{
  "id": 172113,
  "title": "How the Verus-Ethereum Bridge Exploit Bypassed Cross-Chain Validation",
  "url": "https://urgent.news/2026/08/05/how-the-verus-ethereum-bridge-exploit-bypassed-cross-chain-validation",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-08-05T08:01:04.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/how-the-verus-ethereum-bridge-exploit-bypassed-cross-chain-validation?source=rss"
  },
  "original_language": "en",
  "account": "Cross-chain bridges require agreement between two different state machines, leading to vulnerabilities. The Verus-Ethereum bridge exploit was a failure of basic cross-chain validation, trusting a forged receipt due to oversight. Developers attempting to connect an account-based Ethereum ledger to a UTXO-based Verus system created an incompatible marriage, relying on intermediate relayer nodes that submit unverified state proofs. The Ethereum smart contract accepted a malformed proof of burn without verifying the cryptographic root of the transaction tree. Bridges use lock-and-mint mechanisms, where tokens locked on Chain A mint IOUs on Chain B, preventing infinite money glitches. The exploit bypassed this by submitting a fabricated Merkle proof, which the contract blindly accepted. The EVM processed the verification function without cross-referencing the block header against a decentralized oracle. The attacker exploited this by feeding the Ethereum smart contract a fabricated block header claiming burned tokens on Verus, which the contract accepted. The attacker drained 1,137 ETH and proportionate tokens within a single transaction, causing a $7.54 million loss due to MEV bots pouncing on the liquidity imbalance. The incident resulted from trust in centralized relayers and prioritizing speed over robust validation.",
  "summary": "Forensic deep-dive into the Verus-Ethereum bridge exploit. Discover how compromised cross-chain validation and fabricated Merkle proofs drained $7.54M.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}