Key Highlights:
  • The Verus-Ethereum bridge suffered an ongoing exploit that drained roughly $11.6 million in crypto assets.
  • Stolen funds included tBTC, ETH, and USDC before being swapped into more than 5,400 ETH.
  • Security researchers suspect the attack involved forged bridge messages or a withdrawal validation bypass.
  • The attacker reportedly funded the exploit wallet using Tornado Cash before launching the attack.
  • The incident adds to growing concerns around cross-chain bridge security after several major DeFi exploits in 2026.

Verus Network Halts Following Bridge Attack

Privacy-focused blockchain project Verus suffered a major exploit targeting its Ethereum bridge, with blockchain security firms estimating losses at approximately $11.6 million.

According to researchers from Blockaid and PeckShield, the attacker drained large amounts of tBTC, ETH, and USDC before converting the stolen assets into roughly 5,400 ETH.

PeckShield reported that the stolen assets included 103.6 tBTC, 1,625 ETH, and 147,000 USDC.

The Verus team later confirmed that the network had effectively halted operations, with many block-producing nodes voluntarily taking themselves offline after detecting issues connected to the exploit.

Developers said they are actively investigating how the attack was executed and evaluating recovery options.

Attack May Have Exploited Bridge Validation Logic

Security firms believe the attacker exploited weaknesses tied to the Verus-Ethereum bridge contract itself.

According to GoPlus Security, the attacker appears to have initiated a small transaction before triggering a function that caused the bridge contract to transfer reserve assets directly to the attacker-controlled wallet.

Researchers suggested several possible attack vectors, including cross-chain message validation forgery, withdrawal logic bypasses, or flaws in access control permissions.

The attacker wallet was reportedly initially funded using 1 ETH from Tornado Cash, a crypto mixing protocol frequently used to obscure transaction origins.

Bridge Exploits Continue Across DeFi

The Verus attack is the latest in a growing list of bridge-related exploits hitting the crypto industry this year.

Cross-chain bridges remain one of the most vulnerable parts of decentralized finance because they rely on complex validation systems to move assets between networks.

Recent attacks involving Kelp DAO, LayerZero-powered infrastructure, and other bridge systems have already pushed several protocols to migrate toward stricter security standards and alternative interoperability providers like Chainlink CCIP.

The incident also highlights how attackers continue targeting infrastructure layers rather than individual users, with bridge exploits often leading to some of the largest losses in crypto.

Verus Ecosystem Faces Pressure After Exploit

Verus launched in 2018 as a privacy-focused blockchain using a hybrid consensus model combining proof-of-work and proof-of-stake mechanisms.

Its Ethereum bridge, introduced in 2023, was designed to allow users to move and convert assets between Verus and Ethereum.

Now, the exploit places significant pressure on the project’s infrastructure and reputation, especially as regulators and institutions increasingly scrutinize bridge security across decentralized finance.