THORChain halted trading and transaction signing on May 15, 2026 after unauthorized outbound transactions drained approximately $10.7 million from one of the cross-chain protocol’s asset vaults. The event interrupted a network designed to let users exchange native assets across blockchains without relying on a centralized intermediary or conventional wrapped-token bridge.
The loss estimate changed as investigators traced the transfers. THORChain’s first public development-team statement, issued at 11:01 UTC on May 15, estimated the unauthorized outflow at approximately $7.4 million and said the cause had not been determined. By 19:10 UTC, the team had revised the estimate to approximately $10.7 million and identified a vulnerability in its GG20 threshold-signature implementation as the leading explanation.
What the network did
A THORChain incident report published on May 20 reconstructed the response using UTC times and mainnet block numbers. It said the protocol’s solvency checker detected a divergence of more than 1% between expected and observed vault balances on several connected chains. That triggered automatic restrictions, while node operators subsequently coordinated manual pauses and governance votes through THORChain’s Mimir parameter system.
The report recorded trading and signing halts at mainnet blocks 26183438 and 26183439. Global chain observation and validator churn were then halted at blocks 26183590 and 26183849. Pausing churn was significant because the suspected attacker had entered the active validator set on May 13. Preventing that node from leaving preserved evidence and reduced the risk that another unknown node could enter during the investigation.
By the end of May 15, the development team attributed the receiving addresses to a newly churned node and said key material may have leaked progressively during repeated signing activity. The working theory was that the attacker reconstructed a vault private key and produced valid-looking outbound signatures outside the intended multiparty process. That explanation was a contemporaneous protocol claim, not yet a complete independent forensic conclusion.
Why the incident mattered
THORChain’s security model distributed control of vault keys among validators through a threshold-signature scheme. In normal operation, participating nodes jointly authorize transactions without any one node assembling the complete private key. The May 15 incident therefore raised a deeper issue than a compromised user account: it indicated that a participant inside the permissionless validator set might defeat the cryptographic process intended to prevent unilateral vault control.
The network’s segmentation limited the immediate scope. THORChain reported that the other vaults were unaffected, while its automatic and operator-controlled halt mechanisms stopped broader activity. That containment did not make users whole or establish that remaining funds were secure. It demonstrated that circuit breakers could restrict an incident after balances diverged, while also showing that apparently valid signatures could bypass preventive controls before the discrepancy was detected.
Contemporaneous CoinDesk reporting placed the affected assets across Bitcoin, Ethereum, BNB Chain and Base and reported an approximately $10.8 million value, citing Arkham Intelligence for observed wallet balances. The small difference from THORChain’s revised $10.7 million estimate reflects separate observations and valuation timing. Neither source supplied a full audited accounting or a reproducible asset-by-asset pricing timestamp.
Limits of the May 15 record
No completed post-mortem was available on May 15. The precise exploit mechanics, responsibility for the loss and recovery method remained unsettled. Proposals mentioned that day—including validator-bond slashing or using protocol-owned liquidity—were discussion items rather than adopted decisions. This reconstruction therefore does not describe any later restart, reimbursement or software change as an event-day outcome.
The article also excludes an exact RUNE price move. Contemporaneous coverage reported a decline after the incident but did not state a sufficiently precise exchange, start time, end time or benchmark methodology to support a reproducible market-return calculation.
Later context
A July 3 THORChain post-mortem later said the attacker combined three weaknesses in the deployed GG20-related code and induced 864 failed signing steps over roughly two and a half days. That later technical finding clarifies the May 15 event but was not available to market participants when the network first halted.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

