Verus Ethereum Bridge Exploited for $11.6M via Fraudulent Cross-Chain Messages on Monday

ETH-1.53%
W-2.52%

According to blockchain security platform Blockaid, Verus Protocol's Ethereum bridge was exploited on Monday through fraudulent cross-chain transfer messages, allowing an attacker to steal at least $11.58 million. The attacker transferred 1,625 ETH, 147,659 USDC, and 103.57 tBTC v2, which were subsequently converted to approximately 5,402 ETH worth $11.4 million, according to Etherscan data verified by PeckShield.

Blockaid identified the exploit as a missing source-amount validation flaw in the bridge's verification logic, requiring roughly 10 lines of Solidity code to fix. The attacker deceived the protocol by using forged cross-chain import payloads that passed verification flows, resembling previous bridge exploits including the $190 million Nomad Bridge and $325 million Wormhole incidents from 2022.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments