Chainalysis tracks the source of the THORChain attack: skilled in money laundering, the attack was carried out weeks after cross-chain fund movements

By: www.chaincatcher.com|2026/05/18 23:57:25

Chainalysis posted on the X platform that before the theft of THORChain, wallets suspected to be associated with the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several weeks. The attacker-associated wallets had already deposited into Hyperliquid positions via the Hyperliquid and Monero privacy bridge as early as the end of April. The funds were then exchanged for USDC and transferred to Arbitrum, and later bridged to Ethereum, with some ETH subsequently transferred to THORChain to become staked RUNE for newly added nodes, which are believed to be the source of the attack.

Afterward, the attacker bridged some RUNE back to Ethereum and split it into four pathways, one of which went directly to the attacker. After being transferred through intermediate wallets, 8 ETH was sent to the final wallet receiving the stolen funds 43 minutes before the attack. The funds from the other three pathways flowed in the opposite direction. These wallets bridged ETH back to Arbitrum, deposited it into Hyperliquid, and transferred it into Monero through the same privacy bridge, with the last transaction occurring less than 5 hours before the attack began.

As of Friday afternoon, the stolen funds have not yet been used, but the attacker has demonstrated their skilled cross-chain money laundering capabilities, and the Hyperliquid to Monero path may become the next move.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

THORChain Soft Launch Integrates Monero, ADR31 and ADR27 Proposals Passed, v3.20 Enters Testing

DeFi has reached its most dangerous moment: the real vulnerabilities are not in the code

April 2026 is not just a security crisis; it is the moment when the industry's mental model completely collapses, and it is also the moment when the protocols that can survive are distinguished from those that cannot.

THORChain has released a recovery plan for the attack incident, and voting for node operators has begun

THORChain has released its fourth update regarding the attack incident on May 15, and the proposal ADR028 has been announced, with voting for node operators now open.According to the recovery plan, the protocol will first absorb losses through its own liquidity, with the remaining portion to be shar...

Cryptocurrency Market Update: Major Developments and Insights

Key Takeaways Sky co-founder Rune Christensen has leveraged strategic moves to short the S&P 500 and invest in…

Kelp DAO Exploit Fallout Deepens as Attacker Routes $175M in ETH via Privacy Rails

Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…

Three major DeFi attacks in five days, with a total of 14 cryptocurrency hacking incidents in May

The Echo Protocol encountered a vulnerability attack on the Monad network, where the attacker minted 1,000 eBTC (worth approximately $76.64 million). According to PeckShield's tracking, the attacker deposited 45 eBTC (about $3.45 million) into Curvance, borrowed 11.29 WBTC, and then bridged it to Et...
...
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com