Verus-Ethereum Bridge May 2026 import verification exploit
In May 2026, the Verus-Ethereum Bridge suffered a separate Ethereum-side cross-chain import verification exploit before the later July incident. Independent incident reporting and transaction analysis place the gross drain at about $11.4–11.6 million across ETH, tBTC and USDC. Verus later documented partial asset recovery, a restoration and restitution process, and a July 12 bridge reopen process. A separate unexploited vulnerability caused another precautionary pause on July 16. These May-aftermath facts do not resolve the later July exploit.
Incident facts
- Incident title
- Verus-Ethereum Bridge May 2026 import verification exploit
- Bridge
- Verus-Ethereum Bridge
- Incident date
- Approx. 2026-05-18
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Verus, Ethereum
- Affected assets
- ETH, tBTC, USDC
- Attack category
- Message Verification Failure
- Reported loss
- about $11.4–11.6 million
- Amount confidence
- Medium
- Loss amount basis
- Mixed Sources
- Recovery
- Partial Recovery
- Reimbursement
- In Progress
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-20
- Last verified
- 2026-08-20
Amount and valuation
Contemporaneous security reporting described approximately 1,625 ETH, 103.6 tBTC and about 147,000 USDC drained, with gross contemporaneous valuation around $11.4–11.6 million.
The gross USD value is a mixed-source contemporaneous estimate, not a first-party exact accounting figure. Keep it distinct from later attacker-fund returns, residual backing loss, restitution credits and bounty treatment.
approximately 1,625 ETH, 103.6 tBTC and about 147,000 USDC drainedabout $11.4–11.6 million
Used only as a mixed-source gross-loss range; no exact first-party USD loss is inferred.
Why this remains unresolved
- The reviewed first-party restoration release establishes partial recovery and restitution mechanics but does not prove that every restitution credit was fully distributed to completion.
- The gross USD loss remains an approximate mixed-source range rather than an exact first-party accounting value.
- Later July 16 and July 23 lifecycle states belong to separate subsequent security events and do not convert May recovery or reopening into July recovery or reopening evidence.
Timeline events
Verus-Ethereum Bridge May exploit drains Ethereum-side reservesApprox. 2026-05-18
A separate May exploit caused unauthorized release of Ethereum-side bridge reserves after a cross-chain import/message verification failure. Contemporaneous reporting placed the gross drain around $11.4–11.6 million across ETH, tBTC and USDC. BIR keeps the public mechanism description non-operational.
Separate from the July 23 incident. No exploit reproduction instructions are included.
Partial attacker-fund return and residual backing loss established2026-05-22
Contemporaneous reporting recorded a return of about 4,052.4 ETH under a negotiated bounty arrangement. Verus later stated that, after some asset recovery, about 26.6% of the ETH and tBTC backing held in the Ethereum contract remained lost. These are different recovery scopes and are not converted into an invented recovered-USD total.
Attacker-fund return, residual backing loss and bounty are preserved as distinct claims.
Verus publishes restoration and restitution process2026-07-03
Verus v1.2.17 described a deterministic restoration process for affected holdings and restitution credits intended to represent reduced vETH and tBTC.vETH value. The reviewed source supports restitution in progress but does not prove completion for every affected user.
Restitution is separate from attacker-fund recovery and from the bounty arrangement.
Verus begins Ethereum bridge upgrade and reopen process2026-07-12
Verus v1.2.17-1 enabled voting to upgrade the Ethereum bridge contracts and reopen the Verus↔Ethereum connection, establishing a May-aftermath reopen milestone before later security events.
This is May-aftermath reopen evidence only; it is not post-July-23 reopen evidence.
Cross-chain functions paused again for separate unexploited vulnerability2026-07-16
Verus v1.2.17-2 said a researcher found a potential cross-chain exploit that was confirmed not to have been exploited; an oracle notification disabled cross-chain functions again until nodes upgraded. BIR records this as a later security re-pause, not as another exploit and not as the July 23 incident.
Later lifecycle event only. It does not change the classification of the May exploit or the separate July 23 exploit.
Evidence records
- Verus v1.2.17 — bridge restoration and recovery updateVerusCoin · Tier 1 · High reliability · primary · 2026-07-03Claim scope: Incident Case
Stable first-party authority naming the May 17 exploit and establishing the later recovery/restoration boundary. Used here for incident existence and lifecycle, not for an exact gross USD loss.
- Verus Bridge Exploit — May 2026 independent transaction analysisu0 · Tier 2 · High reliability · secondary · Approx. 2026-05-18Claim scope: Incident Case
Independent reproducible transaction/root-cause analysis. BIR uses it only to support the high-level import/message-verification failure and transaction package; operational exploit reproduction detail is not promoted into canonical text.
- Verus-Ethereum Bridge May 2026 exploit transactionEtherscan · Tier 2 · High reliability · secondary · Approx. 2026-05-18Claim scope: Incident Case
Direct Ethereum transaction anchor for the reviewed May exploit boundary.
- Ongoing exploit drains $11.6 million from Verus-Ethereum bridge: BlockaidThe Block · Tier 2 · High reliability · secondary · 2026-05-17Claim scope: Amount
Contemporaneous reporting supporting the approximate $11.4–11.6 million gross range and the reported ETH, tBTC and USDC quantities.
- Verus v1.2.17 — partial recovery and residual backing-loss statementVerusCoin · Tier 1 · High reliability · primary · 2026-07-03Claim scope: Recovery
First-party statement that after some asset recovery about 26.6% of ETH and tBTC backing held in the Ethereum contract remained lost. This is not converted into a recovered-USD amount.
- Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty: onchain analystThe Block · Tier 2 · High reliability · secondary · 2026-05-22Claim scope: Recovery
Contemporaneous recovery reporting for the approximately 4,052.4 ETH return and separately retained bounty; neither is treated as proof of user restitution completion.
- Verus v1.2.17 — restoration and restitution mechanicsVerusCoin · Tier 1 · High reliability · primary · 2026-07-03Claim scope: Reimbursement
First-party authority for the restoration/restitution process. It supports in-progress restitution, not completion for every affected user.
- Verus v1.2.17-1 — Ethereum bridge contract upgrade and reopen processVerusCoin · Tier 1 · High reliability · primary · 2026-07-12Claim scope: Restart
First-party May-aftermath authority for the Ethereum contract-upgrade vote and explicit reopen process. Not post-July-23 reopen evidence.
- Verus v1.2.17-2 — precautionary cross-chain pause for separate unexploited vulnerabilityVerusCoin · Tier 1 · High reliability · primary · 2026-07-16Claim scope: Status
First-party statement that a potential cross-chain exploit was confirmed not ever exploited and cross-chain functions were disabled again as a precaution. This is not another exploit record.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Reviewed public sources straddle May 17 and May 18 date labeling across time zones, so BIR uses an approximate May 18 incident boundary rather than claiming a more precise timestamp.
- The exact realized economic loss and exact attacker-fund recovery in USD are not normalized from the later residual-backing percentage.
- The completion state of every user restitution credit remains unverified in the admitted first-party release package.
- Public canonical text intentionally stops at a high-level import/message-verification failure and omits exploit reproduction instructions.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.