Skip to main content
AVOID.NET
Verus Protocol Ethereum Bridgereviewed 2026-09-07 · 26 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Verus Protocol Ethereum Bridge against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

1 claim

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #21[disputed][awaiting moderator]in section: Broader 2026 Bridge Exploit Context
    Notable co-occurring incidents included a $10 million THORChain exploit and a $76 million Echo Protocol exploit on the same day, May 18, 2026.
    reviewerNotable co-occurring incidents included a $10 million THORChain exploit and a $76 million Echo Protocol exploit on the same day, May 18, 2026.The Echo Protocol portion of the claim is accurate, but the THORChain exploit occurred on May 15, 2026 per CoinDesk and The Block, not 'the same day' as the May 18 Verus and Echo Protocol incidents.
    Proposed correction (not yet applied)
    Notable co-occurring incidents included a $10 million THORChain exploit on May 15, 2026, and a $76 million Echo Protocol exploit on the same day as the Verus incident, May 18, 2026.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #23[partially supported][awaiting moderator]in section: Broader 2026 Bridge Exploit Context
    Security researchers noted that while cross-chain bridge exploits dominated 2022 — six major incidents totaling $1.9 billion — attackers had subsequently shifted toward social engineering and supply-chain compromises before returning to infrastructure-layer attacks in 2026.
    reviewerCross-chain bridge exploits dominated 2022 — six major incidents totaling $1.9 billion.The $1.9B/six-incident figure for 2022 is confirmed by the cited source. The trailing clause about attackers 'shifting toward social engineering and supply-chain compromises' before 'returning to infrastructure-layer attacks in 2026' is a broader narrative claim not found verbatim in the cited source or independently verified; it reads as plausible industry framing rather than a sourced fact.

confirmed

23 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    On May 18, 2026, the bridge was exploited for approximately $11.58 million through a business-logic validation flaw that allowed an attacker to withdraw far more value on the Ethereum side than was deposited on the Verus side.
    reviewerThe Verus-Ethereum Bridge was exploited on May 18, 2026 for approximately $11.58 million via a business-logic validation flaw.Multiple independent, higher-credibility outlets (The Block, CoinDesk) confirm the date and dollar figure.
  2. #2[confirmed][no action needed]in the summary
    Following negotiations, the attacker returned approximately 75% of the stolen funds (4,052 ETH) in exchange for a 1,350 ETH bounty and an agreement to halt investigations.
    reviewerFollowing negotiations, the attacker returned approximately 75% of stolen funds (4,052 ETH) in exchange for a 1,350 ETH bounty and an agreement to halt investigations.Confirmed by multiple outlets describing the same negotiated 75/25 split and no-prosecution terms.
  3. #3[confirmed][no action needed]in section: Background
    Verus Protocol is a decentralized, open-source blockchain project launched in 2018 by Michael J. Toutonghi, a former Microsoft Technical Fellow and Vice President, along with a group of volunteer technology professionals.
    reviewerVerus Protocol was launched in 2018 by Michael J. Toutonghi, a former Microsoft Technical Fellow and Vice President.Secondary sources differ on exact chronology (Windows-95-era VP vs. later Technical Fellow stint), but the core assertion that he held both titles at Microsoft is corroborated by the cited source and independent bios.
  4. #4[confirmed][no action needed]in section: Background
    The project's native coin is VRSC, which employs a hybrid Proof-of-Work/Proof-of-Stake consensus algorithm called Proof of Power.
    reviewerVRSC uses a hybrid Proof-of-Work/Proof-of-Stake consensus algorithm called Proof of Power.Directly confirmed.
  5. #5[confirmed][no action needed]in section: Background
    Verus is built on foundations derived from Komodo and Zcash, and incorporates zero-knowledge Sapling technology.
    reviewerVerus is built on foundations derived from Komodo and Zcash, incorporating zero-knowledge Sapling technology.Confirmed by independent Komodo-ecosystem documentation, not just the cited page.
  6. #6[confirmed][no action needed]in section: Background
    The bridge relies on a notary system in which 8 of 15 designated notaries must sign a state root for a cross-chain transfer to be accepted as valid.
    reviewerThe bridge relies on a notary system in which 8 of 15 designated notaries must sign a state root for a cross-chain transfer to be valid.Confirmed, and consistent with post-exploit reporting that the notary layer functioned correctly (8-of-15 valid signatures were obtained on the forged blob).
  7. #7[confirmed][no action needed]in section: May 2026 Exploit — Overview
    The stolen assets comprised 103.6 tBTC (Threshold Network's tokenized Bitcoin), 1,625 ETH, and approximately 147,000 USDC.
    reviewerThe stolen assets comprised 103.6 tBTC, 1,625 ETH, and approximately 147,000 USDC.Confirmed by identical figures across CoinDesk, The Block, and Merkle Science.
  8. #8[confirmed][no action needed]in section: May 2026 Exploit — Overview
    Blockaid first detected suspicious activity at approximately 00:54 GMT involving the Verus-Ethereum Bridge contract and flagged the exploit as ongoing.
    reviewerBlockaid first detected suspicious activity at approximately 00:54 GMT and flagged the exploit as ongoing.Confirmed via independent corroboration of the 00:54 GMT timestamp.
  9. #9[confirmed][no action needed]in section: May 2026 Exploit — Overview
    PeckShield independently confirmed the theft and tracked the consolidation of all stolen assets into 5,402.4 ETH held in attacker wallet 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9.
    reviewerPeckShield tracked the consolidation of stolen assets into 5,402.4 ETH held in wallet 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9.Wallet address and ETH total confirmed by two independent security firms as reported across outlets.
  10. #10[confirmed][no action needed]in section: May 2026 Exploit — Overview
    The attacker's wallet had been funded with 1 ETH via Tornado Cash approximately 14 hours before the exploit was executed, and the attacker spent only approximately $10 in VRSC transaction fees to drain the entire bridge reserve.
    reviewerThe attacker's wallet was funded with 1 ETH via Tornado Cash approximately 14 hours before the exploit, and spent only approximately $10 in VRSC fees to drain the bridge.Both the Tornado Cash pre-funding timing and the ~$10 fee figure are corroborated outside the cited source.
  11. #11[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
    The Ethereum bridge's submitImports() function then released 103.6 tBTC, 1,625 ETH, and 147,000 USDC from reserves against the fraudulent proof, as the checkCCEValues validation step lacked a check confirming input and output amounts were equal.
    reviewerNeither side of the bridge validated that the Verus-side input amount matched the Ethereum-side payout; submitImports()/checkCCEValues lacked this check.Technical description matches independent security-researcher accounts of the exploit mechanism.
  12. #12[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
    The attacker constructed a cross-chain export containing only approximately $0.01 (roughly 0.02 VRSC) in source-side input.
    reviewerThe attacker constructed a cross-chain export containing only approximately $0.01 (roughly 0.02 VRSC) in source-side input.Confirmed.
  13. #13[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
    Blockaid described the vulnerability as belonging to the same class as the 2022 Wormhole ($320 million) and Nomad ($190 million) bridge exploits, both of which also involved gaps between source-chain proof verification and destination-chain value binding.
    reviewerBlockaid described the vulnerability as belonging to the same class as the 2022 Wormhole ($320 million) and Nomad ($190 million) bridge exploits.Both historical dollar figures and the vulnerability-class comparison are accurate.
  14. #14[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
    Blockaid estimated the fix required only approximately 10 lines of Solidity code.
    reviewerBlockaid estimated the fix required only approximately 10 lines of Solidity code.Confirmed by a source independent of Halborn.
  15. #15[confirmed][no action needed]in section: Network Shutdown and Immediate Response
    Approximately 12 hours after the initial exploit, the Verus blockchain halted block production. The Verus core team stated via the project's Discord channel that most block-generating nodes had taken themselves offline in response to byproducts of the attack.
    reviewerApproximately 12 hours after the exploit, the Verus blockchain halted block production as most block-generating nodes took themselves offline, per a Discord statement.One cited source (PulseChain Nexus) misdates the underlying exploit itself as May 17 rather than May 18, but the network-halt claim it supports is corroborated elsewhere and is not itself in dispute.
  16. #16[confirmed][no action needed]in section: Network Shutdown and Immediate Response
    Two days before the exploit, on approximately May 16, 2026, Verus had released what it described as an "urgent and mandatory" emergency update, version 1.2.14-2, referencing a vulnerability fix.
    reviewerTwo days before the exploit, on approximately May 16, 2026, Verus released an 'urgent and mandatory' emergency update, version 1.2.14-2.Confirmed.
  17. #17[confirmed][no action needed]in section: Network Shutdown and Immediate Response
    As of reporting, the relationship between the patched vulnerability in that update and the exploited validation gap has not been publicly clarified by the Verus team. No public post-mortem from the Verus development team has been identified in available sources.
    reviewerThe relationship between the May 16 patch and the exploited validation gap has not been publicly clarified, and no public post-mortem has been identified.Accurate as an as-of-reporting statement about the May incident. However, a July 23, 2026 repeat exploit of the same bridge (same contract path, same bug class, ~$7.54M) that Verus also did not publicly explain is not mentioned anywhere on the page; see coverage_gaps.
  18. #18[confirmed][no action needed]in section: Fund Recovery and Bounty Negotiation
    Verus offered the attacker a bounty of 1,350 ETH (approximately $2.8 million) in exchange for returning the remaining 4,052 ETH (approximately $8.5 million) within 24 hours.
    reviewerVerus offered the attacker a 1,350 ETH bounty (~$2.8M) in exchange for returning the remaining 4,052 ETH (~$8.5M) within 24 hours, and agreed to halt investigations.Confirmed across multiple outlets with consistent figures.
  19. #19[confirmed][no action needed]in section: Fund Recovery and Bounty Negotiation
    On May 22, 2026, the exploiter returned 4,052.4 ETH to a Verus team wallet (0xF9AB...C1A74), representing approximately 75% of the total stolen value.
    reviewerOn May 22, 2026, the exploiter returned 4,052.4 ETH to Verus team wallet 0xF9AB...C1A74, representing approximately 75% of stolen value.Confirmed.
  20. #20[confirmed][no action needed]in section: Broader 2026 Bridge Exploit Context
    PeckShield reported that eight major bridge-related exploits through mid-May 2026 resulted in cumulative losses of approximately $328.6 million. The Verus incident pushed the year-to-date total past $329 million.
    reviewerPeckShield reported that eight major bridge-related exploits through mid-May 2026 resulted in cumulative losses of approximately $328.6 million, pushing the 2026 total past $329 million.Figures and count match the cited source closely.
  21. #22[confirmed][no action needed]in section: Broader 2026 Bridge Exploit Context
    A single April 2026 incident involving rsETH accounted for approximately $290 million of the 2026 total.
    reviewerA single April 2026 incident involving rsETH accounted for approximately $290 million of the 2026 total.Confirmed directly by the cited source.
  22. #24[confirmed][no action needed]in section: Audit History and Security Posture
    No evidence of a prior third-party security audit of the Verus-Ethereum Bridge has been identified in available sources.
    reviewerNo evidence of a prior third-party security audit of the Verus-Ethereum Bridge has been identified in available sources.This is an appropriately hedged negative claim ('no evidence... has been identified') and is consistent with everything found in this review.
  23. #25[confirmed][no action needed]in section: Audit History and Security Posture
    Halborn's post-exploit analysis characterized the incident as a business-logic failure rather than a cryptographic vulnerability, noting that the code executed as designed but that the design itself was flawed.
    reviewerHalborn's post-exploit analysis characterized the incident as a business-logic failure rather than a cryptographic vulnerability.Confirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.