Incident case

THORChain 2021 ETH Router exploit 2

A second July 2021 attack used a fake router and malicious refund memo to make Bifrost accept a fabricated deposit event, draining economically significant ERC-20 assets from THORChain's Ethereum-side liquidity.

reviewedcurrent

Incident facts

Incident title
THORChain 2021 ETH Router exploit 2
Bridge
THORChain
Incident date
2021-07-22
Incident type
Exploit
Major incident
Yes
Affected chains
THORChain, Ethereum
Affected assets
USDC, USDT, Unknown
Attack category
Message Verification Failure
Reported loss
Approximately $8 million
Amount confidence
High
Loss amount basis
Official Postmortem And Independent Technical Analysis
Recovery
Unknown
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Full
Resolution
Final outcome known
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

The official postmortem and contemporary technical reporting described an impact of approximately $8 million in ERC-20 assets.

The affected assets included USDC, USDT, XRUNE, ALCX, SUSHI, YFI, and other ERC-20s; the seed uses existing asset references plus unknown for the broader basket.

Timeline events

  • Second THORChain ETH Router exploit disclosed2021-07-22

    A second July 2021 ETH Router incident removed an ERC-20 asset basket from protocol liquidity.

    Exploit DisclosedHigh

    Kept separate from the first July incident because the mechanism and asset basket differed.

  • THORChain returned to staged trading after remediation2021-10

    After audits, router changes, node upgrades, and treasury-led loss coverage, THORChain resumed functions and trading in stages.

    Bridge ReopenedMedium

    A later expansion should pin the final staged-reopening date with a dedicated official source. Event type normalized from legacy descriptive value network_reopened.

  • THORChain reported 2021 exploit users fully reimbursed2022-05-11

    THORChain stated that after the chain restarted, liquidity providers and node operators affected by the 2021 exploits were fully reimbursed approximately 16 million dollars in aggregate.

    Reimbursement CompletedHigh

    The official aggregate amount is not split between the two July incidents.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.