source avatarDavid Arnal

Share

THE MAY HACKS ARE STILL ONGOING May 2026 continued to see multiple exploits targeting cross-chain bridges and DeFi protocols, with the Verus-Ethereum bridge and THORChain being the most prominent examples. 1. Verus-Ethereum Bridge Hack (May 18, 2026) - Damage: Approximately $11.58 – $11.6 million. Assets drained: 103.6 BTC, 1,625 ETH, ~147,000 USDC (later swapped to ~5,402 ETH). - Mechanism: Attacker forged cross-chain transfer messages and exploited validation vulnerabilities on the bridge. Due to insufficient verification checks, the bridge automatically transferred assets from the reserve to the attacker's wallet. - Status: The exploit was still active when discovered by Blockaid and PeckShield. The attacker had prepared via Tornado Cash several hours earlier. 2. THORChain (THORSwap/Asgard Vault) Exploit (May 15, 2026) - Damage: Approximately $10 – $10.8 million (some initial reports ~$7.4 million, later updated higher). - Assets: 36.75 BTC (~$3 million) + ~$7 million in EVM tokens (USDT, USDC, WBTC, DAI… on Ethereum, BSC, Base, Avalanche, DOGE, Litecoin, Bitcoin Cash, XRP). - Mechanism: A malicious node (recently churned) exploited Asgard vaults and executed unauthorized outbound transactions on at least 9 chains simultaneously. Suspected involvement of the threshold signature scheme (GG20). - Status: THORChain immediately halted trading to protect remaining vaults. The team confirmed the exploit and opened a compensation portal for victims (not all losses). RUNE plummeted ~12-15%. => This is THORChain's second major incident of the year (following a smaller incident in 2025). 3. Other minor hacks in May 2026 (according to DefiLlama hacks database) *These cases are smaller but still noteworthy due to their continuous occurrence: - TrustedVolumes (May 7): ~$6.7 million – Forged RFQ orders (protocol logic). - Ekubo (May 5): $1.4 million – Improper access control. - Renegade (May 10): $209K – Unprotected initializer. - INK Finance (May 11): $140K – Whitelisted address impersonation. - SmartCredit (May 4): $72K – Flashloan exploit. - SharwaFinance (May 1): ~$33K – Oracle price manipulation. => Most recent cases exploit bridge/cross-chain messaging (forged messages, validation bypass) or operational compromise (malicious nodes, social engineering). Bridges remain a "critical weak point" of DeFi. => Everyone should be extremely careful when using bridges!

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.