Fact-check findings
What an automated fact-checker found when it re-read Verus Protocol Ethereum Bridge against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
1 claimThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #21[disputed][awaiting moderator]in section: Broader 2026 Bridge Exploit Context
“Notable co-occurring incidents included a $10 million THORChain exploit and a $76 million Echo Protocol exploit on the same day, May 18, 2026.”
reviewerNotable co-occurring incidents included a $10 million THORChain exploit and a $76 million Echo Protocol exploit on the same day, May 18, 2026.The Echo Protocol portion of the claim is accurate, but the THORChain exploit occurred on May 15, 2026 per CoinDesk and The Block, not 'the same day' as the May 18 Verus and Echo Protocol incidents.Proposed correction (not yet applied)Notable co-occurring incidents included a $10 million THORChain exploit on May 15, 2026, and a $76 million Echo Protocol exploit on the same day as the Verus incident, May 18, 2026.
link rot
1 claimA cited source no longer resolves or no longer says what the page attributes to it.
- #26[link rot][awaiting moderator]in the cited sources
“https://web.archive.org/web/20260726082916/https://coincentral.com/rocket-lab-rklb-stock-rises-as-u-s-space-force-hands-it-a-90m-satellite-mission/”
reviewerThe CoinCentral article 'Verus Recovers 4,052 ETH as Bridge Hacker Keeps $2.8M Bounty' is preserved at its listed archive_url.The live URL for this CoinCentral source is reachable (HTTP 200) and does support the page's claims about the bounty deal; the defect is isolated to the archive_url field, which points to a completely different, unrelated article.Proposed correction (not yet applied)http://web.archive.org/web/20260726082913/https://coincentral.com/verus-recovers-4052-eth-as-bridge-hacker-keeps-2-8m-bounty/
partially supported
1 claimThe cited evidence supports part of the claim but not all of it.
- #23[partially supported][awaiting moderator]in section: Broader 2026 Bridge Exploit Context
“Security researchers noted that while cross-chain bridge exploits dominated 2022 — six major incidents totaling $1.9 billion — attackers had subsequently shifted toward social engineering and supply-chain compromises before returning to infrastructure-layer attacks in 2026.”
reviewerCross-chain bridge exploits dominated 2022 — six major incidents totaling $1.9 billion.The $1.9B/six-incident figure for 2022 is confirmed by the cited source. The trailing clause about attackers 'shifting toward social engineering and supply-chain compromises' before 'returning to infrastructure-layer attacks in 2026' is a broader narrative claim not found verbatim in the cited source or independently verified; it reads as plausible industry framing rather than a sourced fact.
confirmed
23 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“On May 18, 2026, the bridge was exploited for approximately $11.58 million through a business-logic validation flaw that allowed an attacker to withdraw far more value on the Ethereum side than was deposited on the Verus side.”
reviewerThe Verus-Ethereum Bridge was exploited on May 18, 2026 for approximately $11.58 million via a business-logic validation flaw.Multiple independent, higher-credibility outlets (The Block, CoinDesk) confirm the date and dollar figure. - #2[confirmed][no action needed]in the summary
“Following negotiations, the attacker returned approximately 75% of the stolen funds (4,052 ETH) in exchange for a 1,350 ETH bounty and an agreement to halt investigations.”
reviewerFollowing negotiations, the attacker returned approximately 75% of stolen funds (4,052 ETH) in exchange for a 1,350 ETH bounty and an agreement to halt investigations.Confirmed by multiple outlets describing the same negotiated 75/25 split and no-prosecution terms. - #3[confirmed][no action needed]in section: Background
“Verus Protocol is a decentralized, open-source blockchain project launched in 2018 by Michael J. Toutonghi, a former Microsoft Technical Fellow and Vice President, along with a group of volunteer technology professionals.”
reviewerVerus Protocol was launched in 2018 by Michael J. Toutonghi, a former Microsoft Technical Fellow and Vice President.Secondary sources differ on exact chronology (Windows-95-era VP vs. later Technical Fellow stint), but the core assertion that he held both titles at Microsoft is corroborated by the cited source and independent bios.citediq.wiki/wiki/verus - #4[confirmed][no action needed]in section: Background
“The project's native coin is VRSC, which employs a hybrid Proof-of-Work/Proof-of-Stake consensus algorithm called Proof of Power.”
reviewerVRSC uses a hybrid Proof-of-Work/Proof-of-Stake consensus algorithm called Proof of Power.Directly confirmed.citediq.wiki/wiki/verus - #5[confirmed][no action needed]in section: Background
“Verus is built on foundations derived from Komodo and Zcash, and incorporates zero-knowledge Sapling technology.”
reviewerVerus is built on foundations derived from Komodo and Zcash, incorporating zero-knowledge Sapling technology.Confirmed by independent Komodo-ecosystem documentation, not just the cited page.citediq.wiki/wiki/verus - #6[confirmed][no action needed]in section: Background
“The bridge relies on a notary system in which 8 of 15 designated notaries must sign a state root for a cross-chain transfer to be accepted as valid.”
reviewerThe bridge relies on a notary system in which 8 of 15 designated notaries must sign a state root for a cross-chain transfer to be valid.Confirmed, and consistent with post-exploit reporting that the notary layer functioned correctly (8-of-15 valid signatures were obtained on the forged blob). - #7[confirmed][no action needed]in section: May 2026 Exploit — Overview
“The stolen assets comprised 103.6 tBTC (Threshold Network's tokenized Bitcoin), 1,625 ETH, and approximately 147,000 USDC.”
reviewerThe stolen assets comprised 103.6 tBTC, 1,625 ETH, and approximately 147,000 USDC.Confirmed by identical figures across CoinDesk, The Block, and Merkle Science. - #8[confirmed][no action needed]in section: May 2026 Exploit — Overview
“Blockaid first detected suspicious activity at approximately 00:54 GMT involving the Verus-Ethereum Bridge contract and flagged the exploit as ongoing.”
reviewerBlockaid first detected suspicious activity at approximately 00:54 GMT and flagged the exploit as ongoing.Confirmed via independent corroboration of the 00:54 GMT timestamp. - #9[confirmed][no action needed]in section: May 2026 Exploit — Overview
“PeckShield independently confirmed the theft and tracked the consolidation of all stolen assets into 5,402.4 ETH held in attacker wallet 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9.”
reviewerPeckShield tracked the consolidation of stolen assets into 5,402.4 ETH held in wallet 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9.Wallet address and ETH total confirmed by two independent security firms as reported across outlets. - #10[confirmed][no action needed]in section: May 2026 Exploit — Overview
“The attacker's wallet had been funded with 1 ETH via Tornado Cash approximately 14 hours before the exploit was executed, and the attacker spent only approximately $10 in VRSC transaction fees to drain the entire bridge reserve.”
reviewerThe attacker's wallet was funded with 1 ETH via Tornado Cash approximately 14 hours before the exploit, and spent only approximately $10 in VRSC fees to drain the bridge.Both the Tornado Cash pre-funding timing and the ~$10 fee figure are corroborated outside the cited source. - #11[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
“The Ethereum bridge's submitImports() function then released 103.6 tBTC, 1,625 ETH, and 147,000 USDC from reserves against the fraudulent proof, as the checkCCEValues validation step lacked a check confirming input and output amounts were equal.”
reviewerNeither side of the bridge validated that the Verus-side input amount matched the Ethereum-side payout; submitImports()/checkCCEValues lacked this check.Technical description matches independent security-researcher accounts of the exploit mechanism. - #12[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
“The attacker constructed a cross-chain export containing only approximately $0.01 (roughly 0.02 VRSC) in source-side input.”
reviewerThe attacker constructed a cross-chain export containing only approximately $0.01 (roughly 0.02 VRSC) in source-side input.Confirmed. - #13[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
“Blockaid described the vulnerability as belonging to the same class as the 2022 Wormhole ($320 million) and Nomad ($190 million) bridge exploits, both of which also involved gaps between source-chain proof verification and destination-chain value binding.”
reviewerBlockaid described the vulnerability as belonging to the same class as the 2022 Wormhole ($320 million) and Nomad ($190 million) bridge exploits.Both historical dollar figures and the vulnerability-class comparison are accurate. - #14[confirmed][no action needed]in section: Technical Root Cause — Input/Output Validation Failure
“Blockaid estimated the fix required only approximately 10 lines of Solidity code.”
reviewerBlockaid estimated the fix required only approximately 10 lines of Solidity code.Confirmed by a source independent of Halborn. - #15[confirmed][no action needed]in section: Network Shutdown and Immediate Response
“Approximately 12 hours after the initial exploit, the Verus blockchain halted block production. The Verus core team stated via the project's Discord channel that most block-generating nodes had taken themselves offline in response to byproducts of the attack.”
reviewerApproximately 12 hours after the exploit, the Verus blockchain halted block production as most block-generating nodes took themselves offline, per a Discord statement.One cited source (PulseChain Nexus) misdates the underlying exploit itself as May 17 rather than May 18, but the network-halt claim it supports is corroborated elsewhere and is not itself in dispute. - #16[confirmed][no action needed]in section: Network Shutdown and Immediate Response
“Two days before the exploit, on approximately May 16, 2026, Verus had released what it described as an "urgent and mandatory" emergency update, version 1.2.14-2, referencing a vulnerability fix.”
reviewerTwo days before the exploit, on approximately May 16, 2026, Verus released an 'urgent and mandatory' emergency update, version 1.2.14-2.Confirmed. - #17[confirmed][no action needed]in section: Network Shutdown and Immediate Response
“As of reporting, the relationship between the patched vulnerability in that update and the exploited validation gap has not been publicly clarified by the Verus team. No public post-mortem from the Verus development team has been identified in available sources.”
reviewerThe relationship between the May 16 patch and the exploited validation gap has not been publicly clarified, and no public post-mortem has been identified.Accurate as an as-of-reporting statement about the May incident. However, a July 23, 2026 repeat exploit of the same bridge (same contract path, same bug class, ~$7.54M) that Verus also did not publicly explain is not mentioned anywhere on the page; see coverage_gaps. - #18[confirmed][no action needed]in section: Fund Recovery and Bounty Negotiation
“Verus offered the attacker a bounty of 1,350 ETH (approximately $2.8 million) in exchange for returning the remaining 4,052 ETH (approximately $8.5 million) within 24 hours.”
reviewerVerus offered the attacker a 1,350 ETH bounty (~$2.8M) in exchange for returning the remaining 4,052 ETH (~$8.5M) within 24 hours, and agreed to halt investigations.Confirmed across multiple outlets with consistent figures. - #19[confirmed][no action needed]in section: Fund Recovery and Bounty Negotiation
“On May 22, 2026, the exploiter returned 4,052.4 ETH to a Verus team wallet (0xF9AB...C1A74), representing approximately 75% of the total stolen value.”
reviewerOn May 22, 2026, the exploiter returned 4,052.4 ETH to Verus team wallet 0xF9AB...C1A74, representing approximately 75% of stolen value.Confirmed. - #20[confirmed][no action needed]in section: Broader 2026 Bridge Exploit Context
“PeckShield reported that eight major bridge-related exploits through mid-May 2026 resulted in cumulative losses of approximately $328.6 million. The Verus incident pushed the year-to-date total past $329 million.”
reviewerPeckShield reported that eight major bridge-related exploits through mid-May 2026 resulted in cumulative losses of approximately $328.6 million, pushing the 2026 total past $329 million.Figures and count match the cited source closely. - #22[confirmed][no action needed]in section: Broader 2026 Bridge Exploit Context
“A single April 2026 incident involving rsETH accounted for approximately $290 million of the 2026 total.”
reviewerA single April 2026 incident involving rsETH accounted for approximately $290 million of the 2026 total.Confirmed directly by the cited source. - #24[confirmed][no action needed]in section: Audit History and Security Posture
“No evidence of a prior third-party security audit of the Verus-Ethereum Bridge has been identified in available sources.”
reviewerNo evidence of a prior third-party security audit of the Verus-Ethereum Bridge has been identified in available sources.This is an appropriately hedged negative claim ('no evidence... has been identified') and is consistent with everything found in this review. - #25[confirmed][no action needed]in section: Audit History and Security Posture
“Halborn's post-exploit analysis characterized the incident as a business-logic failure rather than a cryptographic vulnerability, noting that the code executed as designed but that the design itself was flawed.”
reviewerHalborn's post-exploit analysis characterized the incident as a business-logic failure rather than a cryptographic vulnerability.Confirmed.