web3 / news / / Crypto News
An attacker has siphon off more than $11.5 million in crypto assets through a forged cross-chain transfer message.
The Verus-Ethereum bridge exploit was due to missing source-amount validation in checkCCEValues.
KEY POINTS
- Attackers used a forged cross-chain import payload that bypassed the bridge’s verification process.
- The flaw could reportedly be fixed with about 10 lines of Solidity code.
- Attack methods resembled the 2022 Nomad and Wormhole bridge exploits involving fraudulent transfer instructions.
- The attacker initially funded their wallet via Tornado Cash shortly before the exploit.
COMPANIES
Summarized by Newsio from Crypto News. How we summarize →