Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Clears Senate Banking Committee 15-9 Here’s What Every Crypto Leader Is Saying
    CLARITY Act Clears Senate Banking Committee 15-9: Here’s What Every Crypto Leader Is Saying
    GENIUS Act stablecoin regulation 2026 — US Treasury, OCC, FDIC and NCUA rulemaking on federal vs state oversight
    GENIUS Act at 10 Months: Inside America’s New Stablecoin Rulebook
    $10.8 Million Drained Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    $10.8 Million Drained: Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    BG Wealth and DSJ Exchange collapse exposes 2026 crypto scam pipeline
    How BG Wealth and DSJ Exposed the New Pipeline Model Behind 2026 Crypto Fraud
    Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    Exclusive: Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

THORChain Shares Exploit Report Revealing $10.7M Vault Breach by New Node

The decentralized liquidity protocol said it froze cross-chain activity within minutes after detecting abnormal vault balances linked to the $10.7M exploit.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: 22 minutes ago
Published 24 minutes ago
Share
Last updated: 22 minutes ago
Published 24 minutes ago
THORChain Shares Exploit Report Revealing $10.7M Vault Breach by New Node
Show AI Summary
The $10.7 million exploit affected roughly 20% of protocol-owned funds in active vaults.
Users’ funds and LP positions remained untouched due to swift emergency shutdowns.
The breach highlights vulnerabilities in decentralized protocols’ security systems.

THORChain disclosed new details about the May 15 exploit that drained roughly $10.7 million from one of its network vaults. In a post-incident report, the decentralized liquidity protocol said a newly added node operator exploited a weakness in its GG20 signing system only two days after joining the network. The attack triggered emergency shutdowns across trading, signing, and validator operations as developers rushed to contain further losses.

In the report, THORChain said its automatic solvency system detected abnormal vault balances within minutes and immediately froze activity across several connected blockchains. Node operators later expanded the response through emergency governance votes to fully halt network operations. The breach affected only 1 of THORChain’s 6 Asgard vaults — meaning the attacker drained roughly 20% of protocol-owned funds in active vaults. User funds, LP positions, and the remaining five vaults were untouched.

THORChain Exploit Report #1 is now live.

Full timeline of the May 15 incident, how the security layers responded, and what comes next via ADR-028.https://t.co/8QXfeKxwva

— THORChain (@THORChain) May 21, 2026

GG20 flaw allowed vault key reconstruction

THORChain traced the exploit to a validator node that joined the network on May 13. The malicious node was identified as thor16ucjv3v695mq283me7esh0wdhajjalengcn84q. According to the report, the attacker spent two days participating in routine GG20 signing operations before reconstructing a vault’s private key. The attacker then bypassed the normal approval process and moved funds directly from the compromised vault through unauthorized outbound transactions.

The protocol explained that its GG20 system splits cryptographic key fragments across several validators instead of relying on one private key. Validators normally work together through multiple communication rounds to approve transactions securely. However, investigators believe the attacker exploited gradual information leakage inside the GG20 implementation to rebuild the vault key over time.

The GG20 family — a fork of Binance’s tss-lib — has been on security researchers’ watchlist for years. Critical vulnerabilities in earlier GG18/GG20-family protocols have been documented, and Ledger CTO Charles Guillemet noted that in some previously documented attack scenarios, a single compromised co-signer could reconstruct enough information to recover the full signing key. The class of attacks first put on the industry’s radar by the “TSSHOCK” CVEs appears to be the closest analog to the May 15 incident.

THORChain also revealed that it had already planned to move toward the newer DKLS cryptographic system before the exploit occurred. The network said it had worked with Silence Labs since November 2025 to develop a customized version designed with additional security protections.

Where the stolen funds went

Per onchain analysis, the attacker drained assets across Bitcoin, Ethereum, BNB Chain, and Base. Wallets linked to the attacker held approximately 3,443 ETH, 36.85 BTC, and 96.6 BNB shortly after the attack, before consolidating the proceeds into a two-address cluster. TRM Labs noted the drain spread across at least nine chains in total, with the four named chains being the primary destinations for the stolen funds.

Emergency systems limited broader damage

THORChain said its automated solvency system detected abnormal vault balances after losses exceeded the network’s 1% threshold. Within 52 minutes, the protocol automatically halted trading and signing activity across Ethereum, Avalanche, Binance Smart Chain, Base, Dogecoin, and Gaia integrations to prevent further losses.

Meanwhile, node operators coordinated additional emergency measures through Discord and the network’s Mimir governance system. Roughly 18 to 20 validators stacked manual pauses to keep the network frozen while the investigation continued. Operators also activated HALTTRADING, HALTSIGNING, HALTCHAINGLOBAL, and HALTCHURNING controls within about one hour after community members flagged suspicious transactions.

The protocol later linked the malicious validator node to Ethereum addresses that received the stolen assets through on-chain forensic analysis. THORChain also confirmed that it continues working with Outrider Analytics and law enforcement agencies during the ongoing investigation.

THORChain has since released patch v3.18.1 to secure the remaining vaults while developers continue reviewing the exploit path. Recovery efforts will now move through community governance under ADR-028, where node operators will decide how the protocol restores the lost funds.

Also Read: Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Bithumb Freezes Heleket Transfers Over Money Laundering, Terror Links
Bithumb Freezes Heleket Transfers Over Money Laundering, Terror Links
Today in Crypto: HYPE Outshines, DASH Jumps 16%, Bitcoin ETFs See Fresh Outflows as BTC Holds Near $77K
Today in Crypto: HYPE Outshines, DASH Jumps 16%, Bitcoin ETFs See Fresh Outflows as BTC Holds Near $77K
Unsealed Court Filings Reveal Jane Street Traders Joked About Edge Before $192M UST Dump
Unsealed Court Filings Reveal Jane Street Traders Joked About Edge Before $192M UST Dump
Bipartisan PARITY Act Seeks Major Overhaul of US Crypto Tax Rules
Bipartisan PARITY Act Seeks Major Overhaul of US Crypto Tax Rules
Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol
Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol

Find Us on Socials

You may also like

MAP Bridge Exploit 1 Quadrillion MAPO Minted in Cross-Chain Attack

MAP Bridge Exploit: 1 Quadrillion MAPO Minted in Cross-Chain Attack

$6.7M Stolen From Kraken and Coinbase User, Funds Mixed On-Chain

$6.7M Stolen From Kraken and Coinbase User, Funds Mixed On-Chain

Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets

Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets

GitHub Investigates Internal Repo Breach Tied to Poisoned VS Code Task

GitHub Investigates Internal Repo Breach Tied to Poisoned VS Code Task

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information