
THORChain has paused trading following the identification of a suspected exploit spanning multiple blockchain networks. According to onchain investigator ZachXBT, the cross-chain liquidity protocol appears to have been compromised in a coordinated exploit spanning at least four major networks. The exploit has already resulted in estimated losses exceeding $7.4 million, with ZachXBT reporting the findings in an alert posted on Telegram on Friday. The protocol paused operations Friday morning while investigators examine on-chain activity, with the $7.4 million figure representing the estimated stolen amount though it remains unclear whether this is the final tally of losses. Following the announcement, THORChain's native token RUNE crashed approximately 11% in just a few hours to near $0.52, with the token falling about 10% to near $0.52 on the day of the announcement. The token's daily trading volume has skyrocketed to $24.49 million, reflecting panic selling by investors holding RUNE tokens, with trading volume increasing by almost 140% over the last 24 hours as investors book profits amid the price decline.
ZachXBT identified two alleged theft addresses on the Bitcoin network and EVM-compatible chains, as reported by The Block. The researcher's analysis suggests the exploit may have been executed across Bitcoin, Ethereum, BNB Chain, and Base networks, though the findings remain preliminary and require further confirmation. Security firm PeckShield has provided detailed analysis of the stolen assets, confirming that approximately $7.4 million worth of crypto was stolen, including 36.75 BTC ($3 million) and $7 million worth of assets from Ethereum, BNB Chain, and Base networks. The stolen funds have been tracked on-chain, with Bitcoin transferred to wallet bc1q14u94klk265lnfur2ujk9p6uh52f2a8jhf6f37 and Ethereum deposited at 0xd477b69551f49C0519F9B18c55030676138890Bd. The $7.4 million figure represents the estimated stolen amount, though it remains unclear whether this is the final tally of losses. Investigators say attackers appeared to use the protocol's cross-chain routing to move funds tied to the KelpDAO breach between Ethereum and Bitcoin, then consolidate assets through the two identified addresses. The exploit involved large unauthorized outflows from THORChain's router contracts across the affected chains.
The stolen crypto has been distributed across multiple wallets with precise tracking through blockchain explorers. According to PeckShield, the attack targeted Bitcoin, Ethereum, BNB Chain, and Base blockchains, enabling unauthorized token withdrawals. ETH inflows and transactions were detected as late as 9:06 UTC on May 15, 2026, indicating the exploit occurred over a 13-14 hour period when THORChain was processing roughly $394 million in daily volume. For Bitcoin, approximately 36.85 BTC ($2.97 million) has been transferred to the wallet bc1q14u94klk265lnfur2ujk9p6uh52f2a8jhf6f37, while Ethereum and derivatives worth more than 3,156 ETH ($7.11 million) have been received by address 0xd477b69551f49C0519F9B18c55030676138890Bd. Security researchers and analytics platforms such as PeckShieldAlert revealed the attacker's wallets, which hold 36.85 BTC, 3,443 ETH, and 96.6 BNB, along with other tokens like USDT, USDC, and WBTC according to Arkham data. The stolen crypto coins have performed relatively well despite the market turbulence, with Bitcoin increasing 2.61% to $81,667.13 and Ethereum rising 0.12% to $2,252.88 over the past 24 hours.
THORChain's current suspension adds to a pattern of previous security and operational disruptions for the cross-chain liquidity protocol. According to The Block, the protocol previously suspended its ThorFi lending operations in January 2025 amid insolvency allegations and implemented a 90-day restructuring through validators to address about $200 million in defaulted obligations. The protocol subsequently resolved a $200 million debt crisis by converting defaulted obligations into a new equity-style token. The latest incident follows other significant security breaches affecting THORChain, including a $1.2 million exploit of THORChain founder John-Paul Thorbjornsen's personal wallet in September 2025, which ZachXBT linked to North Korean hackers. The 2021 Poly Network hack drained over $600 million in what was, at the time, one of the largest DeFi exploits ever recorded, demonstrating that cross-chain bridges and swap protocols have been recurring targets for attackers. This represents the second notable security event for THORChain this year, amplifying concerns about DeFi interoperability risks.
The THORChain exploit represents part of a concerning trend in DeFi security, with approximately $25 million lost to hacks in the crypto space since the start of May 2026. Recent attacks have affected other protocols, including Huma Finance which suffered an exploit of its V1 smart contracts on Polygon, resulting in $101,400 worth of USDC and USDC.e tokens stolen on May 11. Ink Finance also became a victim of theft totaling $140,000 from its Workspace Treasury Proxy contract on Polygon. Security firm CertiK reports North Korean-linked hackers accounted for about $2.1 billion in cryptocurrency thefts during 2025, roughly 60% of losses the firm tracked. The total value locked across DeFi ecosystems tends to wobble after high-profile exploits, with confidence remaining fragile in this space. The broader DeFi market feels the impact, with users watching suspected exploits unfold in real time wanting to see platforms hit the brakes rather than keep operating while money potentially bleeds out. Protocols have talked about collaborative security for years, but actual partnerships with real implementation timelines would represent meaningful progress in addressing these recurring vulnerabilities.