An attacker drained roughly $11.58 million from the Verus-Ethereum bridge on May 18, 2026, exploiting a validation flaw that let the contract release wrapped assets on Ethereum without confirming matching collateral on the Verus chain. Blockaid flagged the suspicious activity at 00:54 GMT, after which the attacker pulled 1,625 ETH, 147,659 USDC, and 103.57 tBTC v2, then swapped the haul into 5,402 ETH worth more than $11.4 million at the time. The wallet had been funded with 1 ETH routed through Tornado Cash about 14 hours earlier, according to CoinDesk and Bitcoin.com News citing PeckShield on-chain data.
A cross-chain bridge is a smart-contract system that locks an asset on one blockchain and mints a wrapped version of it on another so funds can move between networks. The Verus design relies on validators attesting that a deposit happened on Verus before its bridge contract releases assets on Ethereum, and that attestation check is what failed.
Key Takeaways
- The Verus-Ethereum bridge lost approximately $11.58 million on May 18, 2026, after an attacker exploited a flaw in the bridge’s deposit-verification logic.
- Drained assets included 1,625 ETH, 147,659 USDC, and 103.57 tBTC v2, converted within minutes to 5,402 ETH to consolidate value before any freeze action.
- The attacker’s wallet was funded through Tornado Cash about 14 hours pre-attack, a pattern consistent with planned bridge exploits.
- 2026 bridge losses now exceed $328.6 million across eight major incidents, with PeckShield tracking bridges as the largest single attack surface in DeFi.
Published: May 21, 2026 14:00 UTC
How the Verus bridge was drained
The exploit took advantage of a missing or insufficient verification step in the bridge’s release function. The attacker triggered a withdrawal on the Ethereum side without a corresponding locked deposit on Verus, and the contract paid out anyway. Blockaid’s monitoring picked up the anomaly at 00:54 GMT and broadcast a public alert within minutes, but the attacker had already moved most of the funds by the time the alert circulated, according to CCN.
On-chain tracker PeckShield linked the attacker wallet (0x5aBb91B9c01A5Ed3aE762d32B236595B459D5777) to a 1 ETH deposit funded via Tornado Cash, a mixing protocol used to obscure transaction origins. The funding pattern, in which a small amount is staged through a mixer hours before a much larger drain, has appeared in several other 2026 bridge exploits and suggests the attack was prepared rather than opportunistic.
Drained tokens were swapped into ETH within roughly the same block window. Consolidating into a single asset before any team or exchange can blacklist the wallet is standard playbook for bridge attackers, since wrapped tokens like tBTC v2 can sometimes be paused or rolled back at the issuer level.
Why bridges keep failing in 2026
The Verus incident is the eighth major bridge-related attack of 2026, and the running total across those incidents is now $328.6 million, per PANews citing PeckShield data. Bridge exploits accounted for more than 68% of DeFi losses in Q1, and April 2026 became crypto’s most-hacked month on record with roughly 30 incidents.
The structural reason is concentration. A bridge typically holds the full collateral backing of every wrapped asset it issues, which means one validation bug or one compromised signer set can release the entire pool. KelpDAO lost about $292 million through its LayerZero-powered bridge on April 18, and Drift Protocol’s Solana infrastructure was drained for more than $200 million earlier this year. The Verus loss is small by comparison but follows the same template: cross-chain logic plus a verification gap equals total drain.
Impact on Verus users and the wider market
At time of publication the Verus development team had not posted a formal incident response or detailed reimbursement plan. The bridge contract on Ethereum was still active in the hours immediately after the exploit, raising the risk of additional draws if the underlying flaw was not patched. Bridges that pause quickly tend to limit follow-on losses, so the delay is a credibility issue for the project regardless of how the recovery effort proceeds.
Holders of bridged Verus assets on Ethereum face a familiar problem. Wrapped tokens depend on a 1:1 backing assumption, and when collateral on the source chain is missing, the wrapped token can trade well below par on secondary markets. Liquidity providers in pools containing bridged Verus assets are the most exposed.
Broader market impact has been limited because the dollar amount is modest by 2026 standards, but the steady drumbeat of bridge failures is shifting how serious DeFi capital treats cross-chain routes. Several large protocols have moved toward intent-based bridging or canonical L2 messaging in part because the trusted-validator model keeps producing eight-figure losses.
What comes next
The immediate questions are whether Verus will pause the bridge contract, whether the team can recover any portion of the funds through negotiation with the attacker, and whether validators or insurers will cover losses for affected users. Bridges that have offered post-exploit bug bounties this year, such as IoTeX, have recovered partial amounts. Fully on-chain bridges with no team multisig generally have not.
Regulators are also watching. The CFTC and SEC have both signaled greater interest in cross-chain infrastructure as part of the broader market structure debate around the CLARITY Act, and a string of nine-figure bridge losses gives lawmakers a concrete reason to push validator and disclosure standards. Expect more pressure on bridge teams to publish audits, validator identities, and incident-response procedures before the next major exploit.
Frequently asked questions
How much was stolen from the Verus-Ethereum bridge?
The attacker drained approximately $11.58 million on May 18, 2026, made up of 1,625 ETH, 147,659 USDC, and 103.57 tBTC v2. The stolen tokens were swapped into 5,402 ETH within minutes, valued at more than $11.4 million at the time of the conversion, according to on-chain trackers Blockaid and PeckShield.
How did the attacker exploit the Verus bridge?
The bridge contract released wrapped assets on Ethereum without correctly verifying that matching collateral had been locked on the Verus chain. By calling the withdrawal function under conditions the contract’s logic failed to reject, the attacker pulled funds that had no backing deposit. Tornado Cash was used to fund the attacker wallet about 14 hours before the exploit.
How much has been stolen from cross-chain bridges in 2026?
Cross-chain bridges have lost approximately $328.6 million across eight major incidents through mid-May 2026, according to PeckShield. Bridge exploits accounted for more than 68% of all DeFi losses in the first quarter, with KelpDAO’s $292 million loss in April standing as the largest single bridge incident of the year.








