Skip to main content
Back to overview
Medium

THORChain Security Breach

Cryptocurrency platform THORChain, based in Switzerland, encountered a security breach that led to the theft of about $10.7 million.

Key points

  • Cryptocurrency platform based in Switzerland.
  • Theft of approximately $10.7 million.
  • Exploit on May 15, 2026, targeting a vulnerability in the GG20 threshold signature scheme.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Hacking

Threat source not confirmed

03

Potential impact

Potential business exposure

Impact remains under assessment

Published
May 18, 2026
Updated
Jun 25, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch internet-facing systems, credential abuse and exploit activity.

Business impact

Potential business exposure
Impact area
Unknown

Mentioned entities

ThorchainTHORChainSwitzerlandGG20CryptocurrencySwitzerland. Theft ofExploit

Quick context

Questions about this signal

What happened in this signal?

Cryptocurrency platform THORChain, based in Switzerland, encountered a security breach that led to the theft of about $10.7 million. The exploit occurred on May 15, 2026, when a vulnerability in the GG20 threshold signature scheme was exploited by a newly churned node operator, leading to funds being drained from one of its six vaults. The incident was reported in a threat intelligence report on May 18, 2026, and trading was halted.

When was this signal reported?

Shadow Tier lists May 18, 2026 as the signal date.

Which organization is connected to this signal?

Thorchain is the organization connected to this public signal.

Explore Thorchain