Home » Verus Bridge Suffers Second Exploit in 66 Days as Flaw Pushes Total Losses to $19.1M

Verus Bridge Suffers Second Exploit in 66 Days as Flaw Pushes Total Losses to $19.1M

by Maria Vaughan
0 comments


Key Takeaways

Flawed Logic Behind the Breach

The Verus-Ethereum Bridge smart contract was exploited again on Thursday, with attackers draining $7.3 million to $7.5 million in different digital assets, according to blockchain security researchers. The incident marks the second breach of the same contract and vulnerability in two months. On May 17, attackers stole approximately $11.6 million using a similar method, bringing total losses to about $19.1 million.

Security analysts said the attack involved a maliciously crafted import from the Verus side that included an unbacked payout request on Ethereum. The bridge verified notary signatures, state roots, and Merkle proofs, but it failed to verify that the requested payout amount matched the assets locked or exported on the Verus side.

According to Backward Labs, the root cause was an authorization bypass and protocol-state assumption issue. The bridge accepted a proven import authorizing multi-asset reserve payouts, but critical upstream checks for creation, authorization, transfer hash, count, and economic backing were insufficient. One analysis noted:

“This time, the same root cause remained exploitable for 66 days.”

Assets drained from the bridge’s reserves included Ether, tBTC, MKR, USDC, Tether, EURC, and scrvUSD. For DAI, the bridge interacted with a Sky (formerly MakerDAO) collateral position to mint roughly 220,357 DAI to fulfill the fraudulent request.

Several monitoring tools flagged the transaction with a critical score, citing state manipulation, arbitrary minting, and decentralized finance (DeFi) outflows.

Backward Labs published a report and proof-of-concept highlighting the broken invariant: “Ethereum bridge reserves may be released only for source-chain reserve transfers whose CCE creation, authorization, transfer hash, count, and economic backing are all proven under the expected bridge lifecycle.”

The exploit highlights ongoing security challenges with cross-chain bridges, where cryptographic verification succeeds but business-logic validation for asset backing fails. Bridge exploits remain a recurring issue in DeFi, often leading to unrecoverable losses because blockchain transactions are immutable.



Source link

You may also like

Leave a Comment

About Us

Advertisement

Latest Articles

Editor's Picks

© 2024 Technewsupdate. All rights reserved.