Incident case

Verus-Ethereum Bridge May 2026 import verification exploit

In May 2026, the Verus-Ethereum Bridge suffered a separate Ethereum-side cross-chain import verification exploit before the later July incident. Independent incident reporting and transaction analysis place the gross drain at about $11.4–11.6 million across ETH, tBTC and USDC. Verus later documented partial asset recovery, a restoration and restitution process, and a July 12 bridge reopen process. A separate unexploited vulnerability caused another precautionary pause on July 16. These May-aftermath facts do not resolve the later July exploit.

reviewedcurrent

Incident facts

Incident title
Verus-Ethereum Bridge May 2026 import verification exploit
Bridge
Verus-Ethereum Bridge
Incident date
Approx. 2026-05-18
Incident type
Exploit
Major incident
Yes
Affected chains
Verus, Ethereum
Affected assets
ETH, tBTC, USDC
Attack category
Message Verification Failure
Reported loss
about $11.4–11.6 million
Amount confidence
Medium
Loss amount basis
Mixed Sources
Recovery
Partial Recovery
Reimbursement
In Progress
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-08-20
Last verified
2026-08-20

Amount and valuation

Contemporaneous security reporting described approximately 1,625 ETH, 103.6 tBTC and about 147,000 USDC drained, with gross contemporaneous valuation around $11.4–11.6 million.

The gross USD value is a mixed-source contemporaneous estimate, not a first-party exact accounting figure. Keep it distinct from later attacker-fund returns, residual backing loss, restitution credits and bounty treatment.

Why this remains unresolved

Timeline events

  • Verus-Ethereum Bridge May exploit drains Ethereum-side reservesApprox. 2026-05-18

    A separate May exploit caused unauthorized release of Ethereum-side bridge reserves after a cross-chain import/message verification failure. Contemporaneous reporting placed the gross drain around $11.4–11.6 million across ETH, tBTC and USDC. BIR keeps the public mechanism description non-operational.

    Exploit OccurredHigh

    Separate from the July 23 incident. No exploit reproduction instructions are included.

  • Partial attacker-fund return and residual backing loss established2026-05-22

    Contemporaneous reporting recorded a return of about 4,052.4 ETH under a negotiated bounty arrangement. Verus later stated that, after some asset recovery, about 26.6% of the ETH and tBTC backing held in the Ethereum contract remained lost. These are different recovery scopes and are not converted into an invented recovered-USD total.

    Funds RecoveredHigh

    Attacker-fund return, residual backing loss and bounty are preserved as distinct claims.

  • Verus publishes restoration and restitution process2026-07-03

    Verus v1.2.17 described a deterministic restoration process for affected holdings and restitution credits intended to represent reduced vETH and tBTC.vETH value. The reviewed source supports restitution in progress but does not prove completion for every affected user.

    Reimbursement StartedHigh

    Restitution is separate from attacker-fund recovery and from the bounty arrangement.

  • Verus begins Ethereum bridge upgrade and reopen process2026-07-12

    Verus v1.2.17-1 enabled voting to upgrade the Ethereum bridge contracts and reopen the Verus↔Ethereum connection, establishing a May-aftermath reopen milestone before later security events.

    Bridge ReopenedHigh

    This is May-aftermath reopen evidence only; it is not post-July-23 reopen evidence.

  • Cross-chain functions paused again for separate unexploited vulnerability2026-07-16

    Verus v1.2.17-2 said a researcher found a potential cross-chain exploit that was confirmed not to have been exploited; an oracle notification disabled cross-chain functions again until nodes upgraded. BIR records this as a later security re-pause, not as another exploit and not as the July 23 incident.

    Bridge PausedHigh

    Later lifecycle event only. It does not change the classification of the May exploit or the separate July 23 exploit.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.