THORChain·Crypto / Web3·
Approximately $10.7 million was drained from a vault.
THORChain said a malicious node exploited a GG20 flaw, draining about $10.7 million before signing and trading were halted. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: Vulnerability in the GG20 Threshold Signature Scheme
- Consequence
- Confirmed: Approximately $10.7 million was drained from a vault.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- THORChain
- Industry
- Crypto / Web3
- Disclosed
- Entry path
- Exploited Vulnerability
- Affected asset
- A single vault
- Product / vendor
- GG20 Threshold Signature Scheme
- Data involved
- Crypto Assets
- Documented impact
- Asset theft
- Attached evidence
- 3 independent domains · 3 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved exploited vulnerability.
ConfidencePrimaryExact excerpt
E1“exploited a vulnerability in the GG20 Threshold Signature Scheme”
blog.thorchain.org · May 20 - 02
Reported cause
Vulnerability in the GG20 Threshold Signature Scheme
ConfidencePrimaryExact excerpt
E2“exploited a vulnerability in the GG20 Threshold Signature Scheme”
blog.thorchain.org · May 20 - 03
Affected product
GG20 Threshold Signature Scheme
ConfidencePrimaryExact excerpt
E3“vulnerability in the GG20 Threshold Signature Scheme”
blog.thorchain.org · May 20 - 04
Reached
A single vault
ConfidencePrimaryExact excerpt
E4“drained approximately $10.7M from a single vault”
blog.thorchain.org · May 20 - 05
Observed
Approximately $10.7 million was drained from a vault.
ConfidenceConfirmedExact excerpt
E5“drained approximately $10.7M from a single vault”
blog.thorchain.org · May 20
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Not publicly established
No qualifying public evidence in the attached record.
- That a Defence review would have prevented this incident
4)Relevance to your product
A single protocol invariant can carry the weight of the complete asset path.
This pattern applies when…
- Products that implement threshold-signature or vault authorization logic.
Diagnostic questions
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
This incident does not establish your product's risk.
5)Sector context — Crypto / Web3
- 0 incident threads
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 15 incident threads
- 15 incident threads
- 6 incident threads
- 15 incident threads
- 17 incident threads
- 14 incident threads
- 16 incident threads
- 26 incident threads
- Same incident family
- 98 Protocol exploit
- Confirmed share
- 14% 18 confirmed · 108 reported
- Display family
- Vulnerability exploitation Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Crypto / Web3 in Radar →6)Defence control mapping
Context-only control area
Protocol and contract control area
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
3 attached sources across 3 independent domains. At least one primary source is attached.