THORChain halts trading after $10M cross-chain exploit

THORChain exploit drained $10M across four blockchains

THORChain halted all trading and signing operations on May 15, 2026, after an attacker drained roughly $10.8 million from the cross-chain liquidity protocol in a coordinated raid across Bitcoin, Ethereum, BNB Chain, and Base. On-chain investigator ZachXBT first flagged the incident, and blockchain security firm PeckShield confirmed losses spanning four networks. Attacker wallets now hold about 3,443 ETH, 36.85 BTC, and 96.6 BNB. RUNE, THORChain’s native token, fell 12% on the news and was trading near $0.59 with a market cap around $208 million, according to CoinGecko.

A cross-chain bridge is a piece of software that lets users move assets between separate blockchains, typically by locking tokens on one chain and minting or releasing equivalents on another. THORChain is one of the largest decentralized liquidity protocols offering this service, and bridges as a category have absorbed more than $2.8 billion in cumulative losses since 2021.

Key takeaways

  • Attackers moved about $10.8 million across four chains on May 15, 2026; THORChain’s Mimir governance module activated trading and signing halts for roughly 12 hours and 42 minutes from block 26190429.
  • Linked wallets hold 3,443 ETH ($7.77M), 36.85 BTC ($2.97M), and 96.6 BNB ($66K), per ZachXBT and PeckShield.
  • RUNE dropped 12% on the news; the token trades near $0.59 against a $208M market cap.
  • THORChain has not yet published a post-mortem identifying the attack vector.

Published: May 15, 2026 UTC

What happened

The exploit was first flagged on Telegram by ZachXBT, who initially estimated $7.4 million in losses before revising the figure upward to roughly $10.7 million as more wallets were traced. PeckShield’s count came in slightly higher at about $10.8 million across BTC, ETH, BNB Chain, and Base. According to ZachXBT, the attacker swept USDT, USDC, and wrapped Bitcoin into ETH before bridging through THORChain itself.

THORChain’s response came from its Mimir governance module, which flipped the trading-halt and signing-halt parameters to active. The pause ran for approximately 12 hours and 42 minutes starting at block 26190429, halting swaps and validator signing across the network. As of publication, the protocol had not released a post-mortem identifying the specific attack vector, leaving open whether the loss originated from a code flaw, a validator key compromise, or a hostile use of THORChain’s bridging functions to launder funds stolen elsewhere.

Why this matters

Cross-chain bridges sit at the center of a long-running security problem in DeFi. The category has lost more than $2.8 billion since 2021, and THORChain itself has been targeted before: three logic-flaw exploits in 2021 cost the protocol nearly $16 million combined, and a 2023 halt followed reports of a separate vulnerability.

The 2026 incident also lands in a charged compliance environment. TRM Labs reported earlier this year that North Korean operators accounted for 76% of crypto hack losses in 2026, and that THORChain has repeatedly served as the bridge of choice for laundering proceeds from the Bybit and KelpDAO heists. Whether Friday’s exploit was a direct attack on THORChain or another instance of stolen funds passing through it, the protocol’s role as the largest neutral cross-chain swap venue keeps drawing regulatory attention.

What comes next

Three things will shape the next few days. First, the post-mortem: if THORChain identifies a code or validator flaw, expect a patch and a governance vote on validator slashing or treasury reimbursement, similar to past incidents. If the protocol concludes it was used as a laundering rail rather than directly hacked, the conversation shifts to whether validators should be able to freeze suspicious flows, a step THORChain has historically resisted.

Second, the token. RUNE’s 12% drop reflects how quickly traders price security risk into liquidity protocols. A clean technical explanation and visible remediation tend to compress that discount within days; an unresolved root cause does not.

Third, the regulatory angle. U.S. lawmakers cleared the Clarity Act in the Senate Banking Committee on May 14, the day before the THORChain halt. Bridge exploits with a North Korea overhang give the bill’s critics fresh material on illicit-finance risks, and they give the SEC and CFTC a live example as they negotiate jurisdiction over DeFi protocols.

FAQ

How much was stolen in the THORChain exploit?

Attackers drained about $10.8 million across Bitcoin, Ethereum, BNB Chain, and Base on May 15, 2026. ZachXBT and PeckShield traced wallets holding roughly 3,443 ETH, 36.85 BTC, and 96.6 BNB. THORChain has not yet released a post-mortem confirming the exact attack path.

Why did RUNE drop after the exploit?

RUNE fell 12% because traders price security risk directly into liquidity protocols. THORChain halted trading and signing for nearly 13 hours, signaling that operators saw the threat as severe enough to suspend the entire network. The token traded near $0.59 in the hours after the halt.

Has THORChain been hacked before?

Yes. Three exploits in 2021 cost THORChain close to $16 million combined, and the network halted again in 2023 over a separate vulnerability. Cross-chain bridges as a category have lost more than $2.8 billion since 2021.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *