A single rogue node operator drained $10.8 million from THORChain's Asgard vault on May 15, 2026, exploiting a vulnerability in the protocol's GG20 threshold signature scheme (TSS) implementation. The attack hit nine chains — Bitcoin, Ethereum, BSC, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Ca...
"A single compromised co-signer could reconstruct enough information to recover the full signing key." — Charles Guillemet, CTO, Ledger
A single rogue node operator drained $10.8 million from THORChain's Asgard vault on May 15, 2026, exploiting a vulnerability in the protocol's GG20 threshold signature scheme (TSS) implementation. The attack hit nine chains — Bitcoin, Ethereum, BSC, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP — and impacted 12,847 wallets before an automated halt froze the network within eight minutes.
The incident is the latest in a string of cross-chain infrastructure failures that have now cost the sector $328.6 million in bridge-related exploits through mid-May 2026 alone. THORChain's cumulative direct losses since 2021 now approach $25 million, according to TRM Labs. The technical root cause — gradual leakage of vault key material during routine signing ceremonies — implicates a vulnerability class that extends well beyond THORChain to any protocol relying on multi-party computation (MPC) wallet infrastructure.
THORChain's recovery portal went live on May 16, backed by a treasury-funded refund pool. Affected users have until June 4 to file claims. RUNE fell 12–15% in the 24 hours following disclosure, with market capitalization dropping roughly $27 million to $182 million.
The operation did not begin on May 15. Chainalysis investigators traced preparatory wallet activity back to late April 2026, when the attacker began constructing an exit route through a Monero-Hyperliquid privacy bridge.
| Date | Event |
|------|-------|
| Late April 2026 | Attacker deposits XMR through Hyperliquid-Monero privacy bridge; funds swapped for USDC, withdrawn to Arbitrum, bridged to Ethereum |
| Early May 2026 | Attacker bonds RUNE to spin up validator node thor16ucjv3v695mq283me7esh0wdhajjalengcn84q; node churns into active signing set |
| May 14–15, pre-attack | Three separate return branches rehearse the exit: ETH bridged to Arbitrum, deposited into Hyperliquid, routed back to Monero. Last rehearsal transaction lands fewer than five hours before the exploit |
| May 15, ~09:45 UTC | On-chain investigator ZachXBT flags unusual Asgard vault outflows |
| May 15, minutes later | THORChain pauses all trading, swaps, liquidity actions, and signing at Block 26190429 |
| May 15 | 13-hour network halt begins; pause scheduled to lift at Block 26191149 |
| May 16 | Recovery portal launches at swap.thorchain.org |
| May 16 | THORChain issues warning about phishing scams targeting exploit victims |
| June 4 (deadline) | Refund claims close; unclaimed funds roll to protocol insurance fund |
The 43-minute gap between a final 8 ETH transfer into the target wallet and the actual theft indicates the attacker operated on a precise, pre-planned schedule.
The attack exploited a weakness in THORChain's implementation of GG20 (Gennaro-Goldfeder 2020), a widely referenced multi-party ECDSA protocol. The compromise unfolded in three stages.
Stage 1 — Network Infiltration. The attacker bonded RUNE collateral, launched a validator node, and waited for it to churn into the active signing set. This granted legitimate access to vault threshold signing ceremonies — the multi-party sessions where nodes collectively authorize outbound transactions.
Stage 2 — Cryptographic Extraction. During normal signing rounds, the attacker exploited a flaw in the GG20 implementation that caused partial key material to leak incrementally. This attack class — first documented publicly by Verichains under the designation TSSHOCK — demonstrates that a single malicious participant can extract fragments of other parties' secret shares across multiple protocol rounds. By accumulating enough leaked shards, the attacker reconstructed the vault's complete private key offline.
Stage 3 — Unilateral Signing. With the full key reconstructed, the attacker bypassed multi-party consensus entirely. Outbound transactions were signed unilaterally and directed to pre-positioned addresses across nine chains, draining the Asgard vault before the automated anomaly detection triggered a halt.
The TSSHOCK vulnerability class encompasses three distinct key extraction attacks — α-shuffle, c-split, and c-guess — that can extract private keys after as few as one to two signatures. Academic research published through Black Hat USA and by Verichains identified that most implementations of GG18, GG20, and CGGMP21 were vulnerable. Affected software has been deployed by Binance, ZenGo, Multichain, and ING Bank, among others.
The critical gap: this attack surface extends beyond smart contract code to the cryptographic ceremony itself. Standard smart contract audits do not cover TSS implementation security.
TRM Labs confirmed the total drain exceeded $11 million across nine chains:
| Chain | Amount Stolen | USD Value | |-------|--------------|-----------| | Ethereum | 3,443 ETH | ~$7.77M | | Bitcoin | 36.85 BTC | ~$2.97M | | BNB Chain | 96.6 BNB | ~$66K | | Base | Various tokens | Remainder | | Avalanche | Undisclosed | Included in total | | Dogecoin | Undisclosed | Included in total | | Litecoin | Undisclosed | Included in total | | Bitcoin Cash | Undisclosed | Included in total | | XRP | Undisclosed | Included in total | | Total | | $11M+ |
Losses were confined to protocol-owned liquidity inside the compromised Asgard vault. User-controlled funds — assets held in personal wallets — were not directly drained.
Chainalysis reconstructed the attacker's operational pattern, revealing a level of preparation that distinguishes this from opportunistic exploits.
Funding. The attacker sourced initial capital through Monero, a privacy-focused cryptocurrency, then converted to USDC via Hyperliquid before bridging to Ethereum. This obfuscated the origin of funds before any on-chain interaction with THORChain.
Infrastructure. Hundreds of thousands of dollars in ETH were used to acquire and bond RUNE for the malicious validator node. The Ethereum addresses used for bonding "appear connected to addresses that later received stolen funds," according to THORChain developers, establishing a direct link between the pre-attack infrastructure and the theft.
Exit Route. The attacker built three separate return branches, all routing through Arbitrum to Hyperliquid to Monero — the same path used for initial funding. The exit route was rehearsed at least once in the hours before the exploit. As of May 17, the $10.8 million in stolen funds remained dormant in tagged wallets.
Multiple forensic teams mobilized within hours.
TRM Labs tagged five attacker addresses and traced flows across all affected chains. The firm issued compliance guidance recommending that institutions with exposure to tagged addresses "act within hours, not days," noting that cross-chain fund movement outpaces traditional attribution workflows. TRM has not attributed the exploit to a specific threat actor as of May 17.
Chainalysis traced the pre-attack Monero-Hyperliquid trail and provided the timeline reconstruction linking wallet setup activity to the exploit.
Arkham Intelligence and PeckShield independently identified attacker wallet clusters, corroborating the chain-by-chain drain amounts.
Outrider Analytics is working directly with THORChain's treasury and law enforcement agencies on asset recovery.
Known attacker addresses flagged by TRM:
bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f370x82fc0d5150f3548027e971ec04c065f3c93154eb0xd477b69551f49c0519f9b18c55030676138890bdqpp775v2je9texcv54rhd6kl9pfudy2nyyz4df2uvcDBLJWFemMHbduKofBRg6TJ9XFAgWdvFCjSltc1qg0h4rz5kf27fkr99gamw4heg20rfz5epd7m7whrwoGBrYEJ28jhBjchrTyCGXd1Pt4pobFBzThis is not THORChain's first security failure. The protocol's incident history follows a pattern of exploit, halt, patch, and resume.
| Date | Incident | Loss | |------|----------|------| | July 2021 | Two separate exploits in rapid succession | ~$13M combined | | Early 2025 | $200M debt crisis threatening protocol solvency | Restructured via equity-style token | | September 2025 | Founder JP Thorbjornsen personally targeted | ~$1.3M (suspected North Korean actors) | | May 2026 | GG20 TSS exploit | $10.8M+ |
Cumulative direct losses targeting THORChain and its leadership now total approximately $25 million, per TRM Labs.
Separately, THORChain's permissionless swap infrastructure has served as the primary laundering rail for two of the largest crypto thefts on record: the $1.5 billion Bybit hack (February 2025) and the $292 million KelpDAO exploit (April 2026). This dual role — as both victim and laundering conduit — creates a compounding reputational and regulatory liability.
The THORChain exploit is a specific instance of a broader vulnerability class. The TSSHOCK research, first presented at Black Hat USA and published by Verichains, demonstrated that most implementations of threshold ECDSA protocols (GG18, GG20, CGGMP21) contained exploitable weaknesses allowing key extraction by a single malicious participant.
The implications extend to:
Ledger CTO Charles Guillemet warned that "advances in LLM-assisted vulnerability discovery and exploit generation may reduce the difficulty" of compromising validator infrastructure that was previously considered secure. The observation suggests the attack surface for MPC implementations may widen as adversarial tooling improves.
The core question for the sector: if GG20 implementations have exploitable leakage in adversarial multi-party settings — where one participant is actively malicious — how many other protocols carry the same unpatched exposure? Standard smart contract audits do not cover TSS implementation security, creating a blind spot in the industry's assurance framework.
The THORChain incident fits within a broader pattern of cross-chain infrastructure failure in 2026.
According to Peckshield, eight bridge exploits through mid-May 2026 have drained $328.6 million cumulatively. April 2026 alone produced over $625 million in total crypto exploit losses across 30 separate incidents, making it the worst month since the $1.5 billion Bybit hack in February 2025.
Cumulative bridge losses since 2022 now exceed $2.8 billion, representing roughly 40% of all value hacked in Web3, according to industry tracking data. The economic cost of cross-chain interoperability — measured in direct theft, opportunity cost during network halts, token price depreciation, and compliance overhead — continues to accumulate with no structural solution in sight.
For protocols like THORChain, which process native asset swaps without wrapping or custodial intermediaries, the value proposition remains clear: trustless cross-chain exchange. The recurring security question is whether the cryptographic infrastructure underpinning that promise can survive adversarial conditions at production scale.
Refund Portal. THORChain launched a treasury-funded recovery portal on May 16 at swap.thorchain.org. The 12,847 affected wallets can verify compensation amounts and submit claims through June 4. Unclaimed funds will transfer to the protocol's insurance reserve.
Node Slashing. The malicious node's bonded RUNE collateral is under consideration for slashing — a protocol mechanism designed to penalize validator misbehavior by seizing staked assets. The bond amount has not been disclosed publicly.
Token Impact. RUNE dropped 12–15% in the first 24 hours after the exploit, trading at $0.4382 as of May 16. Market capitalization fell from approximately $209 million to $157 million — a $52 million contraction attributable to both the direct loss and the confidence discount applied by the market.
Secondary Scams. Within 24 hours of the exploit, THORChain issued warnings about phishing campaigns targeting victims. Fake accounts circulated fraudulent "refund" offers, "airdrop" announcements, and compensation scams — a pattern now so consistent after major DeFi incidents that it should be anticipated as a secondary cost of any large-scale exploit.
Network Status. As of May 19, the network halt remains in place. THORChain has not published a restart timeline, stating the pause will continue until the foundation confirms the TSS vulnerability is fully patched.
The THORChain exploit is a $10.8 million data point in a larger pattern. Cross-chain infrastructure continues to produce the largest single-day losses in crypto, and the attack surface is expanding from smart contract logic into the cryptographic primitives themselves. The GG20 TSS flaw exploited here was documented in academic research years before it was weaponized in production — a gap between known vulnerability and deployed patch that the industry has yet to close.
For THORChain specifically, the question is whether a protocol that has now lost $25 million to direct exploits and facilitated the laundering of over $1.7 billion in stolen funds can maintain the user trust required to function as critical cross-chain infrastructure. The 12,847 affected wallets awaiting refund through June 4 represent the immediate cost. The longer-term cost — measured in liquidity provider confidence, regulatory scrutiny, and the credibility of MPC-based security models — remains unpriced.