Skip to main content
Sign in
Verus Protocol (VRSC)1 decision on this page

Audit log

Every state-changing event for Verus Protocol (VRSC): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-06 17:12:40Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    77BJ3kn2m14N…jbDQFRoesha256 → base58
    verifying row…
    canonical bytes (19828 B) ▸
    {"actor":"system:backfill","investigation_id":"8b05afa2-b3b1-4812-a3c2-2b69513839e8","kind":"publish","page_slug":"verus-protocol-vrsc","published_at":"2026-08-06T17:12:40.281Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Verus Protocol (VRSC)","sections":[{"content":"Verus Protocol (ticker: VRSC) is an open-source, decentralized blockchain protocol launched in May 2018. It was conceived by Michael J. Toutonghi, a former Vice President and Technical Fellow at Microsoft and the architect of the .NET framework, along with co-founders including Alex R. English, David Dawes, and Asher Dawes. The project had a fair launch with no ICO, no premine, and no developer fees. Verus is a fork of Komodo, which itself derives from Zcash, and uses a hybrid consensus mechanism called Proof of Power (PoP) combining 50% Proof of Work and 50% Proof of Stake. A key feature is Public Blockchains as a Service (PBaaS), enabling users to deploy independent blockchains. The Verus Ethereum Bridge was built to facilitate cross-chain asset transfers between the Verus chain and Ethereum mainnet.","heading":"Project Background","severity":"low","sources":[{"credibility":2,"name":"IQ.wiki: Verus — Decentralized Finance","type":"research","url":"https://iq.wiki/wiki/verus"},{"credibility":2,"name":"HTX Exchange: Verus (VRSC) — Project Background","type":"other","url":"https://www.htx.com/tokens/VRSC/"}]},{"content":"On May 18, 2026, an attacker drained approximately $11.58 million from the Verus-Ethereum Bridge. The stolen assets comprised 1,625 ETH, 103.57 tBTC (Threshold Network tokenized bitcoin), and 147,000 USDC. Within approximately 24 hours, the attacker consolidated these into 5,402 ETH held at drainer wallet 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9. Pre-funding for the attack was traced to Tornado Cash. Security researchers at Merkle Science and Halborn identified the root cause as a missing source-amount validation in the bridge's checkCCEValues function. While the contract correctly performed cryptographic checks — including notary signatures, Merkle proofs, and hash bindings — it never verified that the source-chain export's economic totals matched the payout being claimed on the Ethereum side. This allowed an attacker to forge a cross-chain import payload that passed every cryptographic check while committing effectively zero value on the Verus chain — approximately $10 in VRSC transaction fees could authorize a multi-million-dollar Ethereum-side payout. Security researchers noted the fix required approximately 10 lines of Solidity code. The vulnerability class was compared by researchers to the Wormhole (2022) and Nomad (2022) bridge hacks.","heading":"May 2026 Bridge Exploit — $11.58M","severity":"critical","sources":[{"credibility":2,"name":"Merkle Science: Hack Track — The $11.58M Verus Bridge Hack","type":"research","url":"https://www.merklescience.com/blog/hack-track-the-11-58m-verus-bridge-hack"},{"credibility":2,"name":"Halborn: Explained — The Verus-Ethereum Bridge Hack (May 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-verus-ethereum-bridge-hack-may-2026"},{"credibility":1,"name":"CoinDesk: Verus-Ethereum bridge loses $11 million as hackers keep targeting cross-chain infrastructure","type":"news_article","url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"},{"credibility":2,"name":"CCN: Verus Bridge Exploited — $11.58M Drained, Attack Still Live","type":"news_article","url":"https://www.ccn.com/news/crypto/verus-bridge-exploited-12m-drained-attack-still-live/"},{"credibility":2,"name":"Cryptopolitan: Verus suffers $11.5M hack as bridge-related exploits hit $329M in 2026","type":"news_article","url":"https://www.cryptopolitan.com/verus-suffers-11-5m-hack-as-bridge-related-exploits-hit-329m-in-2026/"}]},{"content":"Following the May 18, 2026 exploit, the Verus development team made a public on-chain offer: if the attacker returned 4,052.4 ETH, the remaining balance would be recognized as a legitimate white-hat bounty. By May 22, 2026, the attacker complied, returning 4,052 ETH (valued at approximately $8.5 million at the time) and retaining 1,350 ETH (approximately $2.8 million) as the negotiated bounty. No information was disclosed in contemporaneous reporting about a confirmed full patch deployment or an independent third-party security audit of the bridge contract following recovery. On approximately July 8, 2026 — approximately six weeks after the exploit — bridge reserves were redeposited, effectively reopening the bridge to user funds. No public announcement confirming a verified patch or audit before this reopening has been identified by researchers. This decision left the same vulnerable contract active and sufficiently capitalized to enable a second material exploit.","heading":"White-Hat Recovery and Bridge Governance Failure","severity":"critical","sources":[{"credibility":2,"name":"Blockonomi: Verus Bridge Hack Resolved — 4,052 ETH Recovered Through $2.8M Bounty Deal","type":"news_article","url":"https://blockonomi.com/verus-bridge-hack-resolved-4052-eth-recovered-through-2-8m-bounty-deal"},{"credibility":2,"name":"CoinEdition: Verus Bridge Exploiter Returns 4,052 ETH, Keeps 1,350 ETH as Bounty","type":"news_article","url":"https://coinedition.com/verus-bridge-exploiter-returns-4052-eth-keeps-1350-eth-as-bounty/"},{"credibility":1,"name":"The Block: Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty","type":"news_article","url":"https://www.theblock.co/post/402319/verus-bridge-exploiter-returns-4052-eth"},{"credibility":2,"name":"CryptoCoinCentral: Verus Ethereum Bridge Drained of $7.54M in Repeat Exploit","type":"news_article","url":"https://coincentral.com/verus-ethereum-bridge-drained-of-7-54m-in-repeat-exploit/"}]},{"content":"On July 23, 2026 at 03:45 UTC, a second attacker drained approximately $7.54 million from the Verus-Ethereum Bridge through exploit transaction 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099. The attacker-controlled EOA was 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c, with loot wallet 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54. Assets stolen included approximately 1,137.45 ETH, 71.50 tBTC v2, 149,275 USDC, 78,300 USDT, 31,475 EURC, 59.43 MKR, 92,784 scrvUSD, and approximately 220,357 DAI in internal transfers. The attacker consolidated the stolen basket into approximately 3,916 ETH and began routing portions through Tornado Cash within hours. Security firm Blockaid confirmed the attack employed the same bridge contract, same entry path, and same bug class as the May exploit — specifically using the bridge's submitImports function to release reserves without matching value committed on the Verus source chain. The July attacker made no recovery offer and did not return any funds. At the time of reporting, no public statement had been issued by the Verus team.","heading":"July 2026 Repeat Exploit — $7.54M","severity":"critical","sources":[{"credibility":1,"name":"The Block: New Verus-Ethereum bridge attack drains $7.5 million through flaw used in May","type":"news_article","url":"https://www.theblock.co/post/409489/new-verus-ethereum-bridge-attack"},{"credibility":2,"name":"Crypto.news: Verus Ethereum Bridge hacked again for $7.54M after May exploit","type":"news_article","url":"https://crypto.news/verus-ethereum-bridge-hacked-again-for-7-54m-after-may-exploit/"},{"credibility":2,"name":"CryptoTimes: Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/07/23/verus-ethereum-bridge-exploited-again-for-7-54m-in-repeat-attack/"},{"credibility":1,"name":"CoinDesk: Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart"},{"credibility":2,"name":"AMBCrypto: Verus-Ethereum Bridge hit by second hack as $7.54M vanishes","type":"news_article","url":"https://ambcrypto.com/verus-ethereum-bridge-hit-by-second-hack-as-7-54m-vanishes/"},{"credibility":2,"name":"CoinCentral: Verus Ethereum Bridge Drained of $7.54M in Repeat Exploit","type":"news_article","url":"https://coincentral.com/verus-ethereum-bridge-drained-of-7-54m-in-repeat-exploit/"}]},{"content":"The root cause of both exploits was a single missing validation in the bridge's Solidity contract: the checkCCEValues function did not verify that the source-chain export's economic totals matched the payout being released on the Ethereum side. The cryptographic machinery — notary signatures, Merkle proofs, and hash bindings — functioned as intended, but the contract omitted economic verification. The submitImports function, the specific entry point abused in both attacks, accepted cross-chain import payloads that were cryptographically valid but economically unbacked. An attacker could commit a nominal amount of VRSC (approximately $10 in fees) on the source chain while claiming a multi-million-dollar payout on Ethereum. Security researchers at Merkle Science assessed the fix required approximately 10 lines of Solidity code. Blockaid described both incidents as involving the same bridge contract, same entry path, and same bug class, indicating the underlying flaw was not fully remediated between the May and July incidents. Halborn and Merkle Science both classified this vulnerability alongside the Wormhole (February 2022) and Nomad (August 2022) bridge exploits as a source-destination value gap class of attack.","heading":"Technical Vulnerability Analysis","severity":"critical","sources":[{"credibility":2,"name":"Merkle Science: Hack Track — The $11.58M Verus Bridge Hack","type":"research","url":"https://www.merklescience.com/blog/hack-track-the-11-58m-verus-bridge-hack"},{"credibility":2,"name":"Halborn: Explained — The Verus-Ethereum Bridge Hack (May 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-verus-ethereum-bridge-hack-may-2026"},{"credibility":2,"name":"Crypto.news: Verus Ethereum Bridge hacked again for $7.54M after May exploit","type":"news_article","url":"https://crypto.news/verus-ethereum-bridge-hacked-again-for-7-54m-after-may-exploit/"},{"credibility":1,"name":"The Block: New Verus-Ethereum bridge attack drains $7.5 million through flaw used in May","type":"news_article","url":"https://www.theblock.co/post/409489/new-verus-ethereum-bridge-attack"}]},{"content":"The Verus-Ethereum Bridge's total value locked fell sharply following the two exploits. One report noted that TVL declined from approximately $100 million at the start of 2025 to approximately $9 million by the time of the July 2026 attack, representing a sustained decline punctuated by the exploit events. The VRSC token's market capitalization has been reported at varying figures across sources in mid-2026, ranging from approximately $22 million to $74 million depending on source and timestamp. The combined nominal losses from the two bridge exploits — $19.12 million — exceed the lower-end market capitalization estimates for the VRSC token itself, indicating a disproportionate impact relative to the broader project's scale.","heading":"Protocol TVL and Market Impact","severity":"high","sources":[{"credibility":2,"name":"CoinCentral: Verus Ethereum Bridge Drained of $7.54M in Repeat Exploit","type":"news_article","url":"https://coincentral.com/verus-ethereum-bridge-drained-of-7-54m-in-repeat-exploit/"},{"credibility":2,"name":"CoinMarketCap: Verus (VRSC) Price, Market Cap","type":"other","url":"https://coinmarketcap.com/currencies/veruscoin/"}]},{"content":"No evidence has been identified in public reporting of an independent third-party security audit of the Verus-Ethereum Bridge contract prior to either exploit, or between the May and July incidents. The Verus development team's decision to reopen the bridge and replenish reserves on approximately July 8, 2026 — without confirming a verified patch or publishing a technical post-mortem — has been identified by multiple security researchers as the direct governance failure that enabled the repeat attack. As of the July 2026 exploit, the Verus team had not issued a public statement detailing the July incident, a remediation plan, or a user compensation strategy. Researchers and media outlets including Blockaid, Merkle Science, and Halborn have called for a full technical post-mortem, a credible and audited fix, and a clear timeline before any bridge resumption. The broader context of the two exploits occurring within the same year and through the same attack vector places Verus among a documented pattern of cross-chain bridge security failures in 2026, which researchers estimated caused over $328 million in total losses across the ecosystem.","heading":"Security Governance and Audit Gaps","severity":"critical","sources":[{"credibility":2,"name":"Merkle Science: Hack Track — The $11.58M Verus Bridge Hack","type":"research","url":"https://www.merklescience.com/blog/hack-track-the-11-58m-verus-bridge-hack"},{"credibility":2,"name":"CryptoTimes: Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/07/23/verus-ethereum-bridge-exploited-again-for-7-54m-in-repeat-attack/"},{"credibility":2,"name":"Cryptopolitan: Verus suffers $11.5M hack as bridge-related exploits hit $329M in 2026","type":"news_article","url":"https://www.cryptopolitan.com/verus-suffers-11-5m-hack-as-bridge-related-exploits-hit-329m-in-2026/"},{"credibility":2,"name":"Halborn: Explained — The Verus-Ethereum Bridge Hack (May 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-verus-ethereum-bridge-hack-may-2026"}]}],"sources_used":[{"credibility":2,"name":"Halborn: Explained — The Verus-Ethereum Bridge Hack (May 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-verus-ethereum-bridge-hack-may-2026"},{"credibility":1,"name":"The Block: New Verus-Ethereum bridge attack drains $7.5 million through flaw used in May","type":"news_article","url":"https://www.theblock.co/post/409489/new-verus-ethereum-bridge-attack"},{"credibility":1,"name":"The Block: Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty","type":"news_article","url":"https://www.theblock.co/post/402319/verus-bridge-exploiter-returns-4052-eth"},{"credibility":1,"name":"CoinDesk: Verus-Ethereum bridge loses $11 million as hackers keep targeting cross-chain infrastructure","type":"news_article","url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"},{"credibility":1,"name":"CoinDesk: Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/23/bitcoin-ethereum-linked-protocols-lose-usd35-million-in-multiple-attacks-hours-apart"},{"credibility":2,"name":"Merkle Science: Hack Track — The $11.58M Verus Bridge Hack","type":"research","url":"https://www.merklescience.com/blog/hack-track-the-11-58m-verus-bridge-hack"},{"credibility":2,"name":"Crypto.news: Verus Ethereum Bridge hacked again for $7.54M after May exploit","type":"news_article","url":"https://crypto.news/verus-ethereum-bridge-hacked-again-for-7-54m-after-may-exploit/"},{"credibility":2,"name":"CryptoTimes: Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack","type":"news_article","url":"https://www.cryptotimes.io/2026/07/23/verus-ethereum-bridge-exploited-again-for-7-54m-in-repeat-attack/"},{"credibility":2,"name":"AMBCrypto: Verus-Ethereum Bridge hit by second hack as $7.54M vanishes","type":"news_article","url":"https://ambcrypto.com/verus-ethereum-bridge-hit-by-second-hack-as-7-54m-vanishes/"},{"credibility":2,"name":"Blockonomi: Verus Bridge Hack Resolved — 4,052 ETH Recovered Through $2.8M Bounty Deal","type":"news_article","url":"https://blockonomi.com/verus-bridge-hack-resolved-4052-eth-recovered-through-2-8m-bounty-deal"},{"credibility":2,"name":"CoinEdition: Verus Bridge Exploiter Returns 4,052 ETH, Keeps 1,350 ETH as Bounty","type":"news_article","url":"https://coinedition.com/verus-bridge-exploiter-returns-4052-eth-keeps-1350-eth-as-bounty/"},{"credibility":2,"name":"CoinCentral: Verus Ethereum Bridge Drained of $7.54M in Repeat Exploit","type":"news_article","url":"https://coincentral.com/verus-ethereum-bridge-drained-of-7-54m-in-repeat-exploit/"},{"credibility":2,"name":"Cryptopolitan: Verus suffers $11.5M hack as bridge-related exploits hit $329M in 2026","type":"news_article","url":"https://www.cryptopolitan.com/verus-suffers-11-5m-hack-as-bridge-related-exploits-hit-329m-in-2026/"},{"credibility":2,"name":"IQ.wiki: Verus — Decentralized Finance","type":"research","url":"https://iq.wiki/wiki/verus"},{"credibility":2,"name":"CoinMarketCap: Verus (VRSC) Price, Market Cap","type":"other","url":"https://coinmarketcap.com/currencies/veruscoin/"}],"summary":"Verus Protocol (VRSC) is an open-source, privacy-focused Layer 1 blockchain launched in May 2018 by Michael J. Toutonghi, a former Microsoft Technical Fellow and architect of the .NET framework. Its Ethereum cross-chain bridge suffered two exploits in 2026 — $11.58M on May 18 and $7.54M on July 23 — both caused by the same unpatched source-amount validation flaw in the bridge's import path. The project's decision to reopen the bridge and redeposit reserves on July 8 without a confirmed full patch or independent audit directly enabled the repeat attack, raising significant concerns about security governance.","timeline":[{"date":"2018-05-01","event":"Verus Protocol (VRSC) launches with a fair launch — no ICO, no premine, no developer fees. Founded by Michael J. Toutonghi and co-founders.","source":"IQ.wiki: Verus","source_url":"https://iq.wiki/wiki/verus"},{"date":"2026-05-18","event":"Attacker exploits missing source-amount validation in the Verus-Ethereum Bridge's checkCCEValues function, draining 1,625 ETH, 103.57 tBTC, and 147,000 USDC — a total of approximately $11.58 million. Assets consolidated into 5,402 ETH at wallet 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9.","source":"CoinDesk: Verus-Ethereum bridge loses $11 million","source_url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"},{"date":"2026-05-22","event":"After public on-chain negotiation by the Verus team, the May attacker returns 4,052 ETH (approximately $8.5 million) and retains 1,350 ETH (approximately $2.8 million) as a white-hat bounty — representing approximately 75% recovery.","source":"The Block: Verus bridge exploiter returns 4,052 ETH","source_url":"https://www.theblock.co/post/402319/verus-bridge-exploiter-returns-4052-eth"},{"date":"2026-07-08","event":"Bridge reserves are redeposited, effectively reopening the Verus-Ethereum Bridge to user funds. No confirmed full patch or independent audit had been publicly announced prior to this reopening.","source":"Crypto.news: Verus Ethereum Bridge hacked again for $7.54M","source_url":"https://crypto.news/verus-ethereum-bridge-hacked-again-for-7-54m-after-may-exploit/"},{"date":"2026-07-23","event":"A second attacker exploits the same submitImports entry path and bug class, draining approximately $7.54 million in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from the bridge. Assets consolidated to approximately 3,916 ETH and partially routed through Tornado Cash. Attacker EOA: 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c.","source":"The Block: New Verus-Ethereum bridge attack drains $7.5 million","source_url":"https://www.theblock.co/post/409489/new-verus-ethereum-bridge-attack"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 7e2ce650-cd1b-41a8-b906-ea720da4a7b0
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.