No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

THORChain’s $10M Exploit Caused by MPC Vulnerability, Private Key Leak

May 23, 2026
in Crypto
0
THORChain's $10M Exploit Caused by MPC Vulnerability, Private Key Leak


THORChain said a malicious node operator exploited a vulnerability in its GG20 threshold signature system to drain about $10.7 million from one of the protocol’s vaults.

The GG20 threshold signature scheme is used to secure THORChain vaults by splitting key control across multiple node operators, meaning no single node normally holds the full private key.

The vulnerability allowed the malicious node operator to reconstruct a full private key for one vault, through “progressive key material leakage,” the protocol said in a post-mortem report released on Wednesday.

THORChain said its automatic solvency checks triggered within minutes and halted signing and trading across multiple chains without human intervention. Node operators subsequently coordinated via Discord for a full network halt within two hours after and deployed a patch to fix the vulnerability.

The post-mortem report shows that the protocol’s automatic solvency checks functioned and stopped the exploiter from draining more funds. The report comes a week after blockchain investigator ZachXBT first flagged the $10 million exploit, shortly before THORChain announced a halt to all trading and signing.

The incident adds to a resurgence in crypto exploits, which stole more than $634 million in April, according to DefiLlama data.

Timeline of the $10 million THORChain exploit. Source: THORChain

THORChain weighs recovery path without RUNE sales

THORChain said Friday that the post-exploit recovery path will be determined by a community consensus and published governance proposal ADR-028, with votes currently open for node operators.

The proposal would have THORChain absorb losses first through protocol-owned liquidity and spread the remainder across synth holders. It would deplete protocol-owned liquidity but redirect a portion of protocol income to replenish it over time, without minting or selling THORChain (RUNE) tokens.

ADR-028 community proposal for recovery after $10 million exploit. Source: Gitlab

THORChain also offered a recovery bounty for the return of the stolen funds and said it would slash the attacker’s malicious node while protecting innocent nodes that were placed in the same vault as the exploiter.

Related: Polymarket team says user funds safe as exploit losses climb above $600K

ADR-028 proposes keeping the existing GG20 TSS framework in a patched and upgraded version and said it will resume trading only after the vulnerability is fixed, drawing mixed reactions from crypto industry watchers.

Pseudonymous crypto project analyst Bird said the initial vulnerability suggests that the GG20 TSS signing stack has a “flaw in randomness generation or local signing isolation,” but praised THORChain’s auto-safeguard for limiting the damage done by the exploit.

Other industry watchers were more critical of the decision. “My mental model is that GG20 has many brittle assumptions. You can keep patching it, but it will forever be a bit of a black box,” wrote crypto investor JP in a Wednesday X post.

RUNE/USD, 1-week chart. Source: CoinMarketCap

The RUNE token’s price fell 15.5% in the week following the exploit, but staged a 4% recovery in the 24 hours leading up to 11:00 a.m. UTC on Friday, CoinMarketCap data shows.

Magazine: The legal battle over who can claim DeFi’s stolen millions 

Editorial Team

Editorial Team

Related Posts

Bitcoin ETFs extend outflow streak to sixth day even as BTC reclaims $103k
Crypto

Bitcoin liquidations hit $320M on SEC stock news

May 23, 2026
Bitcoin
Crypto

Bitcoin Bottom May Be 2 Months Away, On-Chain Data Suggests

May 23, 2026
Cointelegraph
Crypto

DeFi Hacks Shake Institutional Confidence as Risks Outpace Yields

May 23, 2026
Binance adds news features to Binance Junior to increase family crypto savings and learning - 1
Crypto

Reelrush wants to turn every viral moment into a tradable market

May 23, 2026
Bitcoin
Crypto

Bitcoin Spot Demand Falls At Fastest Rate Since January — What’s Happening?

May 23, 2026
Cointelegraph
Crypto

Binance Denies WSJ Report Alleging $850M in Iran-Linked Crypto Transactions

May 23, 2026
Load More
Next Post
These 4 market sectors look frothy — and Nvidia’s isn’t even the biggest bubble

These 4 market sectors look frothy — and Nvidia’s isn’t even the biggest bubble

Popular News

  • The 10 best banks for college students in 2025

    The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • Poland Joins The Bitcoin ETF Wave With Warsaw Stock Exchange Debut

    0 shares
    Share 0 Tweet 0
  • Bitcoin Stabilizes At $68K as Fund Flow Ratios Signal An Institutional Standstill

    0 shares
    Share 0 Tweet 0
  • Why You Need To Have Friends At Work

    0 shares
    Share 0 Tweet 0
  • Charlotte Tilbury Skincare & Makeup Bestsellers Review

    0 shares
    Share 0 Tweet 0

Latest News

These 4 market sectors look frothy — and Nvidia’s isn’t even the biggest bubble

These 4 market sectors look frothy — and Nvidia’s isn’t even the biggest bubble

May 23, 2026
0

S&P 500 has a 30% chance of crashing over the next two years. That’s the good news.

THORChain's $10M Exploit Caused by MPC Vulnerability, Private Key Leak

THORChain’s $10M Exploit Caused by MPC Vulnerability, Private Key Leak

May 23, 2026
0

THORChain said a malicious node operator exploited a vulnerability in its GG20 threshold signature system to drain about $10.7 million...

Russia preparing strike on Ukraine using hypersonic ’Oreshnik’ missile, Zelenskiy says

Russia preparing strike on Ukraine using hypersonic ’Oreshnik’ missile, Zelenskiy says

May 23, 2026
0

Russia preparing strike on Ukraine using hypersonic ’Oreshnik’ missile, Zelenskiy says

Bitcoin ETFs extend outflow streak to sixth day even as BTC reclaims $103k

Bitcoin liquidations hit $320M on SEC stock news

May 23, 2026
0

Bitcoin liquidations surpassed $320 million in longs on May 22 after the SEC unexpectedly delayed its tokenized stock plan. Summary...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.