THORChain has launched a recovery portal following a $10 million exploit, enabling affected users across four blockchains to revoke malicious approvals and requestTHORChain has launched a recovery portal following a $10 million exploit, enabling affected users across four blockchains to revoke malicious approvals and request

THORChain Confirms $10M Exploit and Launches Recovery Portal for Users

2026/05/16 18:20
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

THORChain has launched a recovery portal following a $10 million exploit, enabling affected users across four blockchains to revoke malicious approvals and request refunds.

THORChain has confirmed a $10 million exploit and introduced a recovery portal that provides affected users with a self-custodial method to revoke malicious token approvals and file refund claims, supported by a treasury-funded refund pool of the same size.

In a Saturday post on X, the THORChain Foundation introduced the recovery portal, stating that “affected users are now able to check what they will be paid as compensation following the exploit.”

The portal, referencing a post-mortem from PeckShield, stated that the attack was identified at 02:14 UTC on May 11 after node operators detected unusual outbound transactions. Trading and outbound signing activity were paused within eight minutes. In total, attackers stole 36.75 BTC, valued at roughly $3 million, along with nearly $7 million in tokens across BNB Chain, Ethereum, and Base, affecting 12,847 wallets on four different chains.

Affected users have 21 days to file their claims. The refund period ends on June 4, after which any unclaimed allocation will be transferred to the protocol’s insurance fund.

How the THORChain Exploit Unfolded

In an incident update, THORChain said the primary theory is that the attacker exploited a weakness in the GG20 threshold signature scheme (TSS) implementation, allowing sensitive vault key material to leak gradually. By collecting enough of the exposed data over time, the attacker was able to reconstruct the vault’s private key and approve unauthorized outbound transactions.

The protocol also noted that a newly churned node joined the network several days before the attack and is currently suspected of being connected to the incident, with onchain links identified between the node’s bonding addresses and the wallets that received the stolen funds.

“The Treasury is actively collecting forensic data and coordinating with Outrider Analytics and relevant law enforcement agencies in an effort to identify the attacker and pursue recovery of stolen funds where possible,” the protocol wrote.

Crypto Hack Losses Reached $630 Million in April

Crypto hacks surged in April, with total losses climbing to $629.7 million, marking the industry’s worst month since February 2025, when $1.47 billion was stolen. Exploits involving KelpDAO and Drift Protocol accounted for most of the damage, as the $293 million KelpDAO exploit and the $280 million Drift Protocol hack together represented 82% of April’s total losses, further establishing DeFi as the sector most heavily targeted by attackers.

The pattern of recent attacks points to a shift in how protocols are being compromised, with bridges, privileged access, and operational failures increasingly emerging as the main causes behind major incidents rather than simple smart contract vulnerabilities.

시장 기회
Portal 로고
Portal 가격(PORTAL)
$0.009193
$0.009193$0.009193
+1.03%
USD
Portal (PORTAL) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!