Urgent.News

What's breaking now, across thousands of outlets.

Finance & Markets

How the Verus-Ethereum Bridge Exploit Bypassed Cross-Chain Validation

Forensic deep-dive into the Verus-Ethereum bridge exploit. Discover how compromised cross-chain validation and fabricated Merkle proofs drained $7.54M.

How the Verus-Ethereum Bridge Exploit Bypassed Cross-Chain Validation

Cross-chain bridges require agreement between two different state machines, leading to vulnerabilities. The Verus-Ethereum bridge exploit was a failure of basic cross-chain validation, trusting a forged receipt due to oversight. Developers attempting to connect an account-based Ethereum ledger to a UTXO-based Verus system created an incompatible marriage, relying on intermediate relayer nodes that submit unverified state proofs.

The Ethereum smart contract accepted a malformed proof of burn without verifying the cryptographic root of the transaction tree. Bridges use lock-and-mint mechanisms, where tokens locked on Chain A mint IOUs on Chain B, preventing infinite money glitches. The exploit bypassed this by submitting a fabricated Merkle proof, which the contract blindly accepted.

The EVM processed the verification function without cross-referencing the block header against a decentralized oracle. The attacker exploited this by feeding the Ethereum smart contract a fabricated block header claiming burned tokens on Verus, which the contract accepted. The attacker drained 1,137 ETH and proportionate tokens within a single transaction, causing a $7.54 million loss due to MEV bots pouncing on the liquidity imbalance.

The incident resulted from trust in centralized relayers and prioritizing speed over robust validation.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Finance & Markets

More from Wednesday 5 August →