backward Labs, the basal origin was an authorization bypass and protocol-state presumption issue. The span accepted a proven import authorizing multi-asset reserve payouts, but captious upstream checks for creation, authorization, transportation hash, count, and economical backing were insufficient. One investigation noted:
“This time, the aforesaid basal origin remained exploitable for 66 days.”
Assets drained from the bridge’s reserves included Ether, tBTC, MKR, USDC, Tether, EURC, and scrvUSD. For DAI, the span interacted with a Sky (formerly MakerDAO) collateral presumption to mint astir 220,357 DAI to fulfill the fraudulent request.
Several monitoring tools flagged the transaction with a captious score, citing authorities manipulation, arbitrary minting, and decentralized concern (DeFi) outflows.
Backward Labs published a report and proof-of-concept highlighting the breached invariant: “Ethereum span reserves whitethorn beryllium released lone for source-chain reserve transfers whose CCE creation, authorization, transportation hash, count, and economical backing are each proven nether the expected span lifecycle.”
The exploit highlights ongoing information challenges with cross-chain bridges, wherever cryptographic verification succeeds but business-logic validation for plus backing fails. Bridge exploits stay a recurring contented successful DeFi, often starring to unrecoverable losses due to the fact that blockchain transactions are immutable.

1 day ago









English (US)