Awaiting deeper $ZEC liquidity on @THORChain!
Excited to activate another decentralized cross-chain route to native @Zcash ⚡️
The future is onchain, private and permissionless 🫡
As mentioned at launch, ZEC is currently in a soft-launch phase.
Liquidity in the pool is still shallow, so larger trades will naturally face higher slippage for now.
As liquidity scales over time, so will the size of trades the pool can efficiently support.
https://t.co/6BUduIF9R5
THORSwap is attending @token2049 Singapore!
Meet our CEO @paperX_Art from October 5 to 9.
We'd love to explore collaborations across all things Bitcoin, Crosschain, RWAs, Privacy and Financial Sovereignty 🤝
Travelling to @Token2049 this weekend 🛫
I'll be representing @THORSwap@MetroXchange. Love to connect with builders, protocols, educators & anyone serious about Bitcoin, DeFi, crosschain, privacy and consumer apps.
Let's chat onchain and self-custody. Here with an open mind 🤝
Travelling to @Token2049 this weekend 🛫
I'll be representing @THORSwap@MetroXchange. Love to connect with builders, protocols, educators & anyone serious about Bitcoin, DeFi, crosschain, privacy and consumer apps.
Let's chat onchain and self-custody. Here with an open mind 🤝
@MetroXchange THIS IS THE LAST MESSAGE IN THIS THREAD.
If you were an affected user, please contact our team ONLY through the official support-desk channel on https://t.co/b3b4ofDf1A. Ignore all other DMs or comments offering support.
🚨 Mava Security Incident Update — Action Required for Some Users
On 28 September 2026, Mava, a third-party customer support platform used by @THORSwap and @MetroXchange, had its domain hijacked at the registrar level. For a limited period, malicious code was served through its support desk widget.
✅ Metro (.) exchange, thorswap (.) finance and v2.thorswap (.) finance are now safe to use. Our own servers and application code were NOT compromised.
However, if you used any of our dapps between 17:50 and 19:40 UTC on 28 September, please review the following carefully:
Who May Be Affected
The malicious widget was capable of:
- presenting a malicious WalletConnect prompt.
- capturing seed phrases or keystore information entered on-site.
- replacing copied or scanned deposit addresses of Direct Swaps.
Approximately $58,000 was stolen, including ~$54,200 from compromised wallets and $3,500 through a manipulated Direct Swap.
The user affected by the Direct Swap has already been reimbursed in full.
⚠️ We have identified potentially affected wallets here:
https://t.co/1DPZllqnhQ
If you may be affected, please ACT NOW.
If your wallet is listed above, or if during the affected window you:
- imported a seed phrase or keystore file;
- copied or scanned a Direct Swap deposit address; or
- connected through the malicious WalletConnect prompt,
Move any remaining funds to a completely new wallet with a new seed phrase immediately.
🚨 Migrate assets across every chain derived from the same seed phrase, not only the listed address or network, and revoke existing token approvals.
If you copied a Direct Swap deposit address during the incident window, verify the destination directly in your wallet before sending funds, or retry the swap completely.
Our Response and Next Steps
The malicious behaviour was detected by our automated tests and monitoring at 18:37 UTC. Fix to remove Mava widget was prepared (18:45 UTC), fix was deployed across THORSwap V2 (19:13 UTC), Metro and THORSwap (19:23 UTC), and all affected sites were verified clean by approximately 19:40 UTC.
The Mava support widget has since been disabled entirely from our dapp frontends. Our Discord support desk was not affected.
We are working with Mava and blockchain-analytics providers to trace the stolen funds and support affected users.
If your wallet is listed, please contact us through the official Support-desk channel on Discord (link in bio) or email [email protected]. Do NOT respond to any other forms of contact or offers of support across any other channel.
⚠️ We will never ask for your seed phrase, private key, keystore file or password. ⚠️
@mava_app@MetroXchange THIS IS THE LAST MESSAGE IN THIS THREAD.
If you interacted with the affected widget or approved a prompted walletconnect request, please contact our team ONLY through the official support-desk channel on https://t.co/b3b4ofDf1A. Ignore all other DMs or comments offering support.
⚠️ Security Notice: THORSwap & Metro Support Widget
THORSwap & Metro were temporarily disabled after we identified malicious activity from in-app Mava support desk widget.
👉 The @mava_app widget has been disabled, both THORSwap and @MetroXchange are back online & safe to use.
Our current findings indicate that a malicious fake "walletconnect/reown" widget was served to visitors without a cached copy from a previous visit. Previous THORSwap/Metro users who already had the original Mava support widget cached from an earlier visit were not affected.
For your safety:
• Do not revisit links or approve any wallet connection requests originating from the affected Mava support widget.
• If you interacted with the affected widget or approved a wallet request it prompted, please contact our team ONLY through our official 💻・support-desk channel (link in bio).
• Never share your seed phrase or private keys, and be cautious of unsolicited DMs claiming to offer support.
We will share any further verified updates through our official channels. Thank you for your patience while we address this issue.
When the markets move, we're here to serve 🫡
Yesterday was a busy on @THORSwap & @MetroXchange with $11.29M+ traded across chains.
As usual, $BTC led the way 🔥
Followed by $ETH $NEAR $SOL $BNB $DOGE $XRP $UNI $MON & zcash:native
Also: big swaps to $DAI, beating out $USDT & $USDC!
DeFi can be confusing, we know.
It's even more dangerous when bad actors are constantly out there trying to scam and exploit.
For any issues, please directly contact @THORSwap official discord's support desk (link in bio). Or simply via the support button in app. Stay safe! 🫡