A bridge between Verus and Ethereum has been exploited for more than $11 million, according to Protos. The incident is one of eight bridge hacks in 2026, bringing total funds lost across cross-chain protocols to almost $329 million, Protos reports.

The latest victim is Verus, a blockchain DeFiLlama ranks as the 58th-largest by total value locked at about $22 million. Protos adds that Verus’ own website markets “security without the audits,” a line that lands awkwardly after another bridge failure.

What happened

Verus’ blockchain explorer showed block production stopping about 12 hours before Protos’ report went to press. In a screenshot shared by the Verus X account, the network halt is attributed to “most block-generating nodes taking themselves offline” following the attack, Protos says.

Blockchain security firm Blockaid flagged the ongoing exploit, Protos reports. Blockaid’s monitoring alleges roughly $11.58 million has been drained so far and points to the Verus–Ethereum bridge (as referenced in the Blockaid post linked by Protos).

Blockaid also suspects the underlying flaw resembles bugs from the 2022 Wormhole and Nomad bridge hacks, Protos writes. Blockaid’s explanation is specific. It says three verification steps completed correctly. The failure came from not checking whether source-chain transaction parameters matched the payouts on Ethereum, enabling the exploit to move funds.

Blockaid estimates the attacker spent just $10 to exploit the vulnerability and that the fix could be implemented with roughly 10 lines of code, Protos reports.

Why it matters

Bridges keep getting hit because they sit at the intersection of two trust models. Protos notes that in 2022, the headline bridge disasters were dominated by smart contract exploits, including Wormhole, Nomad, Ronin, Harmony, and others. In later years, attackers shifted toward “new vectors” like social engineering and supply-chain compromises, Protos says, citing Lazarus Group-linked schemes.

This Verus case again points at bridge-specific verification logic. Blockaid’s description focuses on a mismatch between source-chain transaction parameters and Ethereum payouts. That is the kind of bug that can pass superficial checks while still allowing value to be released on the destination chain.

Protos also frames the monitoring angle. Blockaid’s alert suggests real-time exploit detection is becoming a critical line of defense, not just a post-mortem tool.

Market impact

The incident adds to a 2026 tally that Protos attributes to Peckshield estimates. Peckshield puts 2026 bridge-hack losses at almost $329 million, Protos reports. In mid-May 2026, Protos says there have been eight major bridge-related exploits with a cumulative $328.6 million exfiltrated from cross-chain protocols.

The biggest part of that total is not this Verus event. Protos says April’s $290 million rsETH hack drove much of the sector’s damage. That context matters because bridge hacks can cascade into wider DeFi exposure when collateral, liquidity, or accounting depend on the compromised asset flows.

What to watch next

Two timelines will matter: whether Verus resumes normal block production and whether responders can fully confirm the exploit path and stolen assets.

Protos notes that the hacker address on Ethereum received ETH, plus tBTC and USDC. Those tokens were reportedly swapped to ETH, Protos says. That makes post-theft tracking and exchange/bridge controls the next practical step, even if the destination-chain activity is already underway.

Protos also points readers to its bridge-hack tracking context, noting 79 entries since the beginning of 2026.

Selected 2026 bridge-related incidents mentioned by Protos

Date (2026)IncidentLoss amountNotes from Protos
AprilrsETH hack$290MFallout affected much of DeFi, Protos says
AprilVerus–Ethereum bridge exploit~$11MExploit flagged by Blockaid, Protos says
(Not dated in text)Hyperbridge$2.5MLoss came days after “joking about being hacked” for April Fools’ Day, Protos says
Friday (before report)THORChain hack$10MProtos says THORChain has faced criticism for inaction over illicit fund laundering concerns