LIVE
RedotPay Says It Will Defend Itself Against Binance LawsuitPutin Signs Russia's First Comprehensive Crypto LawPutin Signs Russian Law Regulating Bitcoin and CryptoCircle Shares Fall After EPS Beat, Net Income Gain, Revenue MissJapan FSA to Launch Crypto and Stablecoin Division by August 7: ReportThree Missouri Men Face 20 Years in Bitcoin Home Invasion PlotColdcard Wallet Hack Losses Reportedly Exceed $100 MillionCFTC Crypto Derivatives in 2026: Futures, Perpetuals, Margin, and Market OversightHow the SEC Classifies Crypto Assets and Tokenized SecuritiesCrypto Regulator Responsibilities by Product in 2026RedotPay Says It Will Defend Itself Against Binance LawsuitPutin Signs Russia's First Comprehensive Crypto LawPutin Signs Russian Law Regulating Bitcoin and CryptoCircle Shares Fall After EPS Beat, Net Income Gain, Revenue MissJapan FSA to Launch Crypto and Stablecoin Division by August 7: ReportThree Missouri Men Face 20 Years in Bitcoin Home Invasion PlotColdcard Wallet Hack Losses Reportedly Exceed $100 MillionCFTC Crypto Derivatives in 2026: Futures, Perpetuals, Margin, and Market OversightHow the SEC Classifies Crypto Assets and Tokenized SecuritiesCrypto Regulator Responsibilities by Product in 2026
Homepage/Ethereum/Verus-Ethereum Exploit Drains $11.6 Million as Attack Continues
ETHEREUM

Verus-Ethereum Exploit Drains $11.6 Million as Attack Continues

BY Joshua Trelawen·2 MIN READ·MAY 18, 2026

An ongoing exploit has reportedly drained $11.6 million from the Verus-Ethereum bridge, with the attack still described as active at the time of initial reports.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
3Internal references connected to related coverage
2External source domains cited in the article
2 minEstimated time to read the full report

What the Verus-Ethereum exploit report says so far

The reported incident targets the Verus-Ethereum bridge, a cross-chain infrastructure component connecting the Verus and Ethereum networks. The reported loss figure stands at $11.6 million.

The exploit is described as ongoing rather than resolved, meaning the final damage total could shift as events develop. Details on the specific vulnerability or attack vector have not been confirmed in available documentation at this stage.

Cross-chain bridges have been a recurring target for attackers in the crypto space. Earlier this year, large ETH movements drew attention to Ethereum-linked infrastructure, though that case involved deliberate transfers rather than an exploit.

Why the ongoing status matters for users and observers

The use of “ongoing” in the initial report is significant. Active exploits mean that reported losses may rise before containment is achieved, and early figures are often revised as forensic analysis catches up to the attack.

Users interacting with the Verus-Ethereum bridge should exercise caution until official statements confirm whether the vulnerability has been patched. During active incidents, protocol teams typically pause bridge operations to prevent further drainage.

Incident details, including the root cause, affected wallet addresses, and recovery prospects, can change rapidly during an unfolding exploit. Readers should treat early numbers as provisional and watch for updates from the Verus project team directly.

Immediate security takeaways from the Verus-Ethereum incident

An eight-figure exploit on Ethereum-linked infrastructure is material for the broader ecosystem. Bridge exploits have historically ranked among the largest single-event losses in decentralized finance, and this incident adds to that pattern.

For Ethereum users and observers tracking institutional ETH exposure and crypto-related market activity, bridge security remains a critical infrastructure concern. The incident underscores the importance of auditing cross-chain mechanisms before committing significant capital.

No official post-mortem or confirmation of the attack method has been published as of this writing. Readers should monitor the Verus project’s official channels for verified updates on the exploit status, any fund recovery efforts, and bridge resumption timelines.

Additional source references: source document 1.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: next.verus.io
  • External Source - Referenced domain: duckduckgo.com
  • Byline - Reported by Joshua Trelawen
  • Coverage Desk - Primary editorial category: Ethereum
  • Media Asset - Featured image served from the WordPress media library