THORChain: RUNE transfers are expected to resume in 12 hours, the attack may be due to the GG20 TSS vulnerability

By: www.chaincatcher.com|2026/05/18 23:57:25

THORChain released an update on the hacking incident on platform X. Preliminary evidence suggests that a node that recently joined the network may have been controlled by a malicious operator, who exploited the GG20 TSS vulnerability to obtain key information from vault participants, ultimately reconstructing the vault private key and executing unauthorized withdrawal transactions. Currently, multiple THORChain nodes have been shut down, resulting in the network being in a paused state. RUNE transfers are expected to resume in about 12 hours, but the specific situation will depend on node decisions. Functions such as trading, liquidity provider operations, and signing are still unavailable, and a full restoration of network functionality is expected to take several days. Recovery plans are under discussion and may include reducing the staking of affected nodes, as well as other remedial measures proposed by the community.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

THORChain Soft Launch Integrates Monero, ADR31 and ADR27 Proposals Passed, v3.20 Enters Testing

DeFi has reached its most dangerous moment: the real vulnerabilities are not in the code

April 2026 is not just a security crisis; it is the moment when the industry's mental model completely collapses, and it is also the moment when the protocols that can survive are distinguished from those that cannot.

THORChain has released a recovery plan for the attack incident, and voting for node operators has begun

THORChain has released its fourth update regarding the attack incident on May 15, and the proposal ADR028 has been announced, with voting for node operators now open.According to the recovery plan, the protocol will first absorb losses through its own liquidity, with the remaining portion to be shar...

Cryptocurrency Market Update: Major Developments and Insights

Key Takeaways Sky co-founder Rune Christensen has leveraged strategic moves to short the S&P 500 and invest in…

Kelp DAO Exploit Fallout Deepens as Attacker Routes $175M in ETH via Privacy Rails

Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…

Three major DeFi attacks in five days, with a total of 14 cryptocurrency hacking incidents in May

The Echo Protocol encountered a vulnerability attack on the Monad network, where the attacker minted 1,000 eBTC (worth approximately $76.64 million). According to PeckShield's tracking, the attacker deposited 45 eBTC (about $3.45 million) into Curvance, borrowed 11.29 WBTC, and then bridged it to Et...
...
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com