CryptoVerus bridge attacker sends back $8.5M, keeps bounty

Verus bridge attacker sends back $8.5M, keeps bounty

-


The Verus Ethereum bridge exploiter has returned 4,052 ETH to the project team after a settlement offer, while keeping 1,350 ETH as a bounty.

Summary

  • PeckShield says the Verus bridge exploiter returned 4,052 ETH, equal to 75% of stolen funds.
  • The exploiter kept 1,350 ETH as a bounty after Verus proposed settlement terms publicly.
  • Earlier reports linked the Verus bridge exploit to missing validation checks in cross-chain transfer logic.

PeckShield said the Verus bridge exploiter returned 4,052.4 ETH, worth about $8.5 million, to a Verus team address. The firm said the returned assets represented 75% of the stolen total.

Etherscan data shows a successful transfer of 4,052 ETH from a wallet labeled Verus Exploiter 2 to the address 0xF9AB…C1A74 on May 21. The transaction was valued at about $8.59 million at the ETH price shown by the explorer.

PeckShield said the remaining 25% stayed with the exploiter as a bounty. A separate Etherscan transaction shows 1,350 ETH, worth about $2.86 million, moved from the exploiter wallet to a new address minutes after the return transfer.

Verus bridge attacker sends back $8.5M, keeps bounty - 2
Source: Etherscan

Some X users framed the recovery as a win for negotiated returns. Bee Swarm said “75% recovery is the new standard” and argued that bounty deals can work better than legal threats after funds are gone.

Others said the exploit still points to deeper bridge risks. Zenthis argued that partial recovery does not fix “centralized custody in bridges,” while pointing to atomic swaps as an alternative.

Bounty offer followed public Verus terms

Verus had earlier posted a message to the bridge exploiter, saying its community and developers had discussed terms for the fund return. The post said the terms covered the bounty size, the exploiter’s obligations, and how the assets could be returned.

According to the public Verus message from X, the community had agreed to a 1,350 ETH bounty. The offer was tied to returning the remaining funds and settling the matter under the proposed terms.

The return now makes the Verus case different from many bridge attacks, where stolen funds often move through mixers or remain under attacker control. In this case, most of the drained ETH moved back to a team address after the bounty offer.

Earlier exploit drained $11.5M

The fund return follows the May 18 Verus Ethereum bridge attack. Earlier coverage reported that the bridge lost more than $11.5 million after attackers used what security researchers described as a forged cross-chain transfer message.

PeckShield had reported that the drained assets included 103.6 tBTC, 1,625 ETH, and nearly 147,000 USDC. The attacker later swapped the stolen assets into 5,402 ETH, worth about $11.4 million at the time.

Blockaid linked the exploit to missing source-amount validation inside the bridge logic. The firm said the issue was not an ECDSA bypass, not a notary key compromise, and not a parser or hash-binding bug.

Bridge security remains under pressure

The Verus recovery comes during a busy period for cross-chain security incidents. Recent coverage said MAPO fell 96% after attackers exploited the Butter Network bridge and minted a huge amount of unauthorized tokens.

Echo Protocol also paused cross-chain activity after an attacker minted about $76.7 million in unauthorized eBTC on Monad. On-chain investigators said the exploiter used fake eBTC as collateral before moving funds through Tornado Cash.

These cases show why bridge validation remains a core risk for DeFi. Bridges hold assets across chains, so weak checks can allow attackers to trigger transfers, mint tokens, or move reserves before teams can stop the flow.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

Ethereum Layer 2 Zero Network to Cease Operations After 1.5 Years

Zero Network, the gasless Ethereum Layer 2 blockchain built by crypto wallet company Zerion, is shutting down —...

Razer Viper V4 Pro Review: Iterative Update Packs Big Performance

While a 5-gram reduction in weight may sound minor, the improvements were immediately noticeable, leading to quick, snappy...

US Lawmakers Introduce ARMA Bill to Codify Strategic Bitcoin Reserve With 20-Year Hold and 1M BTC Goal

Key TakeawaysThe ARMA bill, backed by 14+ congressmen, aims for a 1M BTC federal reserve with a 20-year...

Finnish phone-maker HMD bundles Indian AI chatbot onto new smartphone in push to reach local market

Finnish phone maker HMD today launched its first smartphone, called the Vibe 2 5G, which comes preloaded with...

Advertisement

Bali Crypto Event Coinfest Asia Announces 2026 Expansion Across Melasti Beach Clubs

Indonesia Crypto Network (ICN) announced that the fifth annual Coinfest Asia crypto festival will take place on August...

Crypto Traders Brace for $1.5B Bitcoin Options Expiry Today

The end of the week is upon us again, with another crypto options expiry event as spot markets...

Must read

Ethereum Layer 2 Zero Network to Cease Operations After 1.5 Years

Zero Network, the gasless Ethereum Layer 2 blockchain...

Razer Viper V4 Pro Review: Iterative Update Packs Big Performance

While a 5-gram reduction in weight may sound...

You might also likeRELATED
Recommended to you