# Verus-Ethereum Bridge loses $11.5 million in active exploit

**Published:** 2026-05-18T02:04:10.000Z  
**Topic:** Ethereum  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/b53aaa10-010a-499d-9ccb-a3b316b8e3ff

Verus bridge hack drains $11.5 M via forged cross‑chain message; attacker moves 1,625 ETH, 103.6 tBTC and 147k USDC, raising fresh DeFi security concerns.

The Verus‑Ethereum bridge has been drained of roughly $11.5 million after an attacker exploited a validation flaw in the bridge’s verification process on May 18, 2026 [2]. Security firm Blockaid flagged the breach in real time, identifying the malicious wallet 0x5aBb…D5777 and a downstream holding address 0x65Cb…C25F9 where the stolen assets were consolidated [2].

The exploit hinged on a forged cross‑chain transfer message that bypassed the bridge’s source‑amount checks. By sending a low‑cost transaction on Verus—about $10 in fees—the attacker created a payout hash without any corresponding value on the Verus side, then submitted matching data to the Ethereum contract, which released the funds [3]. Blockaid, PeckShield and ExVul all traced the flaw to a missing validation step in the Solidity code, a bug that could be patched with roughly ten lines of code [2][3].

On‑chain data show the drained assets included 1,625 ETH, 103.6 tBTC and nearly 147,000 USDC, which the attacker quickly swapped into 5,402 ETH, valued at about $11.4 million at current prices [2]. The attacker’s wallet had previously received 1 ETH from the Tornado Cash mixer, a pattern often seen in attempts to obscure transaction origins [2]. As of the latest reports, the funds remain untouched in the drainer wallet, and the Verus team has not issued a public response [1][3].

This breach adds to a string of high‑profile bridge attacks in 2026, including a $10 million exploit on THORChain and multi‑hundred‑million losses on Drift and Kelp protocols earlier in the year [2]. The incident underscores that even well‑audited cross‑chain infrastructure can harbor subtle economic gaps, prompting renewed calls for stricter payload validation, layered verification and emergency pause mechanisms [3].

The open question now is whether Verus will pause the bridge, roll out the quick code fix, and how quickly the community can restore confidence in a sector where each new exploit erodes trust in decentralized finance’s interoperability promises.

## Sources
1. Crypto Briefing — [Verus-Ethereum Bridge sees $11.4M in abnormal asset outflows](https://cryptobriefing.com/verus-ethereum-bridge-abnormal-outflow/)
2. Crypto — [Verus Ethereum bridge drained of $11.5M in forged transfer exploit](https://crypto.news/verus-ethereum-bridge-drained-of-11-5m-in-forged-transfer-exploit/)
3. Crowdfund Insider — [DeFi Protocol Verus Hit by Major Security Breach on Ethereum Bridge](https://www.crowdfundinsider.com/2026/05/280076-defi-protocol-verus-hit-by-major-security-breach-on-ethereum-bridge/)
4. Ambcrypto — [Verus-Ethereum bridge hack drains $11.58M - Why DeFi trust is eroding - AMBCrypto](https://ambcrypto.com/verus-ethereum-bridge-hack-drains-11-58m-why-defi-trust-is-eroding/)

---
Cite as: TrendWatcher, "Verus-Ethereum Bridge loses $11.5 million in active exploit", https://www.trendwatcher.in/article/b53aaa10-010a-499d-9ccb-a3b316b8e3ff
