THORChain Suffers Another Attack, Losing Tens of Millions of Dollars
On May 15, 2026, decentralized cross-chain liquidity protocol THORChain once again experienced a significant security vulnerability, with estimated losses between $10 million and $11 million. This attack involved multiple blockchain networks, including Bitcoin, Ethereum, BNB Chain, and Base, with some reports indicating the attack spanned at least nine chains. This marks THORChain's fourth notable security incident since 2021, once again raising market concerns about the protocol's security and the safety of user funds.

Attack Details and RUNE Market Reaction
The root cause of this attack was a flaw in the implementation of the GG20 Threshold Signature Scheme (TSS), which allowed malicious node operators to reconstruct the full private key by progressively leaking key material. THORChain's emergency protocol (Mimir governance module) quickly detected abnormal activity and automatically paused signing and transactions within minutes, effectively limiting further losses. The protocol resumed trading, swaps, and liquidity provision operations on June 23, 2026, after being paused for approximately five weeks.

Following this news, the price of THORChain's native token, RUNE, experienced significant volatility within hours of the attack being reported on May 15, 2026. RUNE's price fell from above $0.58 to around $0.50, a drop of approximately 11% to 15%. On that day, RUNE's market capitalization was approximately $180.52 million, with daily trading volume surging to $24.49 million, reflecting market panic selling. Looking at monthly data, RUNE opened May 2026 at approximately $0.507518 and closed at $0.415191, a monthly decline of 18.19%.
THORChain's Past Security Incidents Review

THORChain is no stranger to security challenges. Previously, the protocol suffered two attacks in July 2021, including a vulnerability involving the ETH router. Additionally, in 2025, THORChain co-founder JP Thorbjornsen lost approximately $1.2 million to $1.35 million in personal funds due to a sophisticated scam involving a compromised Telegram account and deepfake video calls, an attack believed to be linked to North Korean hacking groups. Cumulatively, since 2021, the total losses related to the THORChain protocol and its founder have approached $25 million.
Team Response and Industry Perspectives

The THORChain team quickly confirmed the May 2026 attack, emphasizing that primarily protocol-owned funds (a stolen vault) were affected, and user funds remained safe. The team deployed emergency patches and completed a major vulnerability fix upgrade on June 9. Simultaneously, THORChain denied any false information regarding "refunds," "airdrops," or compensation plans, warning users to be vigilant against scams. In its recovery plan, the team considered slashing the collateral of malicious validator nodes and absorbing part of the losses through Protocol Owned Liquidity (POL), or deciding on a compensation scheme through community governance.
On-chain analysts such as ZachXBT and security firms like PeckShield were among the first to identify and report the attack, with Arkham Intelligence also tracking the stolen assets. Some industry analysts have expressed concern about THORChain retaining the GG20 Threshold Signature System after the fix, believing it may have inherent flaws that make complete security difficult to guarantee. As a cross-chain bridge that does not require wrapped assets, THORChain offers convenience but has also faced criticism for its decentralized and "anti-censorship" stance, having refused to block illicit activities (such as money laundering by North Korean hackers). This highlights the dual challenges of security and regulatory compliance in decentralized cross-chain transactions.








