Between May 15 and May 19, 2026, three separate crypto hacks hit THORChain, the Verus-Ethereum Bridge, and Echo Protocol. Total losses exceeded $32 million in just 96 hours, raising fresh concerns about DeFi security.
THORChain Loses $10.8M via GG20 Signature Flaw
On May 15, attackers drained $10.8 million from THORChain across at least nine chains, including Bitcoin, Ethereum, BNB Chain, and Base. On-chain detective ZachXBT flagged the incident on Telegram. PeckShield confirmed the theft of 36.75 BTC (worth ~$3M) and about $7M in ETH, BNB Chain, and Base assets. Arkham Intelligence labeled the attacker's wallets as 'THORChain Exploiter.' The protocol froze all trading and signing within hours; its native token RUNE dropped 14%. THORChain contributors on Discord attributed the breach to a vulnerability in the GG20 signature scheme, exploited by a malicious node operator.
Verus-Ethereum Bridge Exploited for $11.58M via Forged Transfer
On May 18, the Verus-Ethereum Bridge was compromised. The attacker submitted a forged transfer with zero real value on the Verus side; the bridge verified the proof and paid out real assets. Losses totaled $11.58 million in 103.6 tBTC, 1,625 ETH, and 147,000 USDC, later swapped to 5,402 ETH (~$11.4M). Security firm Blockaid detected it in real time. The attacker funded the wallet with 1 ETH via Tornado Cash 14 hours prior and paid only ~$10 in VRSC fees. Eight of fifteen notaries signed the fraudulent state root, exposing a verification gap similar to the 2022 Wormhole and Nomad exploits.
Echo Protocol Hit via Curvance: $76.64M eBTC Mint, $821K Actual Loss
On May 19, Echo Protocol was exploited through its integrated lending platform Curvance. The attacker minted 1,000 eBTC (nominal value $76.64M), deposited 45 eBTC as collateral ($3.4M), borrowed 11.29 WBTC ($866K), and used Circle CCTP to receive $360,526 USDC. Ultimately, about 385 ETH ($821,000) was extracted as real losses. The fabricated eBTC position allowed the hacker to drain genuine funds.
Pattern: Infrastructure Protocols Are the Prime Target
All three attacks targeted bridges, cross-chain routers, and lending protocols—not individual wallets. PeckShield tracked eight bridge exploits in the first half of May 2026, totaling $328.6 million. Bridge-related losses now account for roughly 41% of all tracked DeFi exploit losses, according to AMBCrypto. Users are advised to verify protocol audits, avoid large bridges during exploit waves, and monitor positions on Etherscan or Arkham Intelligence.

