Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

THORChain Incident Update: Malicious Node and GG20 TSS Exploit Suspected

The network remains partially paused as node operators debate slashing bonds, using protocol-owned liquidity, and other options to cover losses.

Written By Shubham Soni
Published 2026-05-16·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
THORChain Incident Update Malicious Node and GG20 TSS Exploit Suspected
Show AI Summary
A vulnerability in THORChain’s threshold signature scheme likely led to a $10.8 million exploit, highlighting security risks in cross-chain liquidity protocols.
The incident underscores the importance of robust validator node vetting, as a newly added node is suspected to be linked to the exploit, potentially due to inadequate screening.
The partial network pause and ongoing investigation underscore the challenges of maintaining security and trust in decentralized networks, impacting the broader cryptocurrency industry.

THORChain contributors say current evidence points to a newly churned validator node as the likely source of the exploit that drained roughly $10.8 million from the cross-chain liquidity protocol.

In an incident update shared via X on Friday, developers said the leading theory is that the attacker exploited a vulnerability in THORChain’s GG20 threshold signature scheme (TSS), allowing sensitive key material to leak over time. Investigators believe the attacker used that information to reconstruct a vault private key and authorize unauthorized outbound transactions.

THORChain incident update #1
THORChain contributors shared a new update in the dev discord regarding the ongoing incident.

TLDR
– Current evidence points toward a newly churned node linked to the attack, likely operated by a single malicious actor

– The leading theory is an…

— THORChain (@THORChain) May 15, 2026

The network remains partially paused while developers, security contributors, and node operators determine how to restore normal operations and absorb the losses.

Newly added validator under scrutiny

According to the update, a node identified as thor16ucjv3v695mq283me7esh0wdhajjalengcn84q, which joined the active validator set several days before the incident, is believed to be linked to the exploit.

Developers said Ethereum addresses used to acquire and bond RUNE for the node appear connected to addresses that later received stolen funds. Based on the evidence reviewed so far, contributors believe the attack was likely carried out by a single malicious node operator, though the investigation remains ongoing.

GG20 TSS vulnerability emerges as leading theory

THORChain uses a threshold signature scheme to secure shared vaults without relying on a single private key.

Developers now suspect the protocol’s GG20 TSS implementation may have leaked fragments of key material over time. If enough data was exposed, an attacker could have reconstructed the vault key and signed transactions without authorization. The team has not yet released a formal post-mortem, and the root cause remains under investigation.

Network paused as recovery plan takes shape

Multiple node operators executed the make pause command after the exploit was detected, placing the network into a temporary pause state. THORChain said the pause is expected to expire automatically after about 12 hours unless node operators extend it. Contributors indicated they are comfortable allowing RUNE transfers and chain observation to resume when the pause ends. 

More sensitive functions, including trading, liquidity provider actions, and transaction signing, will remain suspended until the network agrees on a broader remediation plan.

Recovery options include bond slashing and POL

Node operators are discussing several ways to cover the losses. Options under consideration include:

  • Slashing the bonds of nodes that participated in the affected vault
  • Using protocol-owned liquidity (POL) to absorb part or all of the loss
  • Adopting other recovery proposals submitted by the community

No final decision has been made.

THORChain said its treasury team is gathering forensic evidence and coordinating with security specialists at THORSec and Outrider Analytics, as well as law enforcement agencies. The goal is to identify the attacker and recover funds where possible.

Incident follows earlier $10.8 million estimate

The latest update builds on earlier reports from security firms, including Cyvers and on-chain investigators, which estimated the exploit affected assets across Bitcoin, Ethereum, BNB Chain, and Base.

Initial estimates placed the loss at about $10.8 million, with stolen assets reportedly consolidated into wallets holding ETH, BTC, and BNB.

Full restart may take days

Contributors cautioned that restoring THORChain’s full functionality will likely take several days and could take longer depending on which remediation path node operators choose.

For now, the focus remains on confirming the exploit mechanism, containing further risk, and reaching consensus on how the decentralized protocol should allocate losses.

Also Read: Buybacks, Burns, and Bonds: CoW DAO Proposes New Plan for COW

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Paul Atkins, SEC Chairman
SEC’s Paul Atkins Says Tokenization Rules Will Move Ahead Despite CLARITY Act Failure
Bitget Protection Fund Back Above $300M After $387.5M Hack, P2P Withdrawals Return October 2
Bitget Protection Fund Back Above $300M After $387.5M Hack, P2P Withdrawals Return October 2
Zcash Developers Merge Udon Into Zakura Common in Broader Scaling Efforts
Zcash Developers Merge Udon Into Zakura Common in Broader Scaling Efforts
Standard Chartered Initiates Ethena Coverage, Sets $2 ENA Price Target for End-2028
Standard Chartered Initiates Ethena Coverage, Sets $2 ENA Price Target for End-2028
Illinois Publishes Draft Rules for 0.2% Digital Asset Tax 
Illinois Publishes Draft Rules for 0.2% Digital Asset Tax 

Find Us on Socials

You may also like

Bitget $387.5M Hack: SlowMist and Mandiant Say Zero-Day Attack Began Weeks Before Theft

Bitget $387.5M Hack: SlowMist and Mandiant Say Zero-Day Attack Began Weeks Before Theft

Aave ghost mascot holding a purple Monad token against a repeated Monad and Aave logo pattern.

Aave Proposes Monad V4 Hub for Tokenized Equity Lending

Blockaid Warns Token Metadata Can Expose AI Agents to Crypto Attacks 

Blockaid Warns Token Metadata Can Expose AI Agents to Crypto Attacks 

An illuminated blue Coinbase logo on a dark wall beside a breached metallic vault spilling gold Bitcoin coins onto the floor.

Coinbase Accused of Hiding Hack Losses and $25M in Unrepaid Client Funds 

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information