The attacker tied to the Verus Ethereum cross-chain bridge exploit has returned 4,052 ETH, valued in the report at about $8.5 million, equal to 75% of the original 5,402 ETH taken from the protocol. Verus said it would accept the settlement, drop legal action, and classify the remaining 1,350 ETH as a white-hat bounty.
Returned funds moved in batches on-chain
On-chain data cited in the report shows the recovered ETH was sent in batches from the attacker-controlled address to a wallet designated by Verus. Full negotiation details were not disclosed, but community discussion has largely framed the outcome as a bounty-style resolution centered on vulnerability disclosure. In a public statement on social platforms, the attacker said the action was not intended as simple theft and was meant to push the protocol to take security issues more seriously.
Settlement draws split reaction inside the community
Verus chose to accept the arrangement and regard the unrecovered 1,350 ETH, estimated in the report at roughly $2.8 million, as payment for discovering and revealing the flaw. That decision drew sharply different responses. Some community members described the outcome as a practical way to recover most of the funds and avoid a prolonged legal fight. Others argued it risks rewarding a “hack first, negotiate later” pattern by allowing an attacker to keep a large payout and walk away without prosecution.
Verus joins a list of bridge cases resolved through negotiation
The article places the incident alongside earlier bridge exploits. THORChain, attacked in July 2021, saw most funds returned after public outreach from the protocol and the attacker received a 10% bounty. Poly Network, hit in August 2021 for $610 million, also ended with nearly all funds returned and no lawsuit filed. The report contrasts those cases with Wormhole, which lost $320 million in early 2022, and Ronin, which lost $620 million. Those incidents followed very different paths, showing that negotiated recoveries depend heavily on the attacker’s identity and motives.
Protocol says bridge security upgrades are coming
Verus co-founder Michael J. Toutonghi said the team learned important lessons from the exploit and plans to strengthen the security of its bridge contracts. He also said the protocol is considering a more complete bug bounty setup so white-hat researchers can report vulnerabilities before an attack takes place. As of publication, the Verus cross-chain bridge had resumed normal operations and user funds were reported safe.

