Incident overview
This record updates the Verus–Ethereum bridge attack that occurred on July 23, 2026; it is not a second incident. Initial reporting emphasized cross-chain import, economic-backing, and proof-validation logic. BlockSec’s later analysis found that the submitted source-chain transaction did not exist on Verus, while the malicious confirmedStateRoot carried valid signatures from 11 of 15 configured notaries and met quorum.
Root-cause update
checkProof/checkBranch did not enforce a minimum nSize, and the contract did not validate branchType. The malicious proof contained only three proof segments with a minimum nSize of 2, while a comparison legitimate proof traversed 17 Merkle layers. These validation weaknesses were insufficient by themselves to make a malicious proof match an honest StateRoot. Compromised or maliciously used notary keys are therefore the stronger current explanation, but this remains a security-research conclusion rather than a final project forensic report.
Incident sequence
- The attack-execution EOA called setLatestData() more than once to install and advance a StateRoot matching the malicious proof.
- The bridge accepted the malicious StateRoot authorized by 11 of 15 configured notaries.
- The extraction transaction released ETH, tBTC, USDC, USDT, EURC, MKR, scrvUSD, and other assets from bridge reserves.
- Assets reached 0xCFd0…2D54 and were converted into approximately 3,916.1 ETH.
- Existing chain review shows that the ETH entered the Tornado Cash Router through 47 transactions, mostly 100 ETH batches; the conversion and mixer deposits occurred before this report’s 18:00 start time.
Fund flow
Affected Ethereum bridge contract 0x715185…7f63 → attack-execution EOA and recipient 0xCFd0…2D54 → conversion into approximately 3,916.1 ETH → Tornado Cash Router 0xd90e…f31b. Public traceability becomes more difficult after mixer entry; the Router is infrastructure, not an attacker address.
Amount basis
The database retains an approximately $7.54 million midpoint for the original multi-asset loss, within public estimates of roughly $7.53 million to $7.60 million. The assets were converted into approximately 3,916.1 ETH. The asset valuation and converted ETH describe the same loss and are not added together. This root-cause update creates no new July 24 loss.
Addresses and transactions
Attack-execution EOA: `0xbda71b58cec0b1c20a8f87ccd52fa0679747855c`.
Affected bridge contract: `0x71518580f36feceffe0721f06ba4703218cd7f63`.
Stolen-asset recipient: `0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54`.
First malicious StateRoot-setting transaction: `0x8f21bd8f0fce72ac959caa93a9923d85f902dfc6eddac2785ac5bc49c3b28d8f`.
Second setLatestData transaction: `0x51b1c8341da4092b7d1e0e4865f7b318de4e96245358b05b2bff2df50adaf0c9`.
Attack and asset-extraction transaction: `0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099`.
Evidence boundary
The notary-key compromise or malicious-use explanation is BlockSec’s technical conclusion from signatures, StateRoots, and proof structure, not a final Verus forensic report. The truncated Verus source-chain transaction identifier remains a lead and is not entered into the formal ledger. The proof weaknesses are not described as independently bypassing an honest StateRoot, and the Tornado Cash Router is not labeled as an attacker.
Current status
The original attack was completed and approximately 3,916.1 ETH entered Tornado Cash. No freeze, return, recovery, real-world attacker identity, or completed compensation has been confirmed, and no final project postmortem has closed all technical questions. recoveredUsd remains 0.