THORChain Restarts Trading After $10.7M GG20 Exploit
THORChain resumed trading, swaps and liquidity after more than a month of security verifications following a $10.7 million exploit; most vaults passed KeyVerify and the GG20 flaw was patched.
THORChain resumed trading, swaps and liquidity operations after more than a month of security verifications and upgrades following a $10.7 million exploit that halted trading on May 15. The network posted the restoration update on X.
Most vaults were verified through the protocol’s KeyVerify process and remaining legacy vaults were retired as part of a migration to a new set of vaults. The project called the upgrade the “most significant milestone” in its recovery and completed verification of every node’s keyshare on Friday.
Investigators traced the breach to a vulnerability in THORChain’s GG20 threshold signature scheme, which spreads control of private keys across multiple node operators. The protocol reported the flaw allowed a malicious node operator to reconstruct a full private key through what it described as “progressive key material leakage,” enabling the theft of $10.7 million.
An emergency patch was applied on May 20 to protect remaining vaults. A software upgrade released on June 9 included a fix for the exploited vulnerability, and a June 11 release added stability improvements and fixes to the KeyVerify protocol. Retiring legacy vaults and migrating funds into newly verified vaults were central elements of the restoration work.
Core functions restored by the update include trading, signing, swaps and liquidity provider actions. The team also outlined near-term network additions: native swaps and vaults for Zcash (ZEC) are expected in about two weeks, followed by Monero (XMR) support, and Bittensor (TAO) token support roughly six weeks after the restart.
THORChain operates as a cross-chain swapping protocol that enables token swaps between networks such as Bitcoin and Ethereum. The protocol has been used previously to move stolen funds across blockchains, an activity that has drawn attention from blockchain investigators.
Trading was paused on May 15 after the exploit was detected. Following code fixes, vault migration and full keyshare verification, the network restored core services and reopened trading.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








