CryptoReal
CASE FILE — May 21, 2026

A Nine-Day-Old Patch and a Years-Stale Signing Library Cost THORChain $10.7 Million

01Background

THORChain's relationship with North Korean threat actors has been unusually direct for a protocol its size. Chainalysis data cited by CoinDesk put roughly $1.2 billion in North Korea-linked laundering through the network, and a separate $200 million insolvency scare nearly broke the protocol on its own. In September 2025, North Korean operators drained $1.2 million directly from co-founder jpthor's personal wallet using a fake-meeting social engineering scheme. Against that backdrop, this is now the third exploit in the protocol's history — and the newest one, on May 15, 2026, cost $10.7 million.

02The May 15 Drain and the Automated Halt

THORChain's Asgard vault infrastructure was drained across several chains in quick succession on the morning of May 15, 2026. The protocol's automatic solvency checker — built as a direct response to the July 2021 exploits — detected the shortfall and triggered a network-wide halt lasting twelve hours and forty-two minutes. It stopped further losses, but it didn't prevent the ones that had already occurred. RUNE's price fell 15% almost as soon as the news spread, and roughly $27 million was wiped from market cap within minutes.

ZachXBT's Telegram channel was first to flag the incident publicly, reporting that THORChain appeared to have been exploited across Bitcoin, Ethereum, BSC, and Base for more than $10.7 million. TRM Labs later widened the confirmed footprint to at least nine chains, adding Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP, and revising the total above $11 million. Arkham subsequently tagged the exploiter's wallet. PeckShield's independent confirmation put the figure at roughly $10 million, including 36.75 BTC and about $7 million spread across BNB Chain, Ethereum, and Base.

The response came from the protocol's own code rather than from any team member. THORChain's Mimir governance module automatically flipped its trading-halt and signing-halt parameters to active, pausing node activity for about 12 hours and 42 minutes starting at block 26,190,429 — no human intervention required.

More than five hours after ZachXBT's initial alert, THORChain issued an official statement confirming that one of its six Asgard vaults had been compromised and that $10.7 million had been lost. The statement noted that node operators securing the affected vault had their bonded RUNE slashed as a consequence of the unauthorized outbound transfers, that validator churn was paused, that chain onboarding was delayed indefinitely, and that early indications showed no individual user swaps had been affected.

Downstream, THORSwap and Metro.exchange immediately halted THORChain-based routing, Maya Protocol paused as a precaution, and ATOM trading went offline. Other liquidity providers built on alternative infrastructure — Chainflip, NEAR Intents, Harbor, Flashnet, Garden, and 1inch — continued operating without disruption.

Even as the ecosystem was reacting, the on-chain trail was pointing toward an answer nobody wanted. Ethereum researcher banteg surfaced a THORNode GitLab commit dated May 6 — nine days before the exploit — titled "sign full ObservedTx wrapper to prevent proposer forgery." The fix existed, had a timestamp, and had simply never been deployed. It wasn't the root cause of the exploit, but it became an early symbol of a pattern: known issues that sat unaddressed.

03How a Single Validator Compromised the Vault

THORChain secures its vaults using Threshold Signature Scheme (TSS), a form of multi-party computation in which a quorum of nodes jointly generates signatures without any single participant ever holding a complete private key. In theory that distributes trust; in practice, the system is only as strong as its weakest co-signer.

The intrusion appears to have started well before the funds moved. A newly registered Discord account, "Dinosauruss," joined THORChain's Developer Discord on May 1 and asked how to get a node churned into the active set as fast as possible. An unrelated delay had pushed back the usual three-day churn cycle, forcing the account to wait longer than expected. On May 13 — two days before the exploit — a brand-new operator controlling roughly 635,000 RUNE split across two bonding addresses churned into the validator set and was randomly assigned to one of the network's five vaults. Over the following two days, that node took part in ordinary GG20 signing ceremonies alongside the rest of its vault.

THORChain's own confirmed finding is that the attacker exploited a flaw in the GG20 TSS implementation that gradually leaked fragments of key material from other vault participants during routine signing. By accumulating enough of these fragments across multiple rounds, the attacker was able to reconstruct the vault's complete private key and issue unauthorized outbound transactions directly, bypassing the normal signing process entirely. Because the proactive solvency check only runs before a signing event, it had nothing to catch; the reactive check that fired only detected the shortfall after the vault was already empty. The solvency system worked as intended — the attack simply operated at a layer beneath it.

Why GG20 Was the Weak Point

GG20 is a widely deployed threshold-ECDSA protocol, common in systems handling Bitcoin and Ethereum signatures, but it also carries a known track record of severe vulnerabilities. CVE-2023-33241 and the TSSHOCK disclosure, both made public in 2023, describe key-extraction attacks that require only a single compromised co-signer and leave no trace in normal operation. It hasn't been publicly confirmed which, if either, matches this specific incident, but both demonstrate the same class of attack.

THORChain's TSS layer runs on a fork of Binance's tss-lib implementing GG20. Security researcher Taylor Monahan observed shortly after the exploit surfaced that the fork appeared to be roughly three years and more than two major security releases out of date.

banteg published the most detailed technical write-up the day after the exploit, examining the deployed code directly — tss-lib v0.1.6 at commit 287e1e2, as run by thornode v3.18.0. According to that analysis, the key-generation logic accepted and stored peer Paillier key material without requiring the MOD/FAC proofs that would normally confirm the modulus is a properly formed two-prime number. That gap meant a malicious node could register a 2048-bit Paillier modulus that passed every existing check while secretly containing factors known only to the attacker. Once that malformed key was accepted and stored by honest nodes, every subsequent signing round involving it leaked small residues of other participants' long-term key shares — residues an attacker could quietly collect and reassemble offline. banteg's own test harness reproduced this leakage pattern.

jpthor had flagged GG20 as the likely culprit within hours of the halt. Security researcher Charles Guillemet summarized the structural issue: in every documented GG18 or GG20 attack to date, a single malicious or compromised co-signer is sufficient — no majority or quorum is needed to break the scheme.

jpthor has since outlined a three-step remediation path: patch GG20 well enough to bring THORChain back online, migrate all ECDSA-based protocols to DKLS, and eventually move Bitcoin signing to FROST. He has also described GG20 as a "black box" full of "brittle assumptions" that will "forever be a bit of a black box" — a striking admission from within the project. THORChain had in fact contracted Silence Labs in November 2025 to build a custom DKLS implementation, targeting delivery in Q1/Q2 2026 — which is why GG20 was still in production when the exploit occurred. That migration had not been completed in time.

None of this would have mattered without THORChain's churning process — the routine rotation of validators in and out of active Asgard vaults. That mechanism is what let a newly bonded, unvetted node join a vault, take part in signing, and slowly harvest the key material it needed. The attacker never had to break the underlying cryptography outright; they only needed a seat at the table.

THORChain says the investigation is ongoing, conducted with THORSec and Outrider Analytics, and that law enforcement has been notified. The attacker's identity has not been established. An initial exploit report was released on May 20, with a follow-up expected once the investigation and recovery plan are finalized. What has been publicly confirmed so far is the malicious node's address, the on-chain links between its bonding and receiving wallets, and the underlying mechanism: an outdated signing library, forked years ago, containing a flaw that let a patient, well-resourced operator siphon vault key material over time.

Malicious node address: thor16ucjv3v695mq283me7esh0wdhajjalengcn84q

04Chain-by-Chain Breakdown of the Stolen Funds

QuillAudits released a full chain-by-chain accounting of the drain on May 19. Across every affected network, funds were moved to attacker-controlled wallets before the halt had even fully propagated.

Sums referenced in this case file

Ethereumstablecoins, blue-chip DeFi tokens, and protocol-native assets were pulled from the vault: 1,756,756.02 USDT, 1,261,986.53 USDC, 73,768,463.86 XRUNE, 3,349,323.54 THOR, 5.206 WBTC, 64,138.47 LUSD, 61,074.86 GUSD, 38,762.45 USDP, 1,044.06 LINK, 4,567.54 DAI, 78.10 AAVE, 1,514.92 SNX, 481,996.68 FOX, 1.057 YFI, and 11.43 DPI. Attacker address: 0x82fc0d5150f3548027e971ec04c065f3c93154eb. Vault address: 0x82a5CF67F3e6970C0529122178075C0a94878bDA. Roughly $6.77 million of the total was routed onward to 0xd477b69551f49C0519F9B18c55030676138890Bd. Full outbound transaction list on Etherscan.

BNB Chaina mix of stablecoins, wrapped BTC, and ETH equivalents: 274,256.09 USDC, 125,117.17 BSC-USD, 32,144.23 BUSD, 32,980.44 TWT, 15.615 ETH, and 0.509 BTCB. Attacker address: 0x82fc0d5150f3548027e971ec04c065f3c93154eb. Vault address: 0x82a5cf67f3e6970c0529122178075c0a94878bda. Full outbound transaction list on BscScan.

Bitcointwo outbound transactions totaling more than 40 BTC (roughly $3.26 million): 36.85351435 BTC and 3.87429558 BTC. Attacker address: bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37. Vault address: bc1qt8f467qdkpmuflgwvgvvlr86r0kldnnvm7zhyv. Transaction history on mempool.space.

Avalanchestablecoins and a SOL-equivalent asset: 238,325.94 USDC, 43,041.25 USDT, and 388.94 SOL. Attacker/receiving address: 0xd477b69551f49C0519F9B18c55030676138890Bd. Vault address: 0x82A3580296b014c27cFe6be23Ed471c30D878Bda.

Basea single outbound transaction of 55,912.41 USDC. Attacker address: 0xd477b69551f49C0519F9B18c55030676138890Bd. Vault address: 0x82a5cf67f3e6970c0529122178075c0a94878bda. Drain transaction: 0x4370739cf3f443fe129727ea1a9e215783d881c643f3ea1d12ce822aeb3e6af8.

Dogecoinnearly 7.82 million DOGE (about $900,000) across two nearly identical transactions: 3,911,749.91 DOGE and 3,911,751.03 DOGE. Attacker address: DBLJWFemMHbduKofBRg6TJ9XFAgWdvFCjS. Vault address: DDL3tEh5P5vjSCNyU7t7sz9DQykRnr97d2.

Litecoin6,866.74772083 LTC moved out. Attacker address: ltc1qg0h4rz5kf27fkr99gamw4heg20rfz5epd7m7wh. Vault address: ltc1qt8f467qdkpmuflgwvgvvlr86r0kldnnvlzcnuu. Transaction: F5985741ef6d7418cd2f0f4e909b6f0d525f18c6010cca48d846731f23972bd4.

Bitcoin Cash638.52948245 BCH in a single transaction. Attacker address: qpp775v2je9texcv54rhd6kl9pfudy2nyyz4df2uvc. Vault address: qpvaxhtcpkc8038ape3p3nuvlgd7makwds74qyng5p.

XRPtwo transactions: 25,404.922305 XRP and 16.999982 XRP. Attacker address: rwoGBrYEJ28jhBjchrTyCGXd1Pt4pobFBz. Vault address: r9BxLykSngpSuUU4jXtZLDycXip3Suo7Rf.

TRON89,172 TRX was swapped for 31,215 USDT via SunSwap, then bridged to Ethereum, delivering 13.9 ETH to the same address used as an Ethereum laundering hub elsewhere in the incident. TRON's signing, trading, and solvency checks were subsequently halted and disabled in Mimir, consistent with the treatment of the other confirmed chains. Attacker address: TXmo5sdVCvQnJgbvjAUpQJfyNx5EnqtAM3. Vault address: TMt1UgzBNKETQMgGckJDomcMQhvwhGUiXo. Drain transaction: 0ee50dd1af24c08a2f73fab18dd96897fcd6c08cfca0a6397b519c8fe1fdf1f4. ETH delivery transaction: 0x09c4bc73fddaac5697a609cb448cefc26e13ccba22ce1b762b309b010e0db5f4, landing at 0x82fc0d5150f3548027e971ec04c065f3c93154eb.

THORChain's official statement confirmed that node operators securing the compromised vault had their bonded RUNE slashed as a direct result of the unauthorized transfers. The losses were protocol-owned funds; the team's initial assessment indicated individual user swaps were not affected. The slashing mechanism performed as designed — the vault itself did not hold.

The exploit's apparent suddenness was misleading. A five-part Chainalysis thread published May 15 traced weeks of preparation starting in late April: the attacker funded their entry through Monero, bonded the RUNE used to stand up the malicious node, and sent 8 ETH to the final receiving wallet just 43 minutes before the drain began.

05A Security Program That Missed the Layer That Mattered

THORChain does have a track record on security. It launched a bug bounty with ImmuneFi after the 2021 exploits, later left that program under disputed circumstances in favor of a self-hosted bounty, which was itself wound down in March 2026 — two months before this exploit. After the 2021 incidents it also brought in both Halborn and Trail of Bits and carried out a five-part recovery process covering red-teaming, protocol hardening, and formal audit sign-off before resuming operations.

The question isn't whether audits happened — it's where they were aimed. Trail of Bits conducted a full audit of THORNode, the Bifrost bridge, and the tss-lib implementation underlying the vault system after the 2021 exploits. Halborn ran a separate penetration test of the THORNode stack, Bifrost, and vault security, including the threshold multisig implementation. Both came back clean, with no unresolved critical findings at the time.

Then in December 2021, Trail of Bits disclosed Shamir's Secret Sharing vulnerabilities in tss-lib that directly affected THORChain. The protocol patched the issue and relaunched — but the underlying audits were never refreshed. Since then, Halborn has completed eight separate assessments between January and November 2025, and every one of them was scoped to Rujira, THORChain's smart-contract application layer covering lending, its order-book DEX, staking, and lending pools — necessary work, but unrelated to the layer that was actually breached.

The fuller audit history:

2020: CertiK code review, April 2020; Kudelski Security TSS audit, June 2020; IOActive penetration test, November 2020.

2021: Trail of Bits core protocol + tss-lib audit, August 2021; Halborn TSS audit, September 2021; Halborn state machine, router, and Bifrost audit, September 2021; Trail of Bits tss-lib Shamir's Secret Sharing disclosure (patched), December 2021.

2024/2025 (Bifrost observation layer): Zellic THORChain Bifrost audit, November 2024; Zellic Bifrost UTXO Client audit, January 2025.

2025 (Rujira application layer): Halborn Rujira Trade (FIN), January–February 2025; Halborn Rujira Pools (BOW), February 2025; Halborn Rujira Staking, March–April 2025; Halborn NAMI Protocol Rujira Index Product, May 2025; Halborn CALC Manager/Scheduler/Strategy, August 2025; Halborn Ghost Vault (RUJI Lending), October 2025; Halborn Ghost Credit (Credit Accounts), October–November 2025; Halborn Rujira Trade FIN v1.1, November 2025.

The GG20 tss-lib fork itself — the exact component at the center of this exploit — has no documented audit after 2021. Bifrost received somewhat more recent scrutiny, with Zellic reviewing its observation layer and a 2024 Code4rena contest covering its EVM smart-contract parsing logic. But the signing library itself — which Taylor Monahan noted was years behind on security patches — last received formal review before either of the two major public GG20 vulnerabilities, TSSHOCK and CVE-2023-33241, was disclosed in 2023. The Trail of Bits audit that touched tss-lib predates both disclosures, and none of the 2025 assessments revisited it.

To be fair, audits are point-in-time assessments — Halborn's 2021 work couldn't have caught vulnerabilities that weren't public yet. What's harder to justify is that no follow-up review of the core cryptographic layer occurred after those vulnerabilities became public knowledge. Eight audits were completed in 2025, all aimed at the application layer, while the cryptographic foundation underneath the vaults went unreviewed since before its known flaws were disclosed.

06Context: Resilience Without Accountability

This is not the first time THORChain has weathered a crisis. It survived two exploits within ten days in 2021, a $200 million insolvency scare that briefly looked existential, and $1.2 billion in North Korea-linked laundering that fractured its community and pushed out contributors. Each time, the protocol absorbed the damage, restructured, and kept operating — but the underlying lessons don't appear to have fully carried forward. The signing library securing the vaults sat years behind on security updates, and the last formal review of the core protocol predates the public disclosure of the vulnerabilities now under investigation, even as eight separate audits shipped in 2025, none aimed at that layer.

In the exploit's immediate aftermath, scammers began circulating fake refund portals targeting the same users who had just lost funds. By May 18, THORChain had to issue a direct public warning stating there is no refund portal and urging users to rely only on official channels — a notice that still sits atop the protocol's website.

The investigation remains active, run jointly with THORSec and Outrider Analytics, with law enforcement involved. An initial report was published May 20; a follow-up is pending, and no compensation plan has been finalized. The governance vote on how to handle the losses, ADR-028, has not yet concluded, and no timeline has been set for restarting the full network.

A separate irony sits underneath all of it: Chainalysis has estimated, conservatively, that THORChain earned at least $12 million in fees from processing the $1.2 billion in North Korea-linked transactions — framed by the protocol as neutrality. When Lazarus Group funds moved through the network previously, node operators initially voted to halt ETH trading, but that vote was reversed within minutes, and a core contributor subsequently resigned while the network kept running. On May 15, the same protocol that had declined to halt for a nation-state actor halted itself automatically within minutes of detecting its own losses, for twelve hours and forty-two minutes.

That contrast has drawn pointed questions across the industry: if THORChain has the technical capacity for an emergency shutdown, why has it historically been used only when the protocol's own funds were at risk, rather than when it was facilitating the movement of hundreds of millions of dollars in stolen assets for state-sponsored actors? Whether that reflects a genuine architectural limitation or a selectively applied principle of decentralization is a question the protocol has yet to answer directly.

THORChain will likely recover from this exploit, as it has from previous ones. But recovering and being held accountable are not the same thing, and on the available record, the protocol has consistently managed the former far better than the latter.

THORChain
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.