Between May 15–18, 2026, three separate DeFi exploits hit THORChain ( $10.7M), the Verus–Ethereum bridge ( $11.6M), and Echo Protocol (1,000 eBTC minted worth $76M but about $816K realized). The incidents were unrelated but collectively highlighted persistent risks in cross‑chain bridges, privileged key management,...

Create a landscape editorial hero image for this Studio Global article: What happened in the three DeFi exploits between May 15 and May 18, 2026 involving Echo Protocol, the Verus-Ethereum Bridge, and THORChain,. Article summary: Across May 15–18, 2026, the three incidents were not one coordinated hack but a cluster of failures in critical DeFi infrastructure: THORChain’s signing/vault layer, Verus’s bridge validation logic, and Echo Protocol’s a. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "Hillcrest Tennis Camp Opens 2026 Registration for Junior and Adult Programs in North York" source context "Crypto Hacks Shock THORChain, Verus & Echo | MEXC News" Reference image 2: visual subject "Best Music AI Websites For Songs And Soundtracks" source context "Crypto Hacks Shock THORChain, Verus & Echo | MEXC N
Between May 15 and May 18, 2026, three major decentralized finance (DeFi) exploits hit different parts of the crypto ecosystem: THORChain, the Verus–Ethereum bridge, and Echo Protocol.
Although they occurred within four days of each other, the incidents were not linked. Each exploited a completely different layer of DeFi infrastructure—validator signing systems, cross‑chain verification logic, and privileged administrative access. Together, they highlighted how vulnerabilities can exist not just in smart contracts but in the broader operational architecture that powers cross‑chain finance.
Across the three events, roughly $22 million was actually extracted, while a much larger $76+ million synthetic exposure briefly appeared in the Echo Protocol incident before most of the tokens were neutralized.
Estimated loss: about $10.7M–$10.8M in assets.
THORChain, a cross‑chain liquidity protocol used for native asset swaps across blockchains, halted trading and signing operations after suspicious outflows were detected from one of its Asgard vaults. Investigators soon confirmed that an attacker had drained approximately $10.7–$10.8 million in assets across multiple chains including Bitcoin, Ethereum, BNB Chain, and Base.
The exploit appears to have targeted the protocol’s GG20 threshold signature scheme (TSS) used for vault signing. Security researchers and protocol updates suggested that a malicious or compromised validator node may have exploited weaknesses in the multi‑party computation signing process, eventually allowing reconstruction of signing authority over vault funds.
Unlike many DeFi hacks, the losses were reported to involve protocol‑owned assets rather than user deposits or liquidity provider funds.
Protocol response
The incident renewed concerns about the security of MPC/TSS wallet systems, which are designed to distribute private key control but still depend on correct node behavior and implementation security.
Estimated loss: about $11.58M.
Three days later, attackers targeted the Verus–Ethereum cross‑chain bridge, draining approximately $11.5–$11.6 million in assets. Stolen funds included 103.6 tBTC, 1,625 ETH, and roughly 147,000 USDC, which were later swapped into ETH and consolidated into a single wallet.
Security researchers traced the exploit to a forged cross‑chain transfer message that the bridge incorrectly accepted as valid.
The root cause was a validation gap between the two sides of the bridge. Both the Verus chain and the Ethereum contract performed checks, but neither side enforced verification that the input transfer value actually matched the amount being released on the destination chain. This allowed the attacker to submit a valid‑looking proof while depositing almost no real value.
In effect, the attacker tricked the bridge into paying out assets that were never truly locked on the source chain.
Protocol response
The exploit resembled earlier bridge failures such as the Wormhole and Nomad hacks, reinforcing how bridges remain one of the highest‑risk components in DeFi infrastructure.
Headline exposure: about $76.6M–$76.7M in unauthorized eBTC.
Estimated realized loss: about $816,000.
Echo Protocol, a Bitcoin‑focused DeFi platform deployed on the Monad blockchain, suffered a critical breach after an attacker gained control of an administrative private key tied to its eBTC minting contracts.
With admin privileges, the attacker minted roughly 1,000 unauthorized eBTC, creating synthetic Bitcoin worth about $76–$77 million at market prices.
However, liquidity constraints prevented the attacker from extracting most of the value.
On‑chain analysis showed the exploiter:
Security reports estimate that the actual realized loss was about $816,000, far smaller than the headline mint value.
Protocol response
The breach highlighted governance risks when protocols rely on single administrative keys without safeguards such as multisig controls or timelocks.
Taken together, the three incidents exposed weaknesses in several layers of the DeFi stack.
The Verus exploit demonstrated how fragile cross‑chain verification can be. If a bridge does not enforce strict validation that a source‑chain event actually occurred and matches the destination payout, attackers can fabricate valid‑looking proofs and drain reserves.
Bridge exploits have repeatedly caused some of the largest losses in crypto because bridges often hold large pools of assets acting as collateral for multiple networks.
THORChain’s design uses threshold signatures and multi‑party computation to prevent any single node from controlling vault funds. Yet the exploit showed that if node admission rules, validator behavior, or the TSS implementation itself fail, attackers can still compromise the signing layer.
Decentralized custody systems reduce risk compared with single private keys, but they introduce new attack surfaces in validator coordination and protocol governance.
The Echo Protocol exploit illustrated the dangers of centralized administrative control in otherwise decentralized systems. A compromised admin key allowed an attacker to mint tens of millions in synthetic assets instantly.
Even though most of the tokens were later burned, the incident showed how quickly privileged access can destabilize DeFi markets.
In all three cases, the protocols relied on rapid intervention:
These actions prevented larger losses but also highlight an uncomfortable reality: many DeFi systems still depend on centralized emergency responses during crises.
The May 2026 exploit cluster demonstrated that DeFi security is no longer just about smart‑contract bugs. The most serious vulnerabilities now often appear in operational infrastructure:
As DeFi continues expanding across multiple chains and protocols, these infrastructure layers—not just Solidity code—are increasingly where the next major exploits are likely to occur.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Between May 15–18, 2026, three separate DeFi exploits hit THORChain ( $10.7M), the Verus–Ethereum bridge ( $11.6M), and Echo Protocol (1,000 eBTC minted worth $76M but about $816K realized).
Between May 15–18, 2026, three separate DeFi exploits hit THORChain ( $10.7M), the Verus–Ethereum bridge ( $11.6M), and Echo Protocol (1,000 eBTC minted worth $76M but about $816K realized). The incidents were unrelated but collectively highlighted persistent risks in cross‑chain bridges, privileged key management, and validator governance across DeFi infrastructure.
Emergency halts, paused markets, and token burns limited further losses, but the attacks showed how quickly systemic weaknesses can cascade across interconnected DeFi systems.