THORChain exploited via malicious node compromise of GG20 TSS signing stack, draining $10.7M across multiple chains before network self-halted.
Security & Exploits ·
On May 15, 2026, a malicious node compromise of THORChain's GG20 TSS signing stack led to the theft of $10.7 million across multiple chains. According to initial reports, one of six Asgard vaults was drained after attackers leaked vault key material, reconstructed the private key offline, and executed rapid outflows. The network's auto-solvency checker—a security measure implemented after a previous 2021 exploit—automatically halted operations for approximately 12 hours and 42 minutes, freezing all signing and trading activity before the stolen funds could be moved further.
The scope of the breach expanded as on-chain data emerged. TRM Labs later confirmed losses across at least nine chains including Bitcoin, Ethereum, BSC, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP, with total losses revised past $11 million. PeckShield publicly confirmed approximately $10 million drained, including 36.75 BTC and roughly $7 million in assets across multiple networks. Node operators managing the compromised vault faced slashed RUNE bonds, and the Mimir governance module automatically triggered the network pause without human intervention.
A security patch addressing the vulnerability class existed for nine days before the exploit occurred—a GitLab commit from May 6 titled "sign full ObservedTx wrapper to prevent proposer forgery" had been authored but apparently not applied to the affected infrastructure. Whether the patch was incompletely deployed, overlooked, or deliberately bypassed remains undisclosed. No individual user swaps were reportedly affected, and alternative routing providers continued operating uninterrupted throughout the incident.