T
iTokenly

THORChain hack — May 2026

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeBlockchain or validator set
Loss$10,700,000Published estimates range $10,000,000 to $11,000,000Price at time of incident
MethodSignature verification flawA validator that had churned into the active set two days earlier exploited THORChain's GG20 threshold signature implementation. At key generation the attacker published a Paillier modulus built from several small primes instead of two large ones; the library only screened for tiny factors and accepted it. Weak range-proof verification and an under-sized blinding term in the signing rounds then let each deliberately failed signing exchange leak a fragment of another validator's key share. After 864 failed rounds over roughly two and a half days the attacker had reconstructed the full vault private key and signed outbound transactions directly, bypassing the signing ceremony.
ChainsEthereum, Bitcoin, BNB Chain, Base
Audited beforehandYes
OutcomeUnresolved

What happened

On 15 May 2026 an attacker drained one of THORChain's five Asgard vaults. THORChain's first exploit report put the loss at approximately $10.7 million, revised upward from an initial public estimate of $7.4 million; its second report describes it as approximately $10 million, and the Q2 2026 quarterly report returns to approximately $10.7 million. Bitcoin.com News reported a per-chain split of roughly 3,443 ETH, 36.85 BTC, 96.6 BNB and, on early reports, around 798,000 USDC, and said the breach hit vaults on Bitcoin, Ethereum, BNB Smart Chain and Base. The on-chain investigator ZachXBT first flagged the incident on his Telegram channel, initially placing losses above $7.4 million.

The attack was cryptographic rather than a contract bug. A new node operator address churned into the active validator set on 13 May, planted a malformed Paillier key during vault setup, and then deliberately failed a specific signing step 864 times over about two and a half days. Each failure looked like ordinary node flakiness — and drew only the minor slashes that such failures normally attract, which the attacker simply absorbed — but leaked a fragment of other validators' key material. Once enough had accumulated the attacker held the vault's full private key and signed and broadcast outbound transactions directly, bypassing the signing ceremony entirely, which is why the solvency checker only detected the shortfall after the funds had gone.

Automatic halts fired within minutes and node operators brought the network to a controlled stop within about two hours. The remaining four vaults were untouched, and Solana was not exposed because the flaw is specific to ECDSA; EdDSA-based chains are not vulnerable to this class of attack.

Node operators approved a recovery plan, ADR-028, under which protocol-owned liquidity absorbs the loss first with any remaining shortfall allocated across synthetic asset holders, no new RUNE is minted or sold, the linked node is fully slashed and a bounty window was opened for the return of funds. The network restarted on 22 June 2026 after a five-week halt. THORChain states that the financial recovery itself remains unresolved.

Sources

  1. THORChainPrimary · retrieved 2026-08-01
  2. THORChainPrimary · retrieved 2026-08-01
  3. THORChainPrimary · retrieved 2026-08-01
  4. Bitcoin.com NewsSecondary · retrieved 2026-08-01
  5. crypto.newsSecondary · retrieved 2026-08-01

Official post-mortem: https://blog.thorchain.org/thorchain-exploit-report-2

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "THORChain hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/thorchain
https://itokenly.com/hacks/thorchain

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.