Altcoins News

Story: Verus Bridge Hacker Returns $8.5M in Ethereum, Pockets Self-Awarded Bounty

By Sakamoto Nashi

1 / 15

What Actually Happened at the Verus Bridge. Verus is a DeFi protocol with a cross-chain bridge — the kind of infrastructure that lets users…

2 / 15

The Bounty Question and What It Means for DeFi Security. Here's where it gets complicated. Legitimate bug bounty programs exist across the DeFi space —…

3 / 15

The Verus bridge attacker gave back $8.5 million in Ethereum. Kept a cut for themselves. That kind of move doesn't happen often in crypto.

4 / 15

The exploit drained millions from the Verus bridge before the attacker made the surprising call to send most of it back. No court order. No law enforcement seizure.

5 / 15

Verus is a DeFi protocol with a cross-chain bridge — the kind of infrastructure that lets users move assets between different blockchain networks.

6 / 15

The attacker found the vulnerability, exploited it, took the funds, and then — apparently — decided to hand most of it back.

7 / 15

What's confirmed: $8.5 million in ETH came back. A bounty portion did not.

8 / 15

Here's where it gets complicated. Legitimate bug bounty programs exist across the DeFi space — protocols offer rewards to white-hat researchers who find and responsibly disclose…

9 / 15

See also: Andreessen Horowitz-Backed Syndicate Labs Shuts Down After 5 Years as Rollup Demand Collapses

10 / 15

But that's not what happened here. The attacker didn't report the bug. They exploited it, took the funds, and then effectively negotiated their own bounty on the way out.

11 / 15

And yet — the funds came back. Most of them, anyway. For the users and liquidity providers who had assets sitting in that bridge, that's better than the alternative.

12 / 15

The broader DeFi community's reaction has been split. Some see the return as a net positive — attacker showed some restraint, most funds are safe, move on.

13 / 15

See also: Frances Crypto Kidnapping Crisis Puts The Sandbox Co-Founders Family at Risk

14 / 15

That silence is its own problem. When a protocol gets hit and funds are returned, stakeholders — liquidity providers, bridge users, token holders — need to know what happened,…

15 / 15

DeFi bridge security has been a known weak point for years. Audits help, but they don't catch everything.

The Currency Analytics

Want the full story?