
THORChain has opened voting on ADR028, a comprehensive recovery plan following a $10.7 million exploit that occurred on May 15. According to reports from CoinDesk, the proposal sets the direction for network recovery while exact figures remain open to later changes through Mimir governance. The attacker was identified as a newly churned node operator who exploited a GG20 Threshold Signature Scheme vulnerability, with the other four vaults remaining unaffected. As reported by CoinDesk, the protocol's post-incident analysis confirmed that GG20 has been patched and upgraded, with the network now requiring a successful churn before normal activity returns.
Under ADR028, protocol-owned liquidity would absorb losses first, with any remaining shortfall shared across synth holders. As reported by CoinDesk, the proposal ensures no new RUNE will be minted, no RUNE will be sold, and holders will not be diluted. Protocol-owned liquidity would be reduced to zero, with part of future system income redirected to rebuild it over time. The network will also require a successful churn before normal activity returns. According to CoinDesk, the protocol stated that "the ADR proposes to redirect a portion of system income to replenish it over time" and that "nodes that are not linked to the attacker but affected by it due to being in the same vault would not be slashed."
The proposal includes full slashing for the attacker's node while protecting innocent nodes assigned to the same vault. According to CoinDesk, recovered RUNE would be paired with any assets recovered from the affected vault, with surplus RUNE burned. THORChain also offers the attacker a bounty to return the funds, with the recovery plan rolling back by the same share if funds are returned in part. The protocol will remain neutral and permissionless, meaning the attacker's swaps will not be censored once trading resumes. As reported by CoinDesk, the proposal also includes a 10% bounty offer to return the funds, with the attacker having been offered 10% of the bounty to return the funds. However, a commenter on GitLab raised concerns about the bounty section, suggesting it should be handled through forensics and law enforcement instead.
The attack was detected within minutes of occurrence, with chain-level trading halts triggered and node operators implementing manual pauses through governance systems. According to CoinDesk, this led to total lockdown of the network within roughly two hours of the alarm being raised. Security firm PeckShieldAlert estimated the haul at roughly $10 million, split between 36.75 BTC (around $3 million at the time) and approximately $7 million in assets across Ethereum, BNB Chain, and Base. THORChain's own post-incident analysis put the figure at $10.7 million. Blockchain analytics firm Chainalysis published on-chain evidence on May 16, tracing the attacker's movements through Monero, Hyperliquid, and THORChain itself. The firm identified that one wallet deposited XMR through a Hyperliquid-Monero privacy bridge in late April, swapped the resulting position for USDC, then withdrew to Arbitrum and bridged to Ethereum, with an intermediary forwarding 8 ETH into the attacker's receiving wallet just 43 minutes before stolen funds arrived.
RUNE, THORChain's native token, dropped more than 21% in the days following the breach and currently trades around $0.44 according to CoinMarketCap data. The incident follows a period of increased DeFi exploits, with crypto protocols losing more than $606 million in the first 18 days of April, led by the $292 million KelpDAO breach and $285 million Drift Protocol exploit. As reported by CoinDesk, TRM Labs reported that North Korea-linked actors drove about 76% of global crypto hack losses in the first four months of 2026, totaling approximately $577 million through April. The protocol had already identified a more modern signature scheme called DKLS as its long-term replacement for GG20 and had engaged Silence Labs in November 2025 to build a custom implementation, with delivery targeted for Q1 or Q2 2026. A commenter on GitLab also suggested implementing permanent allocation of system revenue toward external security audits, adversarial review of the TSS layer, and a funded bug bounty program to prevent future recurrences.