Verus bridge exploited for $7.44M using duplicate state roots to overwrite Ethereum checkpoint.
Security & Exploits ·
An attacker drained $7.44 million from the Verus bridge by exploiting duplicate state roots to overwrite an Ethereum checkpoint, according to security analysis. The exploit targeted a flaw in how the bridge validated cross-chain transactions, allowing the attacker to manipulate the checkpoint mechanism that normally ensures transaction integrity between blockchains.
Bridges function as connective infrastructure between isolated blockchain networks, enabling assets and data to move across chains and power cross-chain DeFi activity. However, they operate at a critical intersection where the complexity of coordinating multiple chains creates security vulnerabilities; the mechanisms that lock, unlock, mint, or burn tokens based on events on other chains are frequent targets for exploitation.
The Verus incident underscores ongoing risks in bridge design and validation logic. Details remain limited on whether the vulnerability has been patched, what safeguards failed to detect the attack, or whether other bridges share similar weaknesses. The broader question of how to achieve safer, proof-based interoperability across fragmented blockchain ecosystems remains an open challenge for the industry.