THORChain halts trading after $10.8M cross-chain exploit

THORChain cross-chain exploit drained $10.8 million across Bitcoin and Ethereum

THORChain halted all trading and signing on Friday morning after an attacker drained roughly $10.8 million in crypto across four blockchains. The breach hit deployments on Bitcoin, Ethereum, BNB Smart Chain, and Base, prompting validators to freeze the cross-chain protocol while engineers traced the attack vector. On-chain investigator ZachXBT was first to flag the incident, identifying suspicious activity tied to THORChain’s router infrastructure. RUNE, the protocol’s native token, fell about 12% in the hours after the exploit surfaced, as traders priced in another security setback for one of crypto’s most heavily used bridges.

A cross-chain liquidity protocol is a network that lets users swap native assets like Bitcoin directly for assets on other chains like Ethereum, without wrapping the tokens or routing through a centralized exchange.

Key takeaways

  • THORChain paused trading and signing after an attacker drained about $10.8 million across Bitcoin, Ethereum, BSC, and Base on May 15, 2026.
  • Attacker wallets currently hold 3,443 ETH ($7.77 million), 36.85 BTC ($2.97 million), and 96.6 BNB ($66,000), per Arkham Intelligence.
  • RUNE dropped roughly 12% on the news, extending losses tied to the protocol’s earlier ThorFi insolvency restructuring.
  • This is at least the third major security incident for THORChain, which has been the laundering route of choice in several large exchange hacks.

Published: May 15, 2026, 16:00 UTC

What happened

The exploit surfaced in the early hours of Friday, May 15, 2026, when ZachXBT posted on Telegram that THORChain’s router contracts were being drained. According to CoinDesk, the attacker swept roughly $7.2 million in USDT, USDC, and wrapped Bitcoin across multiple chains, then swapped most of the loot into ETH to avoid centralized stablecoin freezes.

Arkham Intelligence tracked the stolen funds to a Bitcoin address (bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37) holding about 36.75 BTC, and two EVM addresses (0xd477b69551f49C0519F9B18c55030676138890Bd and 0x82fc0d5150f3548027e971ec04c065f3c93154eb) sitting on 3,443 ETH. The exact attack vector has not been disclosed. THORChain validators paused trading and signing to stop further outflows while a post-mortem is prepared.

Why this matters

THORChain is one of the most heavily used cross-chain swap venues in DeFi, with monthly swap volumes that routinely run in the billions. A failure of its router contracts puts every liquidity provider at direct risk, since the protocol pools assets from depositors on each chain rather than locking individual user funds. That design has made THORChain useful for swapping native BTC for ETH without wrapped tokens, and equally attractive to sophisticated attackers.

The incident also lands at a sensitive moment for cross-chain infrastructure. Crypto Briefing notes that bridge-related theft has now exceeded $2.8 billion since 2021. Regulators in Washington, Brussels, and Singapore have flagged bridges as the weakest link in DeFi security, and the new exploit is likely to feed that line of argument as the Senate works the CLARITY Act through floor debate.

THORChain’s security history

Friday’s exploit is not THORChain’s first. In 2021 the protocol was hit by three exploits in a single month, including a $4.9 million drain through its ETH Bifrost module. In January 2025, validators paused the ThorFi lending product after a $200 million debt crisis and converted defaulted liabilities into an equity-style token to keep the network solvent.

The protocol also became infamous in February 2025 as the laundering route for the $1.46 billion Bybit hack. Bybit CEO Ben Zhou later confirmed that the attackers moved 361,255 ETH, about 72% of the stolen funds, through THORChain swaps. That episode forced governance debates about whether the protocol should add screening at the router level, but most proposals were rejected on censorship-resistance grounds.

Impact on users and the market

For liquidity providers, the immediate concern is whether the $10.8 million loss will be socialized across pools or absorbed by the protocol treasury. THORChain has historically used a mix of insurance pool drawdowns and RUNE issuance to cover hacks, which dilutes existing holders. The 12% RUNE drop reflects that pricing in real time.

For traders, the pause means no new swaps between Bitcoin, Ethereum, BSC, Base, and the other connected chains until validators restart signing. Active LPs cannot withdraw collateral during the halt. Per AMBCrypto, several integrated wallets and aggregators have already routed orders to alternative venues such as Chainflip and the Across Protocol.

What comes next

THORChain’s developer team is expected to publish a post-mortem within 48 to 72 hours detailing the exploit path and any proposed mitigations. Validators will need to approve a software patch and restart signing before swaps resume. Recovery negotiations with the attacker, if attempted, would follow the playbook used in past bridge hacks where teams offered a 10% bounty in exchange for the return of remaining funds.

The bigger story is whether institutional integrations, including the wallets and brokerages that route flow through THORChain, pull back. After repeat incidents, even ideologically aligned partners may demand router-level screening or migrate to bridges with formal audits and slashing-backed validator sets.

FAQ

What is THORChain?

THORChain is a decentralized cross-chain liquidity protocol that lets users swap native assets across blockchains such as Bitcoin, Ethereum, BNB Smart Chain, and Base without wrapped tokens or centralized custodians. Liquidity is provided by RUNE holders who deposit paired assets into pools.

How much was stolen in the May 15 exploit?

The attacker drained roughly $10.8 million in crypto assets across four chains, including 3,443 ETH, 36.85 BTC, and 96.6 BNB, according to on-chain analytics from Arkham Intelligence cited by ZachXBT. The figure could shift as more wallets are linked to the attacker.

Will THORChain users be reimbursed?

That decision will be made by validators and RUNE holders through governance. Past THORChain incidents have been covered by a mix of insurance pool drawdowns and new RUNE issuance, which dilutes existing token holders. A formal recovery plan typically follows the public post-mortem.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *