THORChain fully resumes after more than a month offline

THORChain fully resumes after more than a month offline

Trading, swaps and other core functions restarted after a May exploit drained about $10.7 million, with a 39-day security overhaul completed and governance plans in place to absorb the loss.

XMR
RUNE
ZEC

Fact Check
The official THORChain X post directly confirms trading resumed after a month-long outage with all functions operational and vaults/keyshares verified. Cointelegraph and The Block independently corroborate the ~$10.7M exploit on May 15 from one Asgard vault, a halt of more than a month/five weeks, and the security-first verification of vaults and keyshares before resumption. All elements of the claim are supported.
    Reference123
Summary

THORChain said it has fully resumed trading and other core operations after 39 days offline following a May exploit that drained about $10.7 million from the protocol. Swaps, liquidity provider actions and cross-chain signing infrastructure have reopened after an 11-stage security overhaul that included new multi-party computation protections and a KeyVerify process to check node keyshares before vault churning proceeds. The shutdown began on May 15 after an attacker allegedly posed as a node operator and exploited a flaw in THORChain’s GG20 threshold signature scheme. During the downtime, total value locked fell to about $53 million from more than $80 million on May 15 and from above $500 million at its March 2024 peak. RUNE was trading near $0.42 with a market capitalization just above $141 million, showing little immediate reaction to the restart. THORChain has said protocol liquidity would absorb losses first under the ADR-028 governance plan, with synthetic asset holders covering any remaining shortfall. The team is now returning to its privacy roadmap, with native Monero swaps fully functional in testing and Zcash support dependent on confidence in Zcash’s recovery from a late-May Orchard shielded pool vulnerability.

Terms & Concepts
  • threshold signature scheme: A cryptographic setup that splits signing authority across multiple participants so no single party controls the full key.
  • multi-party computation: A security method that lets multiple parties jointly perform sensitive cryptographic operations without revealing their private data to one another.
  • keyshares: Fragments of a cryptographic key held by different nodes and used together to authorize transactions securely.