Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Warsh, Warren, and Bitcoin’s $80K Wall
    Warsh, Warren, and Bitcoin’s $80K Wall: Three Forces Shaping Crypto’s Summer
    Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    Exclusive: Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    CLARITY Act Markup Vote Today
    CLARITY Act Timeline: From 15-9 Senate Win to July 4 Signing, Here Is Every Step Ahead
    US Inflation Hits 3.8% Here's the Exact Crypto Playbook Smart Money Is Using to Hedge It
    US Inflation Hits 3.8%: Here’s the Exact Crypto Playbook Smart Money Is Using to Hedge It
    Terra Luna Crash $60 Billion Lost, Do Kwon Jailed, Wall Street Sued
    The $60B Ghost: Four Years After Terra Luna’s Collapse, Do Kwon Is in Prison, and Wall Street Faces a Reckoning
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Chainalysis Traces THORChain Hacker’s Pre-Attack Monero-Hyperliquid Trail

Chainalysis linked the THORChain attacker to a weeks-long laundering setup involving Monero, Hyperliquid, and Arbitrum, while investigators suspect a flaw in THORChain’s GG20 signature scheme enabled the $10.8 million exploit.

Written By:
Dishita Malvania

Last updated: 13 minutes ago
Published 13 minutes ago
Share
Last updated: 13 minutes ago
Published 13 minutes ago
Chainalysis Traces THORChain Hacker’s Pre-Attack Monero-Hyperliquid Trail
Show AI Summary
Blockchain analytics firm Chainalysis uncovers a sophisticated cross-chain laundering operation with significant implications for the cryptocurrency industry
The operation highlights the increasing use of privacy-focused routes and bridges to move funds across multiple chains, posing challenges for tracking and regulation
The $10.8 million theft from THORChain serves as a high-profile example of the vulnerabilities in cross-chain transactions and the need for enhanced security measures

Blockchain analytics firm Chainalysis has mapped weeks of on-chain activity linking the THORChain attacker to a calculated cross-chain laundering operation involving Monero, Hyperliquid, and Arbitrum, all set up well before the $10.8 million theft.

Chainalysis shared its findings on X on Friday, revealing that wallets likely connected to the attacker spent weeks moving personal funds through privacy-focused routes before executing the exploit. The on-chain trail ties those wallets directly to the address that later received millions in stolen funds.

Monero was the starting point

According to Chainalysis, the operation began in late April when an attacker-linked wallet funded a position on Hyperliquid by depositing XMR through a Hyperliquid-Monero privacy bridge. That position was then swapped for USDC, withdrawn to Arbitrum, and bridged over to Ethereum.

From Ethereum, hundreds of thousands of dollars worth of ETH were bridged into THORChain to bond RUNE for a newly churned validator node. This node is currently believed to be the source of the compromise. Some of the RUNE was then bridged back into ETH.

Direct wallet link to the attacker

Chainalysis said the bridged ETH was split into four branches. One of those branches connects directly to the attacker. It first passed through an intermediary wallet, and then, just 43 minutes before the theft, it was forwarded 8 ETH into the wallet where the attacker would shortly receive millions of dollars worth of stolen funds.

The other three branches ran funds in the opposite direction. On May 14 and 15, those wallets bridged ETH to Arbitrum, deposited into Hyperliquid, and then routed back to Monero using the same privacy bridge from the initial setup. The last of those transactions landed less than five hours before the attack began.

Stolen funds remain dormant, but the exit path is clear

As of Friday afternoon, the stolen funds are sitting dormant. But Chainalysis warned that this could change quickly. The attacker has already demonstrated the ability to execute a sophisticated cross-chain laundering operation, and the same Hyperliquid-to-Monero path observed in the days leading up to the theft remains one possible next move.

What we know so far about the THORChain exploit

The Chainalysis findings add a new forensic layer to an incident that has been unfolding since May 15. THORChain contributors said in an incident update on Friday that the leading theory points to a vulnerability in the protocol’s GG20 threshold signature scheme (TSS). 

Investigators believe a newly churned validator node exploited this weakness, allowing sensitive key material to leak over time. With enough fragments exposed, the attacker could have reconstructed a vault private key and authorized unauthorized outbound transactions.

The node in question, identified as thor16ucjv3v695mq283me7esh0wdhajjalengcn84q, joined the active validator set several days before the incident. Ethereum addresses used to acquire and bond RUNE for that node appear connected to addresses that later received stolen funds, according to THORChain developers.

The network remains partially paused. Trading, liquidity provider actions, and transaction signing are suspended while node operators discuss recovery options, including slashing the bonds of affected vault participants and tapping protocol-owned liquidity (POL) to cover losses. Contributors have cautioned that a full restart may take several days.

The exploit was first reported on May 15 when security firms Cyvers and on-chain investigators flagged suspicious outbound transactions across Bitcoin, Ethereum, BNB Chain, and Base. Initial estimates placed the total loss at approximately $10.8 million, with stolen assets consolidated into wallets holding ETH, BTC, and BNB. 

THORChain’s treasury team is working with THORSec, Outrider Analytics, and law enforcement agencies to identify the attacker and recover what it can.

Also Read: How Hackers Drained $132K From ShapeShift FOX Colony in One Transaction

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Dishita Malvania - Senior crypto journalist at The Crypto Times
By Dishita Malvania
Follow:
Dishita Malvania is a Crypto Journalist with 3 years of experience covering the evolving landscape of blockchain, Web3, AI, finance, and B2B tech. With a background in Computer Science and Digital Media, she blends technical knowledge with sharp editorial insight. Dishita reports on key developments in the crypto world—including Litecoin, WazirX, Solana, Cardano, and broader blockchain trends—alongside interviews with notable figures in the space. Her work has been referenced by top digital media outlets like Entrepreneur.com, The Independent, The Verge, and Metro.co, especially on trending topics like Elon Musk, memecoins, Trump, and notable rug pulls.

Latest News

Bitcoin ETFs Post $1B Weekly Outflow, Halting Six-Week Inflow Streak
Bitcoin ETFs Post $1B Weekly Outflow, Halting Six-Week Inflow Streak
House Ag to Trump Fill 4 Vacant CFTC Seats Before Crypto Market Structure Rollout
House Ag to Trump: Fill 4 Vacant CFTC Seats Before Crypto Market Structure Rollout
Bitcoin Sees Major Spike in Euphoria Across Social Media_
Bitcoin Sees Major Spike in Euphoria Across Social Media
THORChain Incident Update Malicious Node and GG20 TSS Exploit Suspected
THORChain Incident Update: Malicious Node and GG20 TSS Exploit Suspected
Terrorism Victims Ask Court to Force Tether to Release $344M Frozen USDT
Terrorism Victims Ask Court to Force Tether to Release $344M Frozen USDT

Find Us on Socials

You may also like

Buybacks, Burns, and Bonds CoW DAO Proposes New Plan for COW

Buybacks, Burns, and Bonds: CoW DAO Proposes New Plan for COW

How Hackers Drained $132K From ShapeShift FOX Colony in One Transaction

How Hackers Drained $132K From ShapeShift FOX Colony in One Transaction

THORChain Halts After $10.8M Multi-Chain Exploit Hits Router

THORChain Halts After $10.8M Multi-Chain Exploit Hits Router

Ranger Finance Winds Down Following Drift Exploit and Funding Crisis

Ranger Finance Winds Down Following Drift Exploit and Funding Crisis

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information