CertiK Reveals Verus Bridge Exploit Leveraged Cross-Chain Semantic Flaws
CertiK analysis details how attackers exploited semantic differences in notarization data to forge state roots, bypassing validation checks on the Verus Ethereum bridge to steal assets.
Woofun AI reports that CertiK published an analysis of the July 23 attack on the Verus protocol’s Ethereum bridge. The investigation identified that attackers exploited semantic discrepancies between Verus and Ethereum regarding notarization data interpretation. By inserting malicious duplicate state root entries into legitimate transactions signed by 11 Verus nodes, attackers caused the Ethereum side to overwrite valid state roots with malicious ones during deserialization. This allowed forged checkpoints to be accepted as credible. Attackers then initiated a minimal 0.
01 VRSC cross-chain export using Bridge.vETH. When calling submitImports() on Ethereum, they constructed fake import proofs with matching hashtransfers fields while reusing data from prior legitimate transactions. CertiK highlighted logical flaws in the bridge contract, which failed to verify if import payment amounts matched actual exports on the Verus network. This validation gap enabled the fake proof to pass, resulting in a withdrawal far exceeding the transferred amount. Post-attack, stolen assets were converted to 2778.8662 ETH via Relay and moved to Tornado Cash.
Comments
No comments yet.