Verus-Ethereum Bridge Loses $7.5M in Second Exploit Within 66 Days

ETH-2.40%
USDC0.01%
Key Takeaways
  • Verus-Ethereum Bridge suffered a second exploit on July 23, draining $7.3 to $7.5 million in digital assets.
  • The attack exploited the same authorization bypass flaw from the May 17 breach that stole approximately $11.6 million.
  • The bridge failed to verify that payout amounts matched assets locked on the Verus side, enabling unbacked withdrawals.

The Verus-Ethereum Bridge suffered a second exploit on July 23, Thursday, with attackers draining $7.3 million to $7.5 million in digital assets through a maliciously crafted import request, according to blockchain security researchers. The breach exploited the same authorization bypass and protocol-state assumption flaw that enabled a May 17 attack stealing approximately $11.6 million, bringing total losses to about $19.1 million across 66 days. Security analysts identified the root cause as insufficient verification logic: while the bridge validated notary signatures, state roots, and Merkle proofs, it failed to confirm that payout amounts matched assets locked on the Verus side, allowing unbacked withdrawals from Ethereum reserves. The incident underscores persistent security challenges in cross-chain bridge infrastructure, where cryptographic verification succeeds but business-logic validation for asset backing fails.

Attackers Exploit Authorization Bypass in Bridge Logic

The attack involved a maliciously crafted import from the Verus side that included an unbacked payout request on Ethereum. The bridge verified notary signatures, state roots, and Merkle proofs, but it failed to verify that the requested payout amount matched the assets locked or exported on the Verus side, according to security analysts.

Backward Labs stated the root cause was an authorization bypass and protocol-state assumption issue. The bridge accepted a proven import authorizing multi-asset reserve payouts, but critical upstream checks for creation, authorization, transfer hash, count, and economic backing were insufficient. One analysis noted: "This time, the same root cause remained exploitable for 66 days."

Several monitoring tools flagged the transaction with a critical score, citing state manipulation, arbitrary minting, and decentralized finance (DeFi) outflows.

Bridge Reserves Lose ETH, USDC, DAI, and Six Other Assets

Assets drained from the bridge's reserves included Ether, tBTC, MKR, USDC, Tether, EURC, and scrvUSD. For DAI, the bridge interacted with a Sky (formerly MakerDAO) collateral position to mint roughly 220,357 DAI to fulfill the fraudulent request.

The May 17 breach had stolen approximately $11.6 million using a similar method, bringing combined losses to about $19.1 million.

Backward Labs Publishes Proof-of-Concept and Root-Cause Analysis

Backward Labs published a report and proof-of-concept highlighting the broken invariant: "Ethereum bridge reserves may be released only for source-chain reserve transfers whose CCE creation, authorization, transfer hash, count, and economic backing are all proven under the expected bridge lifecycle."

The exploit highlights ongoing security challenges with cross-chain bridges, where cryptographic verification succeeds but business-logic validation for asset backing fails. Bridge exploits remain a recurring issue in DeFi, often leading to unrecoverable losses because blockchain transactions are immutable.

Frequently Asked Questions

What happened to the Verus-Ethereum Bridge on July 23?
Attackers exploited an authorization bypass flaw on July 23, draining $7.3 million to $7.5 million in digital assets including ETH, USDC, DAI, tBTC, MKR, Tether, EURC, and scrvUSD through a maliciously crafted import request that bypassed asset-backing verification.

Why did the same vulnerability remain exploitable for 66 days?
The bridge's smart contract failed to verify that payout amounts matched assets locked on the Verus side. While it validated cryptographic proofs and signatures, critical upstream checks for creation, authorization, transfer hash, count, and economic backing were insufficient, allowing the same attack method used on May 17 to succeed again on July 23.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments