A day after Thorchain (RUNE) paused all network activity after suffering a $10.8M multichain exploit, the foundation launched a $10M compensation portal to begin returning funds to verified victims.
The breach drained funds across Bitcoin (BTC), Ethereum (ETH), BNB Chain (BNB), and Base, affecting 12,847 wallets.
THORChain contributors now believe the exploit may have originated from inside the validator set itself. In an incident update, the team said evidence points to a newly churned node potentially linked to the attack. Investigators suspect the attacker exploited a flaw in THORChain’s GG20 Threshold Signature Scheme implementation, gradually leaking enough vault key material to reconstruct a private key and authorize unauthorized transactions.
The protocol said recovery discussions now include slashing affected validator bonds and using Protocol-Owned Liquidity reserves to absorb losses. While RUNE transfers could resume once the temporary pause expires, trading, liquidity pool actions and other sensitive operations will remain suspended until the network finalizes a broader remediation plan.
How The Exploit Unfolded
The attack targeted Thorchain's cross-chain liquidity routing layer. Thorchain operates as a decentralized cross-chain swap protocol. It allows users to swap native assets, including BTC, ETH, and BNB, without wrapped tokens or bridges.
The protocol holds liquidity in network-controlled vaults on each supported chain. An attacker identified a vulnerability in the routing logic and extracted funds from vaults across all four networks simultaneously. The multichain nature of the attack is what drove the total loss above the $10M threshold. No single chain bore the full damage.
Thorchain's operators paused all trading after detecting abnormal outflows. The halt prevents further exploitation but also freezes legitimate user funds during the investigation.
Also Read: Dogecoin Pushes At $0.11 Resistance As $3B Volume Tests Recovery





