THORChain vault drain, about $11M across nine chains, GG20 Threshold Signature Scheme flaw suspected (Switzerland-based protocol)
On 2026-05-15 an attacker drained approximately $11M, by THORChain's initial indications protocol-owned funds only, from THORChain, a Switzerland-based decentralised cross-chain liquidity protocol founded in 2018, after one of its six vaults was compromised, across Bitcoin, Ethereum, BNB Smart Chain, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP (The Record, 2026-05-15; TRM Labs, 2026-05-15). The leading technical hypothesis, supported by analysis from PeckShield, Cyvers and security teams collaborating with THORChain's core developers according to CryptoTimes's post-mortem synthesis on 2026-05-17, is a GG20 Threshold Signature Scheme (TSS) implementation flaw: a validator node that had joined the active set only days before the attack is flagged as the likely entry point, suspected of gradually leaking vault key shards during keygen and signing rounds until enough key material could be reconstructed offline to forge outbound vault signatures without triggering normal quorum checks (CryptoTimes, 2026-05-17). THORChain's Incident Update #1 on 2026-05-16 confirmed the malicious-node vector, CryptoTimes reports (CryptoTimes, 2026-05-17). CryptoTimes records verbatim: "the operator (or a compromised machine acting as the operator) exploited a vulnerability in the GG20 Threshold Signature Scheme implementation. Rather than a single dramatic key compromise, the attack appears to have involved the gradual leakage of vault key material during keygen or signing rounds, the kind of malformed-proof exploitation that the TSSHOCK class of CVEs first put on the industry's radar a few years ago." Chainalysis shared an on-chain analysis thread on 2026-05-16 linking attacker-controlled wallets to weeks of preparatory infrastructure staging through Monero and Hyperliquid before the vault drain (CryptoTimes, 2026-05-17). TRM Labs traced the proceeds to a two-address cluster within hours but has not attributed the exploit to any specific actor as of disclosure (TRM Labs, 2026-05-15). TRM notes that THORChain has become the bridge of choice for laundering North Korea's largest thefts, including the $1.5B Bybit and nearly $300M KelpDAO hacks, but no North Korean attribution is confirmed for this event (TRM Labs, 2026-05-15). THORChain said initial indications were that user funds were safe and only protocol-owned funds were affected (The Record, 2026-05-15). Two related but separate 2023 disclosures showed that a single malicious participant in GG18/GG20 threshold signing can extract other parties' key material. Fireblocks' CVE-2023-33241 rests on parties not checking that a participant's Paillier modulus is well formed, which Fireblocks recommends detecting with a suitable zero-knowledge proof (Fireblocks, 2023-08-09). Verichains' TSSHOCK attacks exploit weak or insecurely implemented zero-knowledge proofs, such as ambiguous transcript encoding and a reduced number of proof iterations, in most GG18, GG20 and CGGMP21 implementations by Verichains' account (Verichains, 2023-08-10). If the working theory holds, the THORChain exploit is that class of weakness in production, though CryptoTimes says only that the attack "appears to have involved" key-material leakage (CryptoTimes, 2026-05-17).
THORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million.
At the time of writing, TRM has not attributed the May 15 exploit to any specific actor.
the operator (or a compromised machine acting as the operator) exploited a vulnerability in the GG20 Threshold Signature Scheme implementation. Rather than a single dramatic key compromise, the attack appears to have involved the gradual leakage of vault key material during keygen or signing rounds, the kind of malformed-proof exploitation that the TSSHOCK class of CVEs first put on the industry's radar a few years ago.
The analysis above described CVE-2023-33241 as part of the TSSHOCK class. CVE-2023-33241 is Fireblocks' GG18/GG20 Paillier-key disclosure (Fireblocks, 2023-08-09), and TSSHOCK is Verichains' separate set of key-extraction attacks (Verichains, 2023-08-10). Fireblocks' flaw lies in an unchecked Paillier modulus, which it recommends detecting with a suitable zero-knowledge proof, while TSSHOCK exploits weak or insecurely implemented zero-knowledge proofs. Both let a single malicious participant extract key material (Fireblocks, 2023-08-09; Verichains, 2023-08-10).
The account of the attack above was also narrowed to its sources. The Record reports a compromised vault. The malicious validator node is the vector THORChain's first incident update confirmed, according to CryptoTimes, and the GG20 flaw is the working theory CryptoTimes reports, supported by PeckShield, Cyvers and security teams working with THORChain rather than Chainalysis (CryptoTimes, 2026-05-17). TRM Labs calls THORChain the bridge of choice for laundering North Korea's largest thefts without naming the Lazarus Group or saying such activity dominates (TRM Labs, 2026-05-15).