THORChain Restores Trading and Operations After Month-Long $10.7M Vault Exploit

Only one vault was drained—about $10.7 million—while the other four THORChain vaults remained unaffected.
Automatic solvency checks detected the imbalance within minutes and halted signing and trading across multiple chains, with a roughly two-hour staged halt implemented through Mimir governance controls.
The attacker was a newly churned node operator who entered the network two days before the exploit and used the GG20 vulnerability to reconstruct key material for a vault.
Emergency patch deployed on May 20 to safeguard active vaults, followed by a June 9 major software release addressing the vulnerability and a June 11 update to the KeyVerify protocol.
Some reports indicate THORChain downtime began in late January, suggesting a longer disruption than just the May incident.
THORChain resumed all trading, swapping, and liquidity provider functions on June 23, ending a 39-day shutdown triggered by a $10.7 million vault exploit on May 15. The attack drained one of the protocol's six Asgard vaults — while the other five stayed intact — and sent RUNE's price down 12–15% within minutes, according to Crypto Briefing.
The restart capped an 11-stage recovery process that included security audits, a full vault migration, and new software releases. The protocol's total value locked fell from $80 million on the day of the attack to $53 million at restart, per DefiLlama data cited by researchers.
The attacker bonded RUNE and joined THORChain's active validator set on May 13 — two days before striking. By participating in multiple signing rounds over 48 hours, the malicious node slowly reconstructed the full private key for one vault using a flaw in the GG20 threshold signature scheme, a cryptographic method that splits private keys among nodes. The stolen assets included 36.75 BTC and roughly $7 million spread across Ethereum, BNB Chain, and Base, according to PeckShield.
Automated solvency checkers caught the imbalance at 06:12 UTC on May 15 — less than two hours after the drain began. The system detected a greater-than-1% vault imbalance and automatically halted signing and trading across all chains, Crypto Briefing reported. On-chain sleuth ZachXBT first alerted the community to the suspicious outflows on Bitcoin and Ethereum.
On May 20, developers deployed emergency patch v3.18.1 to protect the five unaffected vaults. On June 9, a major release — v3.19.0 — closed the root GG20 vulnerability and added "vault quarantine" features. Two days later, update v3.19.1 introduced the KeyVerify protocol, which checks the integrity of every node's keyshare, according to Coin Central.
On May 27, node operators passed ADR-028, a governance proposal that used Protocol-Owned Liquidity to cover losses without minting new RUNE. "The recovery plan notably avoided minting additional RUNE... a detail that likely prevented further downward pressure," Crypto Briefing noted. Remaining losses were handled by trimming synthetic asset supply across the protocol.
Security firm QuillAudits found that THORChain used a custom fork of Binance's TSS library that was missing proof checks documented in academic research since 2023. Ledger CTO Charles Guillemet put it plainly: in GG20 attacks, "one malicious co-signer is sufficient" to break distributed security — no majority needed, according to Value The Markets.
Security firm V12 went further, alleging THORChain had been warned about a similar flaw in late April — weeks before the exploit — but ignored the disclosure after retiring its bug bounty program, per Crypto Briefing. THORChain co-founder jpthor described the GG20 library as a "black box" and said the protocol must move to more robust schemes like DKLS or FROST.
THORChain is now pivoting away from GG20 entirely. The protocol plans to adopt DKLS for ECDSA signing and FROST for Schnorr and Bitcoin-style signatures — both designed to prevent any single node from reconstructing a full key. Native Monero swaps are in final testing, with a mainnet launch expected soon. Zcash support is also planned, pending review of a separate vulnerability in Zcash's Orchard pool, according to Crypto Economy.
RUNE was trading at roughly $0.42 at the time of restart — still down from pre-exploit levels. THORChain also faces ongoing regulatory pressure over its role as a permissionless cross-chain swap venue. Researchers at Cyber News Network have linked the protocol to laundering routes used by the Lazarus Group following the Bybit ($1.5B) and KelpDAO ($300M) hacks earlier in 2025 and 2026, according to Head Topics.
Publishers
13
Articles
13
Reach
26