🚨 SlowMist TI Alert 🚨
💸
@VerusCoin Loss: ~$7.5M
⚠️ Unlike the prior 0x6990…b321 exploit, which decoupled the validated proof from the executed transfer payload, this attack hash-bound the transfers to the CCE but failed to validate the CCE’s economic backing; both exploit flawed cross-chain import validation.
🔍 Root Cause: `VerusProof.checkExportAndTransfers` verified selected CCE fields—including `hashReserveTransfers` against attacker-supplied serialized transfers and the source/destination IDs—but did not enforce the CCE’s accounting semantics. It failed to parse or validate `totalamounts`, `totalfees`, `totalburned`, CTxOut `nValue`, or whether the prior CCE outpoint carried sufficient value and assets to cover the claimed transfers. As a result, a matching transfer hash was incorrectly treated as authorization to release bridge assets, rather than merely a commitment to the requested transfers.
📌 Attacker EOA: 0xbda71b58cec0b1c20a8f87ccd52fa0679747855c
📌 Victim Bridge: 0x71518580f36feceffe0721f06ba4703218cd7f63
📌 Vulnerable Contract: 0x54e03a1682fd0bb065b669f6296f97028dcfd4ce
📌 Fund Receiver: 0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54
Impact: The attacker submitted a successor CCE anchored to an accepted Verus state root, containing a hash commitment to eight attacker-defined reserve transfers. Because the bridge did not verify whether the CCE’s economic fields backed those transfers, it executed eight payouts from bridge custody to the attacker-controlled receiver—releasing ETH, DAI, USDC, USDT, and four additional tokens without enforced cross-chain asset backing.
Powered by
Tx: