Cross-chain router exploit; specific vector undisclosed pending post-mortem.
Cross-chain router exploit hit THORChain across four networks — Bitcoin, Ethereum, BNB Smart Chain, and Base. On-chain investigator ZachXBT flagged suspicious router activity early on 2026-05-15; security firm PeckShield estimated ~36.75 BTC (~$3M) plus ~$7M in Ethereum, BSC, and Base assets drained, for a combined loss of approximately $10.7M. Affected tokens included USDT, USDC, WBTC, DAI, THOR, LUSD, XRUNE, GUSD, AAVE, LINK, and FOX. Protocol response: Mimir governance flipped trading-halt and signing-halt parameters to active, imposing a node pause of ~12 hours 42 minutes from block 26190429. RUNE dropped ~12% on the news. Specific attack vector remains undisclosed pending post-mortem. Historical context: THORChain has been exploited multiple times via router-layer issues (notably twice in mid-2021).
- chain
- multichain
- protocol
- THORChain
- bug_class
- bridge
- date_occurred
- 2026-05-15
- loss_usd
- $10,700,000
- classification
- Protocol Logic — Cross-Chain Router
- technique
- Cross-chain router infrastructure exploit
- target_type
- DeFi Protocol
- language
- Go / Solidity (router contracts)
- bridge_hack
- YES
- source_id
- cb:thorchain-router-2026-05-15