Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    MiCA's July 1 Deadline What It Means for Your Crypto in Europe
    MiCA’s July 1 Deadline: What It Means for Your Crypto in Europe
    STRC Drops 19% Below Par Was Peter Schiff Right About Saylor Deceiving Investors
    STRC Drops 19% Below Par: Was Peter Schiff Right About Saylor Deceiving Investors?
    Litecoin Summit Day 2 LitVM's $50M Bet and BasicSwapDEX's Bold Vision
    Litecoin Summit Day 2: LitVM’s $50M Bet and BasicSwapDEX’s Bold Vision
    Litecoin Summit Day 1 Quantum Warnings, Privacy Coin Breakthroughs, & MiCA's Looming Deadline
    Litecoin Summit Day 1: Quantum Warnings, Privacy Coin Breakthroughs, & MiCA’s Looming Deadline
    Inside the High-Stakes Corporate War Over the GENIUS Act
    Inside the High-Stakes Corporate War Over the GENIUS Act
  • Opinion
    OpinionShow More
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

THORChain Incident Update: Malicious Node and GG20 TSS Exploit Suspected

The network remains partially paused as node operators debate slashing bonds, using protocol-owned liquidity, and other options to cover losses.

Written By Shubham Soni Shubham Soni
Published 2026-05-16·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Share
THORChain Incident Update Malicious Node and GG20 TSS Exploit Suspected
Show AI Summary
A vulnerability in THORChain’s threshold signature scheme likely led to a $10.8 million exploit, highlighting security risks in cross-chain liquidity protocols.
The incident underscores the importance of robust validator node vetting, as a newly added node is suspected to be linked to the exploit, potentially due to inadequate screening.
The partial network pause and ongoing investigation underscore the challenges of maintaining security and trust in decentralized networks, impacting the broader cryptocurrency industry.

THORChain contributors say current evidence points to a newly churned validator node as the likely source of the exploit that drained roughly $10.8 million from the cross-chain liquidity protocol.

In an incident update shared via X on Friday, developers said the leading theory is that the attacker exploited a vulnerability in THORChain’s GG20 threshold signature scheme (TSS), allowing sensitive key material to leak over time. Investigators believe the attacker used that information to reconstruct a vault private key and authorize unauthorized outbound transactions.

THORChain incident update #1
THORChain contributors shared a new update in the dev discord regarding the ongoing incident.

TLDR
– Current evidence points toward a newly churned node linked to the attack, likely operated by a single malicious actor

– The leading theory is an…

— THORChain (@THORChain) May 15, 2026

The network remains partially paused while developers, security contributors, and node operators determine how to restore normal operations and absorb the losses.

Newly added validator under scrutiny

According to the update, a node identified as thor16ucjv3v695mq283me7esh0wdhajjalengcn84q, which joined the active validator set several days before the incident, is believed to be linked to the exploit.

Developers said Ethereum addresses used to acquire and bond RUNE for the node appear connected to addresses that later received stolen funds. Based on the evidence reviewed so far, contributors believe the attack was likely carried out by a single malicious node operator, though the investigation remains ongoing.

GG20 TSS vulnerability emerges as leading theory

THORChain uses a threshold signature scheme to secure shared vaults without relying on a single private key.

Developers now suspect the protocol’s GG20 TSS implementation may have leaked fragments of key material over time. If enough data was exposed, an attacker could have reconstructed the vault key and signed transactions without authorization. The team has not yet released a formal post-mortem, and the root cause remains under investigation.

Network paused as recovery plan takes shape

Multiple node operators executed the make pause command after the exploit was detected, placing the network into a temporary pause state. THORChain said the pause is expected to expire automatically after about 12 hours unless node operators extend it. Contributors indicated they are comfortable allowing RUNE transfers and chain observation to resume when the pause ends. 

More sensitive functions, including trading, liquidity provider actions, and transaction signing, will remain suspended until the network agrees on a broader remediation plan.

Recovery options include bond slashing and POL

Node operators are discussing several ways to cover the losses. Options under consideration include:

  • Slashing the bonds of nodes that participated in the affected vault
  • Using protocol-owned liquidity (POL) to absorb part or all of the loss
  • Adopting other recovery proposals submitted by the community

No final decision has been made.

THORChain said its treasury team is gathering forensic evidence and coordinating with security specialists at THORSec and Outrider Analytics, as well as law enforcement agencies. The goal is to identify the attacker and recover funds where possible.

Incident follows earlier $10.8 million estimate

The latest update builds on earlier reports from security firms, including Cyvers and on-chain investigators, which estimated the exploit affected assets across Bitcoin, Ethereum, BNB Chain, and Base.

Initial estimates placed the loss at about $10.8 million, with stolen assets reportedly consolidated into wallets holding ETH, BTC, and BNB.

Full restart may take days

Contributors cautioned that restoring THORChain’s full functionality will likely take several days and could take longer depending on which remediation path node operators choose.

For now, the focus remains on confirming the exploit mechanism, containing further risk, and reaching consensus on how the decentralized protocol should allocate losses.

Also Read: Buybacks, Burns, and Bonds: CoW DAO Proposes New Plan for COW

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Shubham Soni
By Shubham Soni
Follow:
Shubham Soni is the Editor at The Crypto Times, based in Ujjain, Madhya Pradesh. He oversees the editorial desk, reviewing daily news coverage of cryptocurrency markets, US and Indian regulation, institutional adoption, the Solana ecosystem, AI agents, and Real World Assets (RWAs). All policy and markets coverage at The Crypto Times passes through his desk before publication. Before joining The Crypto Times in October 2025, Shubham managed news desks at Sportskeeda and Opoyi, covering global politics, sports, and entertainment for high-volume newsrooms serving the US and Indian markets. His four years in fast-paced newsrooms shaped his approach to fact-checking, source verification, and structural editing on complex stories. Shubham holds a Master's degree in Journalism from Makhanlal Chaturvedi National University of Journalism and Communication (Bhopal) and a Bachelor's degree in Journalism from Amity University Rajasthan. 

Latest News

Dutch Seek Knaken Bankruptcy After 30K Users Lose Crypto Access
Dutch Seek Knaken Bankruptcy After 30K Users Lose Crypto Access
Patrick Witt Says Open USD Shows Why CLARITY Act Matters
Patrick Witt Says Open USD Shows Why CLARITY Act Matters
PI Price Falls to Record Low Despite Pi Network Ecosystem Launch
PI Price Falls to Record Low Despite Pi Network Ecosystem Launch
Nasdaq Brings TotalView Market Data to Pyth Network Marketplace
Nasdaq Brings TotalView Market Data to Pyth Network Marketplace
MetaMask Launches Money Account With Up to 4% APY on Stablecoins
MetaMask Launches Money Account With Up to 4% APY on Stablecoins

Find Us on Socials

You may also like

Taiko Reaches Key Recovery Stage Following $1.7M Security Breach 

Taiko Reaches Key Recovery Stage Following $1.7M Security Breach 

AIDC Token Burn Bug Exploit Drains $121K From PancakeSwap

AIDC Token Burn Bug Exploit Drains $121K From PancakeSwap

Loopring Shuts Down Its DEX Disabling the Trustless Exit It Pioneered

Loopring Shuts Down Its DEX Disabling the Trustless Exit It Pioneered

Cardano's SecondFi Hack EMURGO Sets 2-Week Timeline to Return Stolen ADA

Cardano’s SecondFi Hack: EMURGO Sets 2-Week Timeline to Return Stolen ADA

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information