Incident case

THORChain 2026 GG20 TSS vault exploit

In May 2026, a newly churned node operator exploited a vulnerability in THORChain's GG20 threshold-signature implementation, reconstructed a vault private key, and drained approximately $10.7 million from one Asgard vault across multiple chains.

reviewedcurrent

Incident facts

Incident title
THORChain 2026 GG20 TSS vault exploit
Bridge
THORChain
Incident date
2026-05-15
Incident type
Exploit
Major incident
Yes
Affected chains
THORChain, Bitcoin, Ethereum, BNB Chain, Avalanche, Unknown
Affected assets
BTC, ETH, USDC, USDT, WBTC, DAI, Unknown
Attack category
Validator Key Compromise
Reported loss
$10.7 million official estimate; more than $11 million later analytics estimate
Amount confidence
High
Loss amount basis
Official Exploit Report Prioritized, With Later Blockchain Analytics Scope Retained
Recovery
Unknown
Reimbursement
Unknown
Restart
Paused
Current outcome
Paused Long Term
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-06-15
Last verified
2026-06-15

Amount and valuation

THORChain's initial exploit report reported approximately $10.7 million drained from one vault; TRM Labs later described losses exceeding $11 million across at least nine chains.

The $10.7 million figure is the official initial assessment. The more-than-$11-million figure reflects later cross-chain analytics and may include a broader confirmed scope.

Why this remains unresolved

Timeline events

  • GG20 TSS vault exploit disclosed2026-05-15

    A May 2026 threshold-signature incident drained one Asgard vault before automatic solvency controls halted the network.

    Exploit DisclosedHigh

    Later analytics described a broader total exceeding $11 million across at least nine chains.

  • TSS patch released and recovery options moved to governance2026-05-20

    THORChain reported a patched release and governance review of recovery options while final loss allocation remained pending.

    Patch And Recovery ReviewHigh

    The official site continued to describe trading as temporarily paused during review.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Conflicting claims

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.