THORChain vault drained of $10M on May 15 via GG20 zero-day vulnerability after 864 failed signing rounds.
Security & Exploits ·
THORChain suffered a $10.7M vault drain in May 2026 stemming from a vulnerability in its GG20 threshold signature scheme, according to the protocol's exploit report. The incident forced a complete network halt and was attributed to a newly churned node operator. The exploit followed 864 failed signing rounds, exposing a zero-day flaw in the cryptographic mechanism that secures cross-chain assets held in Asgard vaults.
THORChain's validator network collectively controls these vaults through threshold signatures—a system designed so no single operator can authorize fund movements alone. The compromise of this layer triggered a five-week trading suspension while the protocol activated a treasury-backed recovery plan and drafted new security tools, including KeyVerify checks to validate keyshares before vault churn events. The incident highlighted operational risks in decentralized cross-chain infrastructure even as the protocol continued expanding to support native Monero swaps and other assets.
The recovery sequence included node approval of an ADR028 recovery plan and deployment of v3.19.0 to stagenet, though the specific mechanics of how the attacker exploited the GG20 implementation and the full scope of assets at risk during the 864 signing failures remain incompletely detailed in public disclosures. Whether the vulnerability has been fully remediated or poses residual risks to ongoing operations is not yet clarified.