PublicAML
← All reports

Contract exploit report VR-56B95658

Investigator report

Filed by a vetted PublicAML investigator rather than by an anonymous reader. The account itself has not been independently re-checked.

The addresses below carry a risk label from this report.

Type
Hack
Reported as
Contract exploit
Chain
ethereum
Reported by
DenysInvestigator
Incident date
Jul 23, 2026
Published
Sep 9, 2026

What happened

Verus Ethereum Bridge exploit, 23 July 2026, ~$7.53M drained. Reported by CertiK Alert; PublicAML recovered the full addresses from their screenshot and verified everything on-chain. Root cause per CertiK: the "hashOfTransfers" value calculated from "serializedTransfers" decoded to draining transfers, letting the caller push forged imports through the bridge. 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c β€” the caller. Verified on-chain: submitImports on the Verus bridge contract 0x71518580f36FeCEFfE0721F06bA4703218cD7F63 in block 25592836 at 03:45:59 UTC on 23 July 2026, transaction 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099. The same address had called setLatestData twice in the minutes before. 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 β€” the recipient of the drained assets. All seven ERC-20 transfers in that transaction went here: 71.5 tBTC ($4.69M), 220,357 DAI, 149,275 USDC, 78,300 USDT, 92,784 scrvUSD, 31,475 EURC and 59.43 MKR, plus 1,137.45 ETH ($2.19M) as an internal transfer. Our enrich already flagged it as mixer-interaction before this report. Both are externally owned accounts, not contracts. The bridge contract itself is the victim and is not reported here. Source: https://x.com/CertiKAlert/status/2080153763332174170. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.

Addresses named in this report

Named here and believe it is wrong? Open the address page above and use the flag on the assessment. Every dispute is read.

Contract exploit report VR-56B95658 | PublicAML