# THORChain halts trading after $10 million exploit

**Published:** 2026-05-15T11:36:40.000Z  
**Topic:** Bitcoin  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/4b7cd520-709a-402e-9efc-ce072ea2d70a

THORChain paused all trading and signing after a suspected $10.7 M exploit via a GG20 vulnerability, sending RUNE down 13% to $0.51.

THORChain’s cross‑chain liquidity protocol stopped all trading and signing on May 15 2026 after a malicious node exploited a GG20 threshold‑signature flaw, draining roughly $10.7 million from a single vault [2].

| At a glance | |
|---|---|
| Exploit size | ~$10.7 million |
| RUNE price | $0.51 (‑13% on day) |
| Network pause | ~12 h 42 min (until block 26191149) |
| Catalyst | GG20 TSS vulnerability & automatic solvency halt |

## Exploit details and immediate response  
The breach was traced to a newly‑joined node operator who used a “progressive key material leakage” attack to reconstruct the full private key of one vault, bypassing the GG20 scheme that normally splits key control among multiple nodes [2]. Within minutes, THORChain’s automatic solvency checker flagged the anomaly, triggering an automatic halt of signing and trading across Bitcoin, Ethereum, BNB Chain and Base [2]. Node operators then coordinated via Discord, extending the pause for roughly 12 hours and 42 minutes (block 26191149) while deploying a patch (v3.18.1) to protect the remaining four vaults [1][2].

## Market impact and recovery plan  
RUNE, the native token of THORChain, fell about 13% to near $0.51 after the exploit was reported, extending a year‑long decline of roughly 72% [1]. The token’s weekly drop of 15.5% was partially offset by a 4% rebound in the 24 hours preceding the pause [2]. THORChain’s post‑mortem outlines a recovery path that avoids minting or selling RUNE; instead, losses will be absorbed by protocol‑owned liquidity and later replenished from protocol income, subject to community governance (ADR‑028) [2]. A bounty for returning the stolen funds and a slash of the attacker’s node were also announced [2].

## Broader context  
The incident adds to a surge of DeFi hacks that stole over $634 million in April, the highest monthly total since the $1.46 billion breach of Bybit in February 2025 [1]. THORChain has previously been used to swap stolen assets, including $910 k from the Kelp DAO hack and the bulk of the $1.4 billion Bybit loss [1]. The GG20 vulnerability highlights ongoing concerns about the robustness of threshold‑signature schemes, with some analysts questioning the long‑term viability of GG20 and noting that a migration to DKLS was already planned but delayed [2].

## What to watch
- **Price levels:** RUNE support at $0.48 and resistance near $0.60 as the token tests recovery momentum.  
- **Governance outcome:** Results of ADR‑028 voting on loss absorption and liquidity replenishment.  
- **Technical upgrades:** Deployment of the patched GG20 version and any timeline for the planned DKLS migration.

The pause demonstrates THORChain’s ability to limit damage through automated safeguards, but the exploit underscores the need for stronger cryptographic controls and raises questions about how quickly the protocol can restore confidence and recover the stolen assets.

## Sources
1. Tradingview — [THORChain pauses trading after suspected $10M exploit — TradingView News](https://www.tradingview.com/news/cointelegraph:566bae2b4094b:0-thorchain-pauses-trading-after-suspected-10m-exploit/)
2. CoinTelegraph — [THORChain exploit tied to malicious node and GG20 flaw](https://cointelegraph.com/news/thorchains-10m-exploit-mpc-vulnerability-private-key-leak)
3. Blog — [THORChain Exploit Report #1 | THORChain](https://blog.thorchain.org/thorchain-exploit-report-1)

---
Cite as: TrendWatcher, "THORChain halts trading after $10 million exploit", https://www.trendwatcher.in/article/4b7cd520-709a-402e-9efc-ce072ea2d70a
