$32M Lost in 4 Days: THORChain, Verus Bridge, Echo Protocol Hacked

$32M Lost in 4 Days: THORChain, Verus Bridge, Echo Protocol Hacked

N
News Editor 01
2026-07-24 00:20:16
Between May 15 and May 19, 2026, three DeFi platforms—THORChain, the Verus-Ethereum Bridge, and Echo Protocol—were exploited, losing over $32 million combined.
hackTHORChainVerus BridgeEcho ProtocolDeFi security

Between May 15 and May 19, 2026, three separate crypto hacks hit THORChain, the Verus-Ethereum Bridge, and Echo Protocol. Total losses exceeded $32 million in just 96 hours, raising fresh concerns about DeFi security.

THORChain Loses $10.8M via GG20 Signature Flaw

On May 15, attackers drained $10.8 million from THORChain across at least nine chains, including Bitcoin, Ethereum, BNB Chain, and Base. On-chain detective ZachXBT flagged the incident on Telegram. PeckShield confirmed the theft of 36.75 BTC (worth ~$3M) and about $7M in ETH, BNB Chain, and Base assets. Arkham Intelligence labeled the attacker's wallets as 'THORChain Exploiter.' The protocol froze all trading and signing within hours; its native token RUNE dropped 14%. THORChain contributors on Discord attributed the breach to a vulnerability in the GG20 signature scheme, exploited by a malicious node operator.

Verus-Ethereum Bridge Exploited for $11.58M via Forged Transfer

On May 18, the Verus-Ethereum Bridge was compromised. The attacker submitted a forged transfer with zero real value on the Verus side; the bridge verified the proof and paid out real assets. Losses totaled $11.58 million in 103.6 tBTC, 1,625 ETH, and 147,000 USDC, later swapped to 5,402 ETH (~$11.4M). Security firm Blockaid detected it in real time. The attacker funded the wallet with 1 ETH via Tornado Cash 14 hours prior and paid only ~$10 in VRSC fees. Eight of fifteen notaries signed the fraudulent state root, exposing a verification gap similar to the 2022 Wormhole and Nomad exploits.

Echo Protocol Hit via Curvance: $76.64M eBTC Mint, $821K Actual Loss

On May 19, Echo Protocol was exploited through its integrated lending platform Curvance. The attacker minted 1,000 eBTC (nominal value $76.64M), deposited 45 eBTC as collateral ($3.4M), borrowed 11.29 WBTC ($866K), and used Circle CCTP to receive $360,526 USDC. Ultimately, about 385 ETH ($821,000) was extracted as real losses. The fabricated eBTC position allowed the hacker to drain genuine funds.

Pattern: Infrastructure Protocols Are the Prime Target

All three attacks targeted bridges, cross-chain routers, and lending protocols—not individual wallets. PeckShield tracked eight bridge exploits in the first half of May 2026, totaling $328.6 million. Bridge-related losses now account for roughly 41% of all tracked DeFi exploit losses, according to AMBCrypto. Users are advised to verify protocol audits, avoid large bridges during exploit waves, and monitor positions on Etherscan or Arkham Intelligence.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.