THORChain ERC-20 Router Exploit hack — July 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 23, 2021 |
| Target type | Decentralised exchange |
| Loss | $8,000,000Price at time of incident |
| Method | Contract logic errorThe attacker deployed a fake router contract that emitted a deposit event with a malformed memo and named the attacker's own contract as an Asgard vault. THORChain's Bifrost service could not parse the memo, fell through to its refund path, and sent real ERC-20 vault assets to the address the forged event specified. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
On 23 July 2021 an attacker took roughly $8 million of ERC-20 assets from THORChain's Ethereum router. It was the second successful exploit of that component in eight days and the third incident to hit the cross-chain liquidity protocol in under a month, after a roughly $140,000 loss in late June.
THORChain's Bifrost service watches the Ethereum router for deposit events and mirrors them into the network. The attacker deployed a fake router contract that emitted a deposit event carrying a malformed memo and designated the attacker's own contract as an Asgard vault. Because Bifrost could not parse the memo, it fell through to its refund logic and returned real vault assets to the address the forged event named. THORChain's post-mortem describes the Bifrost code involved as unaudited: the state machine and BNB Bifrost had been audited, but the updated multi-chain state machine and its new Bifrosts had not. SlowMist's analysis of the transaction lists the assets taken as 1,672,794 USDC, 990,137 USDT, 20,866,664 XRUNE, 56,104 SUSHI, 966.62 ALCX and 6.91 YFI.
The attacker embedded a message in the transaction saying they had deliberately limited the damage, that they could also have taken BTC, BNB and BEP-20 assets, and warning the team not to rush code that secures nine figures. Reporting at the time said the attacker asked for a 10% bounty. Contemporaneous reporting does not record the funds being returned.
The network was halted. THORChain put the combined insolvency from both router exploits at about $16 million and said it would cover it in three roughly equal parts of about $5.3 million each: a direct contribution from treasury assets, a loan from Iron Bank against RUNE collateral, and arbitrage once trading resumed. Liquidity providers in the affected ERC-20 pools were subsidised.
Sources
- THORChainPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- SlowMist (technical analysis)Secondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/thorchain/post-mortem-eth-router-exploits-1-2-and-premature-return-to-trading-incident-2908928c5fb
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "THORChain ERC-20 Router Exploit hack — July 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/thorchain-erc20-router-2021https://itokenly.com/hacks/thorchain-erc20-router-2021Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.