Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    From BitMEX to Leap Wallet 100+ Crypto Projects Have Shut Down in H1 2026
    From BitMEX to Leap Wallet: 100+ Crypto Projects Have Shut Down in H1 2026
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Chainalysis Traces THORChain Hacker’s Pre-Attack Monero-Hyperliquid Trail

Chainalysis linked the THORChain attacker to a weeks-long laundering setup involving Monero, Hyperliquid, and Arbitrum, while investigators suspect a flaw in THORChain’s GG20 signature scheme enabled the $10.8 million exploit.

Written By Dishita Malvania
Published 2026-05-16·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Chainalysis Traces THORChain Hacker’s Pre-Attack Monero-Hyperliquid Trail_
AI-generated visual for illustration purposes only
Show AI Summary
Blockchain analytics firm Chainalysis uncovers a sophisticated cross-chain laundering operation with significant implications for the cryptocurrency industry
The operation highlights the increasing use of privacy-focused routes and bridges to move funds across multiple chains, posing challenges for tracking and regulation
The $10.8 million theft from THORChain serves as a high-profile example of the vulnerabilities in cross-chain transactions and the need for enhanced security measures

Blockchain analytics firm Chainalysis has mapped weeks of on-chain activity linking the THORChain attacker to a calculated cross-chain laundering operation involving Monero, Hyperliquid, and Arbitrum, all set up well before the $10.8 million theft.

Chainalysis shared its findings on X on Friday, revealing that wallets likely connected to the attacker spent weeks moving personal funds through privacy-focused routes before executing the exploit. The on-chain trail ties those wallets directly to the address that later received millions in stolen funds.

Monero was the starting point

According to Chainalysis, the operation began in late April when an attacker-linked wallet funded a position on Hyperliquid by depositing XMR through a Hyperliquid-Monero privacy bridge. That position was then swapped for USDC, withdrawn to Arbitrum, and bridged over to Ethereum.

From Ethereum, hundreds of thousands of dollars worth of ETH were bridged into THORChain to bond RUNE for a newly churned validator node. This node is currently believed to be the source of the compromise. Some of the RUNE was then bridged back into ETH.

Direct wallet link to the attacker

Chainalysis said the bridged ETH was split into four branches. One of those branches connects directly to the attacker. It first passed through an intermediary wallet, and then, just 43 minutes before the theft, it was forwarded 8 ETH into the wallet where the attacker would shortly receive millions of dollars worth of stolen funds.

The other three branches ran funds in the opposite direction. On May 14 and 15, those wallets bridged ETH to Arbitrum, deposited into Hyperliquid, and then routed back to Monero using the same privacy bridge from the initial setup. The last of those transactions landed less than five hours before the attack began.

Stolen funds remain dormant, but the exit path is clear

As of Friday afternoon, the stolen funds are sitting dormant. But Chainalysis warned that this could change quickly. The attacker has already demonstrated the ability to execute a sophisticated cross-chain laundering operation, and the same Hyperliquid-to-Monero path observed in the days leading up to the theft remains one possible next move.

What we know so far about the THORChain exploit

The Chainalysis findings add a new forensic layer to an incident that has been unfolding since May 15. THORChain contributors said in an incident update on Friday that the leading theory points to a vulnerability in the protocol’s GG20 threshold signature scheme (TSS). 

Investigators believe a newly churned validator node exploited this weakness, allowing sensitive key material to leak over time. With enough fragments exposed, the attacker could have reconstructed a vault private key and authorized unauthorized outbound transactions.

The node in question, identified as thor16ucjv3v695mq283me7esh0wdhajjalengcn84q, joined the active validator set several days before the incident. Ethereum addresses used to acquire and bond RUNE for that node appear connected to addresses that later received stolen funds, according to THORChain developers.

The network remains partially paused. Trading, liquidity provider actions, and transaction signing are suspended while node operators discuss recovery options, including slashing the bonds of affected vault participants and tapping protocol-owned liquidity (POL) to cover losses. Contributors have cautioned that a full restart may take several days.

The exploit was first reported on May 15 when security firms Cyvers and on-chain investigators flagged suspicious outbound transactions across Bitcoin, Ethereum, BNB Chain, and Base. Initial estimates placed the total loss at approximately $10.8 million, with stolen assets consolidated into wallets holding ETH, BTC, and BNB. 

THORChain’s treasury team is working with THORSec, Outrider Analytics, and law enforcement agencies to identify the attacker and recover what it can.

Also Read: How Hackers Drained $132K From ShapeShift FOX Colony in One Transaction

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto HackHyperliquid (HYPE)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Pi Network Upgrades to Protocol v26, Pushes Nodes to Update
Pi Network Upgrades to Protocol v26, Pushes Nodes to Update
OCC Clears Trump-Backed World Liberty Trust Bank to Take Over USD1 From BitGo
OCC Clears Trump-Backed World Liberty Trust Bank to Take Over USD1 From BitGo
Bitcoin Price Analysis: Early Bottom Signals Emerge as BTC Trades Near $63,000
Bitcoin Price Holds Near $63,000 as Early Bottom Signals Emerge
Trump, SEC, CFTC, Coinbase, Ripple Expected at White House Crypto Meeting
Trump, SEC, CFTC, Coinbase, Ripple Expected at White House Crypto Meeting
Galaxy Cuts CLARITY Act Passage Odds to 10% as Senate Delays Vote
Galaxy Cuts CLARITY Act Passage Odds to 10% as Senate Delays Vote

Find Us on Socials

You may also like

Walix Wallet Hack Over $1M in Stolen Crypto Traced to Xhash

Walix Wallet Hack: Over $1M in Stolen Crypto Traced to Xhash

Galaxy Claims Coldcard Attacks Halt After Aug 6

Galaxy Claims Coldcard Attacks Halt After Aug 6

Derive Opens XRP Derivatives Trading Through Flare’s FXRP

Derive Opens XRP Derivatives Trading Through Flare’s FXRP

Hyperliquid Users Lose $550K in Alleged Phishing Attack Via Google Ads

Hyperliquid Users Lose $550K in Alleged Phishing Attack Via Google Ads

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information