DEFENCE / RADAR

Public snapshot

THORChain·Crypto / Web3·

Approximately $10.7 million was drained from a vault.

THORChain said a malicious node exploited a GG20 flaw, draining about $10.7 million before signing and trading were halted. The attached record does not establish the complete downstream scope.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: Vulnerability in the GG20 Threshold Signature Scheme
Consequence
Confirmed: Approximately $10.7 million was drained from a vault.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
THORChain
Industry
Crypto / Web3
Disclosed
Entry path
Exploited Vulnerability
Affected asset
A single vault
Product / vendor
GG20 Threshold Signature Scheme
Data involved
Crypto Assets
Documented impact
Asset theft
Attached evidence
3 independent domains · 3 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved exploited vulnerability.

    ConfidencePrimary
    Exact excerpt

    exploited a vulnerability in the GG20 Threshold Signature Scheme

    blog.thorchain.org · May 20
    E1
  2. 02

    Reported cause

    Vulnerability in the GG20 Threshold Signature Scheme

    ConfidencePrimary
    Exact excerpt

    exploited a vulnerability in the GG20 Threshold Signature Scheme

    blog.thorchain.org · May 20
    E2
  3. 03

    Affected product

    GG20 Threshold Signature Scheme

    ConfidencePrimary
    Exact excerpt

    vulnerability in the GG20 Threshold Signature Scheme

    blog.thorchain.org · May 20
    E3
  4. 04

    Reached

    A single vault

    ConfidencePrimary
    Exact excerpt

    drained approximately $10.7M from a single vault

    blog.thorchain.org · May 20
    E4
  5. 05

    Observed

    Approximately $10.7 million was drained from a vault.

    ConfidenceConfirmed
    Exact excerpt

    drained approximately $10.7M from a single vault

    blog.thorchain.org · May 20
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • That a Defence review would have prevented this incident

4)Relevance to your product

A single protocol invariant can carry the weight of the complete asset path.

This pattern applies when…

  • Products that implement threshold-signature or vault authorization logic.

Diagnostic questions

  1. Do value and authorization invariants hold across every contract path?
  2. Can one actor manipulate pricing, accounting or bridge state out of sequence?
  3. Are privileged operations bounded under adversarial composition?

This incident does not establish your product's risk.

5)Sector context — Crypto / Web3

126 incident threads in the 365-day public record
  1. 0 incident threads
  2. 1 incident threads
  3. 1 incident threads
  4. 0 incident threads
  5. 15 incident threads
  6. 15 incident threads
  7. 6 incident threads
  8. 15 incident threads
  9. 17 incident threads
  10. 14 incident threads
  11. 16 incident threads
  12. 26 incident threads
Same incident family
98
Protocol exploit
Confirmed share
14%
18 confirmed · 108 reported
Display family
Vulnerability exploitation
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Crypto / Web3 in Radar →

6)Defence control mapping

Context-only control area

Protocol and contract control area

  • Do value and authorization invariants hold across every contract path?
  • Can one actor manipulate pricing, accounting or bridge state out of sequence?
  • Are privileged operations bounded under adversarial composition?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

3 attached sources across 3 independent domains. At least one primary source is attached.

  1. E1, E2, E3, E4, E5
    blog.thorchain.orgTHORChain Exploit Report #1 | THORChainOrganization statement · May 20 · Primary
    Organization statementPrimary
    Exact excerpt
    drained approximately $10.7M from a single vault
  2. S2
    financefeeds.comTHORChain Suspends Trading Following Suspected Exploit Across Bitcoin and EthereumOther public report · May 15 · Attached
    Other public reportAttached
  3. S3
    cointelegraph.comTHORChain's $10M Exploit Caused by MPC Vulnerability, Private Key LeakOther public report · May 22 · Attached
    Other public reportAttached

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →