T
iTokenly

Verus-Ethereum Bridge hack — May 2026

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedMay 18, 2026
Target typeCross-chain bridge
Loss$11,580,000Published estimates range $11,000,000 to $11,580,000Price at time of incident
Recovered$8,500,000
MethodContract logic errorThe Ethereum-side import path verified notarised state roots and notary signatures but never required transfer inputs to balance outputs, so a near-worthless forged transfer blob authorised an eight-figure payout
ChainsEthereum, Other
OutcomeSettled as bug bounty

What happened

The Verus-Ethereum bridge, a non-custodial bridge between the Verus chain and Ethereum, was drained of about $11.58 million in May 2026. PeckShield flagged the transactions. The assets taken were 103.6 tBTC, 1,625 ETH and 147,000 USDC, which the attacker consolidated into roughly 5,402.4 ETH.

The bridge verified notarised state roots from the Verus side, including cryptographically valid signatures from 8 of 15 notaries, but did not bind that proof to the value being released. Halborn's analysis places the gap in the Ethereum-side submitImports path, where the checkCCEValues logic never required inputs and outputs to balance, so a transfer blob backed by a fraction of a cent of VRSC could authorise the full payout. Researchers quoted by Cryptopolitan described the same failure as a forged Merkle proof that passed verification of the bridge's non-open-source contract. Cryptopolitan also noted that Verus had shipped an 'urgent and mandatory' emergency update, version 1.2.14-2, two days before the exploit.

Verus responded with a public bounty offer: return 4,052.4 ETH to a team address within 24 hours, keep 1,350 ETH, and the team would stop investigating. The exploiter accepted. On 22 May 2026 about 4,052 ETH — roughly $8.5 million, or 75 per cent of the take — was returned, and the attacker retained around $2.8 million.

Figures differ across outlets: CoinDesk headlined $11 million, Cryptopolitan $11.5 million, and Halborn $11.58 million. Dating also differs, with CoinDesk and Cryptopolitan placing the exploit on Monday 18 May and CryptoPotato on 17 May.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01
  4. CryptopolitanSecondary · retrieved 2026-08-01
  5. CryptoPotatoSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Verus-Ethereum Bridge hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/verus-ethereum-bridge
https://itokenly.com/hacks/verus-ethereum-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.