On September 27, THORChain, a decentralized cross-chain liquidity protocol, has faced multiple security incidents since 2021. In July 2021, two consecutive 'fake deposit' attacks resulted in a total loss of approximately $16 million. On May 15, 2026, a malicious node operator exploited a vulnerability in the GG20 threshold signature scheme to reconstruct the treasury's private key, withdrawing about $10.7 million in assets from a single Asgard treasury, involving multiple chains such as Bitcoin, Ethereum, BNB Chain, and Base. Including incidents like the theft of the founder's personal wallet, the total losses have approached $25 million. The protocol subsequently paused trading for 39 days for security upgrades before resuming operations. Notably, THORChain has become a significant channel for hackers to launder money due to its feature of allowing direct cross-chain exchanges without wrapping assets, particularly from ETH to BTC. After the theft of approximately $1.4 billion from Bybit in February 2025 (the largest crypto theft in history), the North Korean Lazarus group transferred about $1.2 billion (85% of the stolen funds) through THORChain, with node operators earning millions in fees from this. Additionally, in the KelpDAO hack in April 2026, around $1.75 million also flowed through THORChain. The protocol has appeared in cases involving the FTX hacker, WazirX, Atomic Wallet, and others. Analysis shows that between 2023 and 2026, at least seven confirmed money laundering incidents processed approximately $9.27 billion in illegal transactions through THORChain, with the protocol and liquidity providers earning about $12.47 million in fees. After Bitget's CEO formally requested THORChain to refuse service to the attackers' addresses, THORChain responded that its protocol is a decentralized, permissionless network, similar to Bitcoin, Ethereum, and BNB Chain. Previously, under pressure, the THORChain community voted on whether to block related addresses but ultimately decided against it, citing 'decentralization and non-censorship,' leading to the resignation of a lead developer. Supporters argue this is the essence of open infrastructure; critics point out that the protocol effectively provides a convenient channel for criminal funds, sparking intense debate over the neutrality and responsibility of DeFi. This series of events highlights the long-standing tension between convenience and security compliance in cross-chain protocols.
All Comments