Verus Ethereum Bridge Suffers $7.54M Exploit, Raising Security Concerns

Changelly
Blockonomics


What to know:

  • Verus Bridge loses $7.54 million after attackers exploit cross-chain import validation vulnerability again.
  • Attacker steals ETH, stablecoins, and tokenized assets before laundering funds through Tornado Cash.
  • The second Verus Bridge breach raises concerns over incomplete security patches and validation mechanisms.

The Verus Ethereum Bridge has suffered another major security breach after attackers stole approximately $7.54 million in crypto assets on July 23, marking the protocol’s second exploit in just over two months. 

Blockchain security firm Blockaid said the attacker abused the bridge’s submitImports function to trigger Ethereum-side payouts without corresponding assets being locked on the Verus blockchain, allowing funds to be withdrawn from the bridge’s reserves.

Independent security researcher exvulsec confirmed the exploit shortly after it was detected. The incident has renewed concerns over whether the vulnerability behind Verus’ $11.58 million exploit in May was fully addressed and highlights the persistent security risks facing cross-chain bridges across decentralized finance (DeFi).

Ledger

Verus Ethereum Bridge Loses 1,137 ETH in $7.54M Hack

According to on-chain data, the exploit occurred at approximately 03:45 UTC, draining seven assets from the bridge’s Ethereum reserves, including 1,137 ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD. The stolen assets were valued at roughly $7.54 million at the time of the attack.

Investigators said the attacker quickly swapped the stolen tokens through decentralized exchanges, consolidating them into nearly 3,916 ETH before routing portions of the funds through Tornado Cash, making asset recovery significantly more difficult.

Also Read: SpaceX Stock Surges Into Focus as Alphabet Reveals $94.1 Billion Investment

Same Bug Hits Verus Bridge Again

Blockaid said that the most recent attack targeted the same bridge contract, the same entry point, and the same type of vulnerability that the previous attack in May exploited, but this time by a new attacker wallet. 

Even though Verus has yet to produce a technical breakdown, experts believe that this vulnerability allowed payments in Ethereum without confirming lockups on the other chain.

The recurring security problem raises questions regarding the validity of whether or not the security hole was fully resolved before operations on the bridge resumed. 

In May, the same attacker returned to claim around 4,052 ETH, which represents around 75% of the stolen funds, after reaching an agreement with Verus.

Cross-Chain Security Under Pressure

The Verus attack was just one among many other attacks that also struck AFX Trade and B² Network, which, according to the on-chain tracker Lookonchain, had resulted in a total loss of about $35.55 million. 

According to the security experts, these attacks are an example of how attackers are increasingly trying to attack bridges due to logical errors in cross-chain messaging.

What Happens Next?

Despite Verus having stopped all the bridges due to the ongoing investigation, a compensation plan has not been put forward by the developers alongside an elaborate explanation of the hack. 

It is anticipated that the Verus team will address the core of the problem by strengthening its procedures for validating the bridge and determining where the missing funds have gone. The problem will continue to attract criticism towards the company until such time as an elaborate update is released.

Also Read: Asian Market Falls as AI Spending Doubts and Oil Surge Pressure Stocks



Source link

Bitbuy

Be the first to comment

Leave a Reply

Your email address will not be published.


*