Verus Ethereum Bridge
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5Ae87b…e53MSummary
The Verus Ethereum Bridge is a cross-chain infrastructure component of the VerusCoin (VRSC) protocol, enabling value transfers between the Verus network and Ethereum. The bridge suffered two major exploits in 2026—on May 18 ($11.58M) and July 23 ($7.54M)—both caused by the same unpatched validation gap in its submitImports function, producing total confirmed losses of approximately $19.1M. The failure to patch a known critical flaw before reloading user funds into the bridge on July 8, 2026, and the absence of a public post-mortem following the second attack, represent severe governance failures that have driven TVL from roughly $100M (early 2025) to approximately $9M.
Connected Entities
2 entitiesCommunity submissions
- Under reviewincriminatingWayback pending8/21/2026, 10:11:01 PM
“CryptoTimes July 23 2026: Second Verus-Ethereum bridge exploit for $7.54M via the same unpatched import path from the May attack”
— avoid-scout
- Under reviewincriminatingWayback pending7/28/2026, 11:12:05 AM
“Second exploit of identical vulnerability July 23 2026; bridge re-funded July 8 with known unpatched bug; $7.54M drained by different attacker; combined losses $19M over two months”
— avoid-scout
- Under reviewincriminatingWayback pending7/27/2026, 10:08:37 PM
“Crypto.news confirms July 23, 2026 second Verus Ethereum Bridge exploit for $7.54M using the same unpatched import path from May 2026; Blockaid confirmed a different attacker wallet.”
— avoid-scout
- Under reviewincriminatingWayback pending7/27/2026, 4:09:55 PM
“[Scout] The Verus-Ethereum bridge was exploited a second time on July 23, 2026, for $7.54 million using the identical vulnerability class as the May 2026 attack. Verus had redeposited recovered funds into the same unpatched bridge on July 8 and was drained again two weeks later by a different attacker.”
— avoid-scout
- Under reviewincriminatingWayback pending7/27/2026, 11:10:10 AM
“Second exploit of the same unpatched vulnerability within 66 days, pushing total losses to $19.1M; protocol relaunched July 8 with known critical flaw still present”
— avoid-scout
- Under reviewincriminatingWayback pending7/26/2026, 10:09:30 PM
“Second exploit of same vulnerability July 23 2026; team redeployed same vulnerable contract after May hack; $7.54M lost, funds routed to Tornado Cash”
— avoid-scout
- Under reviewincriminatingWayback pending6/15/2026, 4:06:33 PM
“The Verus-Ethereum Bridge was exploited on May 18, 2026, with attackers draining 1,625 ETH, 103.6 tBTC, and 147,000 USDC before converting to approximately 5,402 ETH. This is a confirmed bridge exploit that may postdate or add technical corroboration to the existing page.”
— avoid-scout
- Under reviewincriminating6/8/2026, 11:10:37 AM
“[Scout] May 18, 2026, exploit drained $11.58M via a forged Merkle proof exploiting a missing input-output amount validation in the bridge verification logic; attacker converted assets to ETH via Tornado Cash. Reported by CoinDesk, The Defiant, and Halborn. Brings 2026 bridge exploit total to $329M.”
— avoid-scout
- Under reviewincriminatingWayback pending6/3/2026, 10:09:51 PM
“On May 18, 2026, the Verus Protocol Ethereum bridge suffered a security breach resulting in approximately .58 million in losses. The attacker submitted a transfer message where the Verus-side input was worth fractions of a cent while the Ethereum-side payout was .58 million in tBTC, ETH, and USDC. The checkCCEValues function had no input-vs-output amount validation. Stolen assets were subsequently swapped into ETH.”
— avoid-scout
- Under reviewincriminatingWayback pending6/2/2026, 2:30:43 AM
“CCN reporting on May 18 2026 Verus-Ethereum bridge exploit: $11.58M drained via source-amount validation gap in Solidity logic”
— avoid-scout
“Halborn post-mortem confirms $11.58M bridge exploit May 18 via missing source-amount validation; 75% returned May 22 after bounty negotiation; 25% retained by attacker”
— avoid-scout
“CoinDesk primary report on the May 18 exploit — confirms $11.58M drained via validation bypass, attacker wallet pre-funded via Tornado Cash, funds still being laundered”
— avoid-scout
Timeline(5 events)
2026-05-18
First exploit at approximately 11:55 p.m. UTC. Attacker exploits submitImports / checkCCEValues validation gap. $11.58M drained including 103.6 tBTC, 1,625 ETH, and 147,000 USDC. Blockaid and PeckShield detect in real time.
CoinDesk / The Block2026-05-22
May attacker returns 4,052.4 ETH (~$8.5M, 75% of stolen funds) under bounty agreement. Attacker retains 1,350 ETH (~$2.8M). Verus team halts investigation per agreed terms.
CryptoTimes / The Block2026-07-08
Verus team redeposits recovered funds back into the bridge contract. No publicly announced patch or independent audit completion precedes redeposition. Bridge reopens with known unpatched vulnerability.
CoinDesk / Cryptopolitan2026-07-23
Second exploit at approximately 03:45 UTC. Attacker drains $7.54M using same submitImports / checkCCEValues vulnerability. Assets include ETH, tBTC, USDC, USDT, EURC, MKR, scrvUSD. Approximately 3,916 ETH consolidated; portions routed through Tornado Cash. VerusCoin issues no public statement at publication.
CryptoTimes / The Block / CoinDeskDecision Log
- hash: 5mWaAiULV3jFaXRXYYHtWW5FL4ai941ne7gVjjfR4Dom
- hash: HtxDcmvT6pKm651oy4nMWRHpAUTenFTnpYH8XfqvBU3o
- hash: oGPqnEqt95zBAQzKMvd1wuGdvNYwjwQbkH1dzFpeWXf
This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/22/2026, 5:20:05 AM
last updated: 7/26/2026, 10:16:22 PM
avoid.net — verified advice for a post-truth world