Decentralized Liquidity Network
THORChain is a decentralized cross-chain AMM trading protocol, created by a group of anonymous cryptocurrency developers at Binance's Hackathon in 2018. Its aim is to decentralize cryptocurrency liquidity via a network of public THORNodes and ecosystem products. Access to its native and cross-chain liquidity is open to any person, product, or institution.
Odaily News: According to monitoring by Galaxy's Head of Research, a victim's Coldcard wallet was compromised in a hacker attack involving nearly 30 BTC, of which 17 BTC were swapped for ETH via THORChain and subsequently deposited into Duel.comcasino. The victim and a researcher have sent emails to all known addresses associated with Duel.comcasino, requesting that the relevant funds be frozen, and provided all transaction and deposit information. The hacker deposited 229.72497255 ETH, valued at $445,000, into Duel.comcasino—funds originating from the Coldcard attack involving approximately 30 BTC. The victim stated that Duel.comcasino responded by saying that the police would need to contact their team. Duel.comcasino's anti-money laundering policy claims it enforces Know Your Customer (KYC) procedures and complies with all applicable laws. Duel.comcasino was notified within minutes of the deposit being completed. To date, Duel.comcasino has not frozen the relevant funds. Since most of the Western world had already passed midnight at the time of the incident, police reports cannot be filed until at least Monday. If Duel.comcasino fails to freeze the funds, the victim will pursue legal action against them. Duel.comcasino's X account has been suspended, and Galaxy's Head of Research has also flagged individuals on X suspected of being associated with the platform, including team members and dealers: @korraflow, @atrois7, @MiaMalkova.
Odaily, the decentralized cross-chain liquidity protocol THORChain has resumed trading after being down for over five weeks following a May attack. Signing, swapping, liquidity provider operations, and redemptions have all been restored.On May 15, blockchain investigator ZachXBT and security firm PeckShield identified that the protocol had likely been exploited, prompting THORChain to halt trading. The vulnerability resulted in a loss of approximately $10.7 million from one of its six Asgard vaults, while the other five vaults were unaffected.THORChain stated that each vault has now been verified, and every key share has been cross-checked. Native Monero swaps are currently undergoing end-to-end testing and will be launched subsequently. (The Block)
THORChain has released its fourth update regarding the Asgard vault intrusion incident, publishing the ADR028 proposal and opening voting for node operators. The proposal indicates that the protocol will first absorb losses through its Protocol-Owned Liquidity (POL), with the remaining portion to be borne by synthetic asset holders. The exact proportion is still under evaluation. The POL will be reduced to zero as a result, and the proposal suggests allocating a portion of system revenue over time to gradually replenish it. This plan does not involve minting new RUNE, selling RUNE, or diluting holder equity.On the technical side, the GG20 version will be temporarily retained with a patch upgrade. Trading will resume after the vulnerability is fixed and a successful node rotation is completed. A slower, more security-focused release cadence is planned for the future.Regarding the slashing mechanism, unrelated nodes sharing the same vault as the attacker will be protected, while the attacker's node will be fully slashed. The recovered RUNE will be paired with recoverable assets from the affected vault, and any excess RUNE will be burned.Additionally, THORChain has offered a white-hat bounty to the attacker to recover funds. If a portion of the funds is recovered, the recovery plan will be adjusted proportionally. THORChain emphasizes its commitment to remaining neutral and permissionless, stating it will not censor the attacker's swap transactions after trading resumes.Currently, node operators are voting on the overall direction and principles of the proposal. The specific figures in the ADR are indicative and will be adjusted later via the Mimir mechanism. The goal is to restart the network as soon as possible. A "yes" vote means developers can proceed further along this path.
Odaily News: THORChain officially stated that a large number of fake accounts and false information have been spotted on the market, involving activities such as "refunds," "airdrops," and "compensation." Preliminary investigations indicate that user funds were not compromised in the previous security incident. No refund, airdrop, or compensation plan has been initiated. Any accounts claiming otherwise are imposters or are disseminating false information. Further investigation progress and additional details will be announced subsequently.
Odaily Odaily, THORChain posted on platform X that its developers have released an incident update on Discord. Current evidence points to a node thor16uc...cn84q, which recently joined the network, as being associated with the attack. This node is operated by a single malicious actor. The primary hypothesis is that the attacker exploited a vulnerability in the GG20 TSS implementation, causing sensitive key material of vault participants to leak over time. This ultimately enabled the reconstruction of the vault's private key and the execution of unauthorized outgoing transactions.Regarding network status, the network has been paused after multiple node operators executed `make pause`. RUNE transfers and on-chain observation may resume within approximately 12 hours, but transactions, LP operations, signing, and other sensitive operations remain paused.Discussed recovery plans include slashing the affected node's bond, covering losses with protocol-owned liquidity (POL), or other community-driven solutions. THORSec and Outrider Analytics are continuing their investigation. The Treasury is gathering forensic data and coordinating with relevant law enforcement agencies. Full functional recovery is expected to take several days or longer.
According to Odaily, THORChain has issued an emergency announcement stating that after discovering a suspected breach of an Asgard vault, the network has suspended trading operations to respond to the security incident. Preliminary information indicates that user funds remain unaffected, with losses primarily concentrated on the protocol's own capital.The official statement noted that the system automatically detected anomalous behavior and halted signing operations, thereby alerting the community and preventing further asset outflow. The investigation is currently ongoing to determine the root cause of the vulnerability and the full scope of the impact.Known information indicates that this incident involves one of the six Asgard vaults, with estimated losses of approximately $10.7 million. Meanwhile, staked RUNE on the affected nodes has been slashed due to a penalty mechanism triggered by unauthorized outgoing transactions. The network has paused churn operations and delayed the launch of new chains and related features until system stability is restored.THORChain stated that no user cross-chain transactions have been affected so far and has requested node operators to thoroughly inspect their infrastructure, secure key management, and anomalous behavior, and to submit relevant logs to assist the investigation.
Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.
Odaily reports, according to on-chain analyst Yu Jin's monitoring, a whale completed a cross-chain BTC purchase 2 hours ago. Over the past 4 days, this whale spent a total of 85.42 million USDC to buy 1,075.6 BTC, with an average cost of $79,412, including approximately $170,000 in swap fees paid to THORChain.
According to on-chain analyst Yu Jin's monitoring, a whale continued to buy 544.5 BTC via cross-chain today, worth $42.43 million. Over the past two days, this whale has swapped 60.37 million USDC for 767.8 BTC through THORChain, at an average price of approximately $78,628.
Odaily News: According to on-chain analyst Yu Jin's monitoring, a whale that cleared 50,600 ETH at an average price of $2,921 late last year, netting a profit of $19.02 million, has resumed buying Bitcoin after an 8-month hiatus. Over the past day, the whale swapped 14.2 million USDC for 179.8 BTC via THORChain at a price of $78,955 per BTC, and is still continuing to buy, with $74.32 million USDC still in hand.
according to Bitcoin News monitoring, the Coldcard thief is prioritizing emptying the largest portion of the third wave of vaults. Galaxy Research stated that these wallets have transferred out 97.09 BTC, worth approximately $7.7 million, accounting for about 45% of the assets in this batch. The attacker created 293 2/2 vaults themselves and previously moved some tokens via THORChain on September 2, followed by multiple rounds of CoinJoin over the weekend. The vulnerability stems from a 2021 firmware flaw that reduced seed entropy to a minimum of 40 bits. Of the tokens stolen in this exploit, approximately 82% remain unmoved.
According to Galaxy Research, in the Coldcard wallet attack incident, the Wave 3 attacker has transferred approximately 45% of the stolen Bitcoin, with the related funds routed to Ethereum via THORChain or entering CoinJoin transactions to increase tracking difficulty. Galaxy stated that the attacker previously created 293 2-of-2 multisig vaults to hold victim funds, draining them from largest to smallest amount, and the funds in the 11 largest vaults have now been fully transferred out.
Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.
Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.
Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.
MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.
Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.
Odaily News: OKX Star posted on X in response to THORChain, stating that he does not believe THORChain's TSS + validator model represents true decentralization. THORChain's validators collectively control the underlying assets in the TSS vault, and funds can be moved once the signature threshold is reached. Therefore, from a custody perspective, it cannot be compared to the underlying consensus mechanisms of Bitcoin and Ethereum, but instead acts as an intermediary between users and native chains. "TSS distributes control among multiple participants, but decentralizing an intermediary does not eliminate the intermediary itself."Previously, discussions arose after some stolen Bitget funds were transferred through THORChain. THORChain responded that it is decentralized and permissionless, just like Bitcoin, Ethereum, and BNB Chain, and stated that if stolen funds were known to flow through Bitcoin, Ethereum, or BNB Chain, what responsibility should those networks bear?
THORChain has announced that the ZEC liquidity pool is now live. The network completed a node churn, and all nodes have begun monitoring the Zcash chain. THORChain stated that trading functionality will be the next step; current liquidity is relatively shallow, and early traders should be aware of risks such as slippage. Previously, THORChain added native Zcash support in a protocol upgrade, including UTXO handling, RPC logic, and a ZEC price oracle, and continues to advance mainnet integration.
Odaily News: THORChain announced the launch of version 3.20, adding native cross-chain swap support for Monero (XMR) and Zcash (ZEC). Users can directly swap XMR and ZEC for Bitcoin, ETH, and stablecoins without wrapping assets, registering on centralized exchange accounts, or relinquishing asset custody. This upgrade also introduces Protocol-Owned Liquidity (POL) and Stable Reserve, and restores support for Solana, Base, and BNB. Among these, Stable Reserve supports zero-liquidity-fee swaps between stablecoins.
Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.
decentralized privacy protocol hinkal has released an update on a security incident, confirming that an attacker extracted approximately 797,000 USDC from its Ethereum contract through a series of transactions and exchanged it for about 454 ETH. Of this, roughly 410 ETH was subsequently transferred to Tornado Cash, while the remaining approximately 44.67 ETH was bridged to the Bitcoin network via THORChain. hinkal is currently collaborating with an external security team to trace the flow of funds.hinkal stated that the impact of this security incident is limited to the relevant fund pools on the Ethereum chain, and contracts on other chains remain unaffected. However, all contracts have been temporarily suspended for fixes and security verification. All affected users will be fully compensated at a 1:1 ratio, with specific compensation procedures and timelines to be announced in a subsequent update.
Odaily, the decentralized cross-chain liquidity protocol THORChain has resumed trading after being down for over five weeks following a May attack. Signing, swapping, liquidity provider operations, and redemptions have all been restored.On May 15, blockchain investigator ZachXBT and security firm PeckShield identified that the protocol had likely been exploited, prompting THORChain to halt trading. The vulnerability resulted in a loss of approximately $10.7 million from one of its six Asgard vaults, while the other five vaults were unaffected.THORChain stated that each vault has now been verified, and every key share has been cross-checked. Native Monero swaps are currently undergoing end-to-end testing and will be launched subsequently. (The Block)
According to the THORChain blog, ZEC is in the queue for launch on THORChain. However, due to a recent vulnerability disclosed in Zcash—whose existing patch impacts integrators’ normal operations—THORChain must first complete a minor code modification to its Bifrost module before proceeding. The development team stated that the change is minimal but must be completed prior to ZEC’s launch. Monero (XMR) is currently expected to launch by the end of this month, with ZEC scheduled to follow.
THORChain has announced that the ZEC liquidity pool is now live. The network completed a node churn, and all nodes have begun monitoring the Zcash chain. THORChain stated that trading functionality will be the next step; current liquidity is relatively shallow, and early traders should be aware of risks such as slippage. Previously, THORChain added native Zcash support in a protocol upgrade, including UTXO handling, RPC logic, and a ZEC price oracle, and continues to advance mainnet integration.
Odaily reports, according to Lookonchain monitoring, the Bitget hacker (0xf7bC...96C3) swapped ETH for BTC via THORChain, having stolen $351.6 million.
According to Odaily, THORChain generated approximately $381,700 in revenue on September 25, marking a new high since April 25. Its swap volume reached $211 million, the second-highest level since April 23, surpassed only by the approximately $280 million in swap volume recorded on September 10.
Odaily News: According to on-chain analyst Yu Jin, over 90% of the funds swapped cross-chain through THORChain are illicit or grey-market funds. Yu Jin stated that most of the funds stolen from Bybit last year were transferred through THORChain, which collected nearly $10 million in fees within 10 days. Recently, some of the funds stolen from Bitget have also been transferred through THORChain, generating $1 million in fee revenue.
Slow Mist's Cosine posted on X platform, stating that the Bitget hack incident has spread widely, involves a huge amount of funds, and the related funds were quickly linked to North Korean hackers. Institutions such as Circle and Tether promptly assisted in freezing the related funds, with Circle freezing the USDC held by the hackers.Regarding THORChain, Cosine pointed out that when THORChain itself previously suffered a hack, it also quickly intervened in its so-called "decentralized" platform; but this time, when facing a major industry security incident, it responded on the grounds of being "decentralized and having no right to interfere," likened itself to Bitcoin and Ethereum, and continued to earn fees from the hackers' large cross-chain transactions.He stated that decentralization should not just be a slogan. After major security incidents occur, the key is to distinguish which issues need to be solved jointly by the industry. He also believes that platforms such as THORChain should not be easily mentioned in the same breath as Bitcoin and Ethereum, as there are clear differences in the degree of decentralization and mechanisms among different systems.
MistTrack (@MistTrack_io) disclosed that, following the transfer of nearly $1.2 billion in stolen funds from last year's $1.46 billion Bybit hack via THORChain, Bitget has recently suffered another major security breach, with stolen funds suspected of again flowing through THORChain. In response, the official THORChain team stated that its protocol is a decentralized, permissionless network, just like Bitcoin, Ethereum, and BNB Chain.