THORChain: More than $10 million stolen from crypto platform THORChain

THORChain: More than $10 million stolen from crypto platform THORChain

THORChain Suffers $10.7 Million Crypto Heist in Vault Compromise

On Friday morning, decentralized cryptocurrency platform THORChain confirmed a security breach resulting in the theft of over $10 million in digital assets. The attack was first flagged by blockchain security firm PeckShield and investigator ZachXBT, who reported that 36 Bitcoin (worth ~$3 million) and $7 million in other coins were siphoned from the platform around 6 AM EST.

THORChain acknowledged the incident in a statement, revealing that one of its six vaults was compromised. The company emphasized that user funds remain secure, as only protocol-owned funds were affected. The network’s automated systems detected the abnormal activity, triggering a halt in signing operations to prevent further losses.

Founded in 2018 and based in Switzerland, THORChain is still investigating the breach but has implemented additional safeguards to mitigate further risks. This incident follows a 2025 attack in which one of its founders lost $1.2 million to an alleged North Korean hacker.

The theft adds to a surge in cryptocurrency platform breaches in 2026, with cumulative losses exceeding $200 million including recent high-profile heists of $26 million, $40 million, and $290 million. The U.S. Treasury Department has since expanded cyber threat intelligence sharing with the crypto industry after a $280 million theft from Drift last month. In 2025, over $2 billion was stolen from crypto platforms, underscoring persistent security vulnerabilities in the sector.

Source: https://therecord.media/more-than-10-million-stolen-crypto-platform-thorchain

THORChain TPRM report: https://www.rankiteo.com/company/thorchain

"id": "tho1778876645",
"linkid": "thorchain",
"type": "Breach",
"date": "5/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Protocol-owned funds only (user '
                                              'funds secure)',
                        'industry': 'Cryptocurrency/Blockchain',
                        'location': 'Switzerland',
                        'name': 'THORChain',
                        'type': 'Decentralized Cryptocurrency Platform'}],
 'attack_vector': 'Vault Compromise',
 'customer_advisories': 'User funds remain secure',
 'data_breach': {'data_exfiltration': 'Yes (siphoned funds)',
                 'sensitivity_of_data': 'High (cryptocurrency assets)',
                 'type_of_data_compromised': 'Digital assets (Bitcoin and '
                                             'other coins)'},
 'date_detected': '2026-0X-XXT06:00:00Z',
 'date_publicly_disclosed': '2026-0X-XX',
 'description': 'On Friday morning, decentralized cryptocurrency platform '
                'THORChain confirmed a security breach resulting in the theft '
                'of over $10 million in digital assets. The attack was first '
                'flagged by blockchain security firm PeckShield and '
                'investigator ZachXBT, who reported that 36 Bitcoin (worth ~$3 '
                'million) and $7 million in other coins were siphoned from the '
                'platform around 6 AM EST. THORChain acknowledged the incident '
                'in a statement, revealing that one of its six vaults was '
                'compromised. The company emphasized that user funds remain '
                'secure, as only protocol-owned funds were affected. The '
                'network’s automated systems detected the abnormal activity, '
                'triggering a halt in signing operations to prevent further '
                'losses.',
 'impact': {'financial_loss': '$10.7 million',
            'operational_impact': 'Halt in signing operations',
            'systems_affected': 'One of six vaults'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain',
 'references': [{'source': 'PeckShield'}, {'source': 'ZachXBT'}],
 'response': {'communication_strategy': 'Public statement acknowledging the '
                                        'incident',
              'containment_measures': 'Halt in signing operations',
              'incident_response_plan_activated': 'Yes (automated systems '
                                                  'detected abnormal activity)',
              'remediation_measures': 'Additional safeguards implemented',
              'third_party_assistance': 'PeckShield, ZachXBT'},
 'threat_actor': 'North Korean hacker (alleged in prior incident)',
 'title': 'THORChain Suffers $10.7 Million Crypto Heist in Vault Compromise',
 'type': 'Cryptocurrency Heist'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.