Just in:
Abu Dhabi launches AI training to accelerate government transformation // Gold reaches weekly peak as oil prices retreat // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // BINGXUE Opens First U.S. Store in Davis, California: Shandong’s First Mass-Market Tea Beverage Brand Enters North America // Saudi Arabia and UAE endorse Japan’s Asian oil initiative // India establishes 5.56 km open-air quantum security link // Malicious GitHub workflows expose credentials across hundreds of repositories // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // LANDMARK Launches ‘Destination CENTRAL’: A District-Wide Invitation to Explore the Dynamism, Luxury, and Soul of Central // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // OpenAI extends GPT-6 access with interactive ChatGPT interface // Wikimedia identifies unauthorised OpenAI agent activity across platforms // Abu Dhabi climate summit records over 1,000 registrations // Dubai property sales slump as war pressures prices // React flaw exposes Next.js servers to service disruption // UAE delegation heads to Bangkok for IMF meetings // ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year //

THORChain exploit exposes cross-chain security fault

THORChain has halted core network activity after a coordinated exploit drained about $10.7 million from one of its liquidity vaults, putting fresh scrutiny on the security model behind decentralised cross-chain swaps.

The incident took place on May 15 and affected a single vault within the protocol’s infrastructure. Early estimates placed the loss lower, but subsequent checks revised the figure to about $10.7 million. The remaining vaults were not drained, while Solana-linked assets were described as unaffected because they rely on a different signing architecture.

The breach centred on a malicious node operator that entered the active validator set two days before the theft. The operator was assigned to a vault and later exploited a weakness in the GG20 threshold signature system, a cryptographic process used to allow multiple node operators to approve transactions without any one participant holding a full private key. The vulnerability allowed the attacker to reconstruct key material for one vault and broadcast unauthorised outbound transactions directly.

THORChain’s automatic solvency monitoring detected abnormal balance changes within minutes. Trading and signing functions were halted across multiple chains, including Ethereum, BNB Chain, Base, Avalanche, Dogecoin and Cosmos-related infrastructure. Node operators then used emergency governance controls to extend the halt across trading, signing, observation and validator churning, preventing the suspected malicious node from exiting the network or further activity from spreading.

The attack exposed the delicate balance in decentralised finance between automation, distributed control and operational risk. THORChain was designed to support native asset swaps across blockchains without relying on wrapped tokens or centralised custodians. That structure has made it one of the better-known cross-chain liquidity networks, but it also means that any weakness in validator coordination, vault signing or infrastructure design can carry multi-chain consequences.

The stolen assets were traced across Bitcoin, Ethereum, BNB Chain and Base-linked routes, with the attacker moving funds in a sequence of smaller and larger transactions. Initial activity suggested testing before the full sweep, a pattern commonly seen when an attacker verifies that a route can be used before extracting higher-value balances. The targeted vault contained protocol-owned liquidity rather than direct user deposits, though the distinction may still matter little to holders if recovery costs are spread through the system.

The protocol’s developers released patch version 3.18.1 as an immediate safeguard while investigators continued to assess the root cause. A fuller recovery plan is being handled through community governance under ADR-028, which is expected to determine how losses are absorbed and how operations resume. Options under discussion include using protocol-owned liquidity, adjusting synthetic asset positions and directing future protocol income towards replenishing reserves.

RUNE, THORChain’s native token, came under pressure after the exploit, falling sharply as traders weighed the size of the loss against the network’s ability to contain further damage. The token remains central to the protocol’s economic security model, as node operators must bond RUNE to participate in validation and vault operations. Any prolonged weakness in confidence can therefore affect both liquidity and network participation.

The exploit also raises questions for other projects using similar threshold-signature systems. GG20-style signing is intended to reduce single-key risk by distributing control among multiple parties. The THORChain incident shows that implementation flaws, poor randomness generation, signing isolation weaknesses or compromised participant behaviour can still create severe exposure if safeguards fail before key material is reconstructed.

Developers have withheld some technical details to avoid giving attackers a ready blueprint before other systems can check their own implementations. That delay is common after cryptographic infrastructure failures, where full disclosure must be balanced against the risk of copycat attacks. Security teams are also examining whether the attack depended solely on THORChain’s implementation or whether it indicates a wider class of risks for comparable deployments.

Cross-chain protocols remain a major target because they concentrate liquidity while interacting with several blockchains at once. Bridges and multi-chain liquidity networks have accounted for some of the largest digital-asset thefts of the past five years, with attackers repeatedly exploiting validator compromises, signature weaknesses, smart-contract bugs and operational lapses. Even when user funds are not directly drained, protocol-owned losses can weaken balance sheets, force governance trade-offs and reduce confidence among liquidity providers.

Arabian Post – Crypto News Network



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // Wikimedia identifies unauthorised OpenAI agent activity across platforms // Almarai earmarks $4 billion for expansion through 2031 // Bypoll Results In Bengal And Assam Underline BJP’s Expansion In Eastern Region // BINGXUE Opens First U.S. Store in Davis, California: Shandong’s First Mass-Market Tea Beverage Brand Enters North America // Two Bypoll Results In Bengal Vindicate State BJP’s Success In Courting Minorities // Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // India establishes 5.56 km open-air quantum security link // LANDMARK Launches ‘Destination CENTRAL’: A District-Wide Invitation to Explore the Dynamism, Luxury, and Soul of Central // Saudi Arabia and UAE endorse Japan’s Asian oil initiative // UK and allies expose Integrity Tech cyber operations // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // Anti-Election Commission Protest: Athletic Rahul Steals The Show // First Week Of Anti-CEC Agitation Turns Into Electoral Rights Movement // India rebuts Musk allegations over Starlink launch delay // Lufthansa and three airlines halt Riyadh flight operations // Gold reaches weekly peak as oil prices retreat // React flaw exposes Next.js servers to service disruption //