Verus Bridge Lost $11.5M. Its Last Patch Was for Something Else Entirely.




 The Verus-Ethereum Bridge was drained for $11.58 million on May 18, 2026. The attacker took 103.6 tBTC, 1,625 ETH, and 147,000 USDC in one transaction, swapped everything through Uniswap into 5,402.4 ETH, and parked it in a single wallet still visible on Etherscan today.

Seven days before the exploit, the Verus development team shipped what they called a critical update. Version v1.2.16-1, released May 11 by developer Asherda, addressed CVE-2024-52911, a Bitcoin Core vulnerability that could crash nodes if miners staked maliciously crafted blocks. The team recommended all operators upgrade immediately.

That patch was not a bridge security update. It addressed node stability, not the bridge contract's transfer validation logic. The bridge had a different weakness, one that allowed an attacker to call an unknown method on the contract, trigger internal transfers, and drain the reserves before the block confirmed.

Blockchain security firm PeckShield caught the outflow in real time and published the wallet addresses within minutes. The attacker's wallet had been pre-funded through Tornado Cash roughly 14 hours before the drain, pointing to deliberate preparation rather than an opportunistic attack.

What makes this case worth paying attention to is what Verus had been telling its community. The project's marketing described its architecture as having "No Code to Exploit." No smart contracts. No audits needed. No attack surface by design.

One transaction ended that claim.

Security researchers drew comparisons to Kelp DAO's $292 million loss, Nomad's $190 million, and Wormhole's $320 million. Each project had its own reason the old bridge attack playbook did not apply. Each lost hundreds of millions anyway.

The Verus team had not released a public statement at the time this was written. No post-exploit emergency patch has appeared on the main GitHub repository.

The full breakdown of the exploit timeline, the on-chain wallet trail, and what it means for cross-chain bridge users is live now at CryptoNewsLive.org.

Visit CryptoNewsLive.org for daily crypto news and real-time security coverage.

Comments

Popular posts from this blog

Ripple Is Building XRPL's Defense Against Quantum Computing, and the Clock Is Already Running

Hoskinson Just Said Everything Nobody Else Will Say About Crypto in 2026

: KelpDAO's $292M Bridge Hack Just Broke Aave and Locked Real Lenders Out