Verus Hack
What happened
On July 23, 2026, the cross-chain bridge connecting the Verus blockchain to Ethereum was exploited for the second time in two months, resulting in the unauthorized extraction of approximately $7.53 million across multiple digital assets.
The exploit targeted a semantic and authority validation flaw in how the Ethereum-side bridge contract verifies cross-chain export outputs from Verus. While the contract verified that a given export payload existed within a valid Verus block and matched a genuine state root notarized on Ethereum, it failed to verify that the Verus network itself had authorized the payload as a legitimate primary export. The attacker initiated a tiny 0.01 VRSC bridge transaction to create a valid export state, then authored a custom Verus transaction spending that output and attaching a handwritten export commitment declaring 8 transfer instructions to the attacker's wallet.
After relaying two legitimate notarizations to Ethereum containing the state root of their custom transaction, the attacker submitted the import request. Because the cryptographic Merkle proofs and payload hash checks matched the attacker-controlled input data, the bridge executed the transfer, releasing $7.53 million in tBTC, DAI, USDC, scrvUSD, USDT, MKR, and EURC. The stolen assets were immediately swapped on-chain for 3,916.1 ETH and deposited into Tornado Cash.
Attacker Address: 0xCFd0A207…142D54
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report x.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.