Verus-Ethereum Bridge Hack
What happened
An attacker exploited the Verus–Ethereum cross-chain bridge, draining approximately $7.44 million in ETH, tBTC, stablecoins, and MKR from Ethereum reserves.
A cross-chain notarization parsing and validation discrepancy allowed duplicate state-root entries to overwrite Ethereum's trusted Verus root, enabling acceptance of a fabricated import proof.
How it happened
The attacker introduced malicious duplicate state-root entries into notarization data that Verus and Ethereum interpreted differently. After the malicious root was relayed to Ethereum, a fabricated bridge-import proof released unbacked assets despite a 0.01 VRSC export.
Protocol details
Evidence
- report Post-mortem rekt.news
- report @0x3b33 incident report x.com
- report @CertiKAlert incident report x.com
- transaction Etherscan: Verus bridge drain transaction etherscan.io
- analysis DeFiLlama defillama.com
- analysis CertiK: Verus Incident Analysis certik.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.