
Verus Protocol’s Ethereum bridge was reportedly exploited on Monday after an attacker used a fake cross-chain transfer message to drain at least $11.58 million in cryptocurrency.
Blockaid said its monitoring system detected the exploit after a transaction transferred 1,625 Ether, 147,659 USDC and 103.57 tBTC v2 from the bridge’s reserves to a wallet controlled by the attacker.
“This is NOT an ECDSA bypass, NOT a notary key compromise, NOT a parser/hash-binding bug, IS a missing source-amount validation in checkCCEValues,”
Blockaid said in a statement analysing the exploit.
PeckShield said onchain data showed the stolen assets were later converted into Ether, with the attacker wallet holding approximately 5,402 ETH worth more than $11.4 million.
Security researchers said the exploit resembled previous bridge attacks including the $190 million Nomad Bridge exploit and the $325 million Wormhole exploit from 2022.
Blockchain security firm ExVul said the attacker used a forged cross-chain import payload that passed the bridge’s verification process and triggered multiple fraudulent transfers to the drainer wallet.
The incident followed a separate $10 million exploit confirmed by THORChain on Saturday as decentralised finance platforms continued facing elevated security risks throughout 2026.
At the time of reporting, Ethereum price was $2,117.95.