According to ME News, on July 31 (UTC+8), CertiK released an analysis of the July 23 attack on the Verus protocol’s Ethereum cross-chain bridge. The analysis revealed that the root cause of the attack was a discrepancy in how Verus and Ethereum interpret notarization data. The attacker inserted multiple malicious duplicate state root entries into a legitimate notarization transaction; these entries were normally signed by 11 Verus notary nodes and relayed to Ethereum. Since the Verus side reads serialized state root data and inserts it into a mapping table, while the Ethereum side iterates sequentially through all proofRoots entries during deserialization and overwrites the state root for every entry matching the system ID, the malicious state root entries submitted later overwrote the initially legitimate state root. As a result, the attacker-controlled state root was ultimately accepted by Ethereum as a trusted checkpoint. Building on this, the attacker initiated an extremely small cross-chain export request of just 0.01 VRSC via Bridge.vETH on the Verus chain. Subsequently, when calling the submitImports() function on the Ethereum side, the attacker forged critical fields in the import proof—such as hashtransfers (transfer hashes)—to match the hash of the actually transferred assets, while reusing portions of data from prior legitimate transactions to construct the remaining proof fields. CertiK noted that the Verus-Ethereum cross-chain bridge contract contained a logical vulnerability: it failed to verify whether the specified payment amount in the import request matched the actual exported amount on the Verus network. This allowed the forged proof to pass validation, ultimately authorizing a withdrawal far exceeding the actual amount transferred. After successfully executing the attack, the attacker used Relay to exchange the stolen assets for 2,778.8662 ETH and transferred them to Tornado Cash. (Source: Foresight News)
CertiK Analyzes the Verus Cross-Chain Bridge Attack: Exploited Semantic Differences in State Roots
KuCoinFlashShare
On July 31, CertiK released an on-chain analysis of the July 23 Verus cross-chain bridge attack, revealing how attackers exploited semantic differences in state roots. The attackers inserted malicious duplicate entries into a legitimate notarization transaction, which were signed by 11 Verus notary nodes and transmitted to Ethereum. A deserialization discrepancy allowed the malicious roots to overwrite valid ones, enabling a fraudulent import proof and the withdrawal of 2,778.8662 ETH. The on-chain data demonstrates how subtle protocol differences can be weaponized in cross-chain attacks.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.