TLDR
THORChain (RUNE), a cross-chain DEX, has brought trading back online after halting its network due to a roughly $10.7 million exploit in May.
- THORChain paused on 15 May after a vault exploit drained about $10.7 million from one of six Asgard vaults, then resumed trading after more than a month offline.
- The team attributes the hack to a GG20 threshold signature bug, has shipped multiple security upgrades, migrated vaults, and verified all keyshares before restoring swaps and liquidity actions.
- Cross-chain swaps are live again, but the incident underlines structural bridge risk, so users should watch future audits, incident reports, and upcoming Monero and Zcash integrations.
Deep Dive
1. What Happened In The Exploit
THORChain is a decentralized cross-chain liquidity protocol that lets users swap native BTC, ETH and other assets across chains without wrapping or using centralized bridges. It paused trading on 15 May after investigators ZachXBT and PeckShield flagged an exploit affecting Bitcoin, Ethereum, BNB Chain and Base, with about $10.7 million drained from one of six Asgard vaults while the other five remained intact as reported when the protocol resumed trading after over five weeks offline.
During the shutdown, swaps, signing, and liquidity provider actions were disabled while the team focused on containment and forensic checks rather than speed of restart.
2. Fixes Implemented Before Restart
THORChains post mortem ties the exploit to a flaw in its GG20 threshold signature scheme, which distributes control of vault keys across node operators. A malicious node could reconstruct a full private key through progressive key material leakage, enabling the theft according to a detailed recovery update.
The protocol deployed an emergency patch on 20 May to protect remaining vaults, followed by a major upgrade on 9 June to fix the vulnerability and a further upgrade on 11 June to harden the KeyVerify protocol and add stability improvements. Every nodes keyshare was verified, legacy vaults were retired, and funds migrated before the network resumed full trading, signing and LP actions.
The restart is based on structural changes to key management, not just turning the system back on, but residual risk still exists like with any complex cross-chain infrastructure.
3. Impact For Users And What To Watch
For users, cross-chain swaps and liquidity operations on THORChain are now available again, restoring one of the few venues for native BTC and privacy coin routing across chains. Price reaction in RUNE has been modest, with reports noting the token stayed relatively flat around the restart announcement.
At the same time, THORChain has drawn scrutiny because past hackers have used it to launder stolen funds, and this exploit adds to an already heavy 2026 DeFi hack tally. The team plans new integrations, including native swaps and vaults for Zcash and Monero plus Bittensor support in the coming weeks, according to its roadmap of post-recovery upgrades.
Liquidity and functionality should improve if users return, but security reputation and future incident handling will heavily influence how much capital is willing to stay on the protocol.
Conclusion
THORChains return to full trading after a $10.7 million exploit shows that the team prioritized deep changes to its key management and vault design rather than a quick reboot. For crypto users, it restores a key cross-chain venue but also reinforces that bridges and interoperability protocols remain among the highest risk parts of DeFi, making ongoing security upgrades and transparent post mortems essential signals to monitor.
