Verus-Ethereum Bridge Exploit Loots $11.6M as Thieves Convert Stolen Assets to ETH
TLDR
- The Verus-Ethereum bridge was exploited, resulting in the theft of approximately $11.6 million worth of crypto assets.
- PeckShield reported that the stolen assets included 103.6 tBTC, 1,625 ETH, and 147,000 USDC.
- The attacker subsequently exchanged these assets for around 5,402 ETH.
- Security experts suspect a flaw related to cross-chain message validation may be responsible for the breach.
- The Verus network temporarily suspended operations as developers worked to investigate the attack.
(SeaPRwire) – According to blockchain security firms monitoring the incident, the Verus-Ethereum bridge has been subject to an ongoing exploit that resulted in the loss of about $11.6 million in crypto assets.
Blockaid, a onchain security platform, detected the attack late Sunday and identified the attacker’s wallet as 0x5aBb…D5777. The firm noted that the stolen funds were transferred to another wallet labeled 0x65C…C25F9.
PeckShield reported that the bridge lost 103.6 tBTC, 1,625 ETH, and 147,000 USDC. The attacker later swapped these assets into approximately 5,402 ETH, which was valued between $11.4 million and $11.6 million at the time of reporting.
Attacker EOA: 0x5aBb91B9c01A5Ed3aE762d32B236595B459D5777
Drainer wallet (still holding the funds): 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9Exploit tx: https://t.co/OqBh2alXGc
Bridge contract: https://t.co/EN3LkDfId9— Blockaid (@blockaid_) May 18, 2026
In its Discord channel, the Verus team announced that the Verus network had halted following most block-generating nodes going offline due to the effects of the attack. Developers are currently investigating how the exploit occurred and determining what actions should be taken next.
Security Firms Point to Bridge Validation Flaw
Early analysis from various security firms suggested that the exploit may have stemmed from a vulnerability in cross-chain message validation rather than a traditional private key compromise.
GoPlus Security indicated that the attacker sent a low-value transaction to the bridge contract before invoking a function that led to reserve assets being transferred in bulk to the attacker’s wallet.
The firm believed the incident was likely linked to a failure in cross-chain message validation, a bypass in withdrawal logic, or a weakness in access control.
Blockaid provided a more detailed explanation later, stating that the issue appeared to involve a lack of source-amount validation within a bridge verification function. The firm clarified that the exploit did not involve an ECDSA bypass, notary key compromise, parser error, or hash-binding bug.
ExVul also stated that the attacker used a forged cross-chain import payload that successfully passed the bridge’s verification process. According to the firm, this triggered multiple transfers from the bridge’s reserves into a wallet under the attacker’s control.
Attacker Wallet Funded Through Tornado Cash
PeckShield revealed that the attacker’s wallet was initially funded with 1 ETH via Tornado Cash roughly 14 hours prior to the exploit. Tornado Cash is frequently associated with DeFi attack investigations because it can obscure the origin of funds used to initiate onchain activities.
At the time of the security alerts, all stolen funds had already been converted into ETH. Security researchers continued to monitor the wallet for any further movements.
Launched in October 2023, the Verus-Ethereum bridge enables users to transfer and convert assets between the Verus network and Ethereum. Verus itself was launched in 2018 and utilizes a hybrid proof-of-power model combining proof-of-work and proof-of-stake elements.
Described as privacy-focused, the protocol markets its bridge as a means to facilitate cross-chain liquidity between Verus and Ethereum-based assets.
This latest exploit has drawn attention because bridges typically hold reserve assets that back tokens or transactions across networks. A flaw in verification logic can allow attackers to withdraw assets from one side of a bridge without providing valid backing on the other side.
DeFi Bridge Security Faces Renewed Scrutiny
The Verus incident adds to a series of bridge and interoperability exploits reported across decentralized finance throughout 2026.
Earlier this year, security reports indicated that hackers stole over $168 million from dozens of DeFi protocols during the first quarter. April saw several larger-scale cases, including the reported $292 million Kelp DAO bridge exploit and a significant Drift Protocol breach.
Over the weekend, THORChain confirmed a separate exploit valued near $10 million, further highlighting concerns around cross-chain liquidity systems.
Bridge infrastructure remains one of the most closely watched sectors of the crypto market due to its role in linking assets across chains and managing large pools of liquidity. Security firms have recommended that protocols enhance payload validation, implement multi-layered verification, apply rate limits, and deploy emergency pause mechanisms for unusual withdrawal patterns.
The Verus team has not yet issued a comprehensive public post-mortem. Additional details are expected once developers complete their review of the exploit path and assess whether user funds can be recovered.
This article is provided by a third-party content provider. SeaPRwire (https://www.seaprwire.com/) makes no warranties or representations regarding its content.
Category: Top News, Daily News
SeaPRwire provides global press release distribution services for companies and organizations, covering more than 6,500 media outlets, 86,000 editors and journalists, and over 3.5 million end-user desktop and mobile apps. SeaPRwire supports multilingual press release distribution in English, Japanese, German, Korean, French, Russian, Indonesian, Malay, Vietnamese, Chinese, and more.