According to blockchain security platform Blockaid, Verus Protocol's Ethereum bridge was exploited on Monday through fraudulent cross-chain transfer messages, allowing an attacker to steal at least $11.58 million. The attacker transferred 1,625 ETH, 147,659 USDC, and 103.57 tBTC v2, which were subsequently converted to approximately 5,402 ETH worth $11.4 million, according to Etherscan data verified by PeckShield.
Blockaid identified the exploit as a missing source-amount validation flaw in the bridge's verification logic, requiring roughly 10 lines of Solidity code to fix. The attacker deceived the protocol by using forged cross-chain import payloads that passed verification flows, resembling previous bridge exploits including the $190 million Nomad Bridge and $325 million Wormhole incidents from 2022.