⚡️ Half of all THORChain node operators have already upgraded to v3.19.1.
The network is moving steadily toward restart, with security fixes deployed, vault protections strengthened, and the community focused on getting it right rather than rushing it.
After weeks of testing, patching, audits, and stress-testing, we’re getting closer to the moment every THORChad has been waiting for.
The rejuvenation of @THORChain is no longer a question of if — only when. 🛡️⚒️
Stronger security. Stronger infrastructure. Stronger community.
The Dex of DEXes is preparing for its next chapter. 🚀
#THORChain #RUNE #DeFi #THORChads 🫡🔥
Altcoin Memecoin #ALTSEASON 2026 💸 is loading
███████▒▒▒ 80%
BULL RUN START SOON!!! 🔥
🔔 LIKE ~ FOLLOW 😎 ARE WE READY?
Shill me your 100x gems! 👀💎
------------------------------------------
👇
And it's coming to @THORChain ⚡️
@Zcash, @monero and @Dashpay incoming
Permissionless access. No CEX to delist it. No gatekeeper to ask
The future of privacy is here
The latest TC release 3.18 was done as a private binary (something we had done before when patching crits). There was a long-standing practice that if a node requested, by signing a message with their validator key, devs would send them the validator-key encrypted diff of the security patch. That’s exactly what the malicious node did in this case. It’s possible even that the private release spooked them into speeding up their timeline for the attack. I find this class of attack very interesting. Networks need to be designed maximally defensive, even against their own validators. In this case, a malicious validator can still get the source code for patches and exploit them before the code goes out. I wonder if this puts an end to that practice. It all exists on a spectrum of decentralization. I actually don’t disagree with @jpthor that closed source TSS might be the move from here. Anyone who is saying that’s “the end of the experiment” is either a crypto-anarchistic maxi that lost the plot or an NK hacker astro-turfing protocols into not making sound trade-offs between security and decentralization.
The new https://t.co/ShpC1XJKin📷 is finally live. 🔥
And to make it absolutely clear:
⚠️ There is NO other official THORChain website besides https://t.co/ShpC1XJKin📷
Be careful with fake domains, impersonators and scam links especially during turbulent times.
The new site is a massive improvement compared to the previous version:
→ cleaner branding
→ easier navigation
→ better ecosystem explanation
→ more professional first impression
→ much stronger foundation for future growth
People underestimate how important this is.
For years, one of @THORChain’s weakest points was never the tech itself.
It was the presentation layer for new users.
Now the protocol finally has a website that better reflects the scale of what has been built. ⚔️
There are still some SEO and optimization improvements that can be made over time, but the direction is absolutely right. 📈
And honestly, this is where the community shines.
Builders, marketers, designers, node operators, analysts, devs, content creators… everyone can help push the ecosystem forward.
I’m here to help however I can. 🛡️
Hack or no @THORChain hack, price action for $RUNE is simple.
Above $0.47 looking up
Beneath $0.47 looking down
One reason price might go down a bit further is because the network is currently halted. Once people can transfer their $RUNE from web3 wallets we might see some new sell pressure.
Atm not interesting in buying more Rune.
If lows are $0.35 are taken out I do am a buyer.
It might take a couple of weeks before @THORChain is fully operational again.
$XMR integration will hopefully come in Q4, I don't expect it sooner. No info, just a feeling.
@THORChain will survive this of course.
Holders just have to be patient, again
The haters celebrated a $10.7M exploit like THORChain was finished. 🤡
Meanwhile the protocol has already processed tens of billions in native cross-chain volume and survived every major crypto extinction event thrown at it. ⚔️
2021 exploits.
Luna collapse.
FTX contagion.
ThorFi crisis.
Regulatory attacks.
Now GG20.
Yes, losing 1 of 5 Asgard vaults was an expensive lesson.
But this network was built for pressure, not comfort. 🛡️
And while CT farms “THORChain is dead” engagement, builders are already testing the next chapter:
⚡ 7-node chainnet running
⚡ 2-3x faster performance observed
⚡ Keygen working
⚡ Keysign working
⚡ Scaling tests toward 30+ nodes underway
The funniest part?
Most people discovering GG20 problems today are 2 years late. 😂
The industry already started moving away after Alpha-Rays and TSSHOCK exposed weaknesses in 2023.
THORChain just accelerated the transition publicly.
$10.7M stolen.
Tens of billions already processed.
Project still alive.
Builders still shipping.
That’s the difference between hype chains and antifragile infrastructure.
GG20 was the past.
DKLS is the future. 🔥
$RUN
My thesis is that the exploiter is going to wait until @Thorchain fixes everything. Then they will wait some more until Thorchain gets $XMR swaps going strong, and then test TC's character to see if it allows swaps through TC to $XMR.
Please keep the hate coming for @THORChain. It only fuels the team, the community, and the machine. It shows who really cares about real DeFi and who gives lip service and virtue signaling.
Thorchain didn't lose $10.7M to a smart contract bug or a stolen key. The bug was in the cryptography itself - and Thorchain probably isn't the only chain running on it.
A single attacker bonded RUNE and joined the validator set days before the incident, looking like any legitimate operator. From inside, they exploited what investigators currently believe was a flaw in GG20, the threshold signature library Thorchain uses to co-sign transactions. Each signing session leaked a fragment of private key material to the attacker's node. After enough sessions, they had collected enough leaked data to mathematically reconstruct the vault's full private key.
Then they signed unauthorized outbound transactions as the vault. The smart contracts behaved correctly. No validator infrastructure was breached. Funds left through normal channels because the signatures were mathematically valid - just produced by an attacker who had silently rebuilt the key.
Here's why this matters beyond Thorchain.
GG20 was published in 2020 (Gennaro-Goldfeder). The Alpha-Rays attack (Verichains, 2023) and TSSHOCK at BlackHat 2023 documented practical weaknesses in tss-lib and related implementations. Some teams patched. Many didn't bother.
Based on shared library lineage, protocols that should audit their TSS right now include Mayachain (direct THORChain fork), Sygma cross-chain bridge, Keep Network's tBTC v1, and any service still running on bnb-chain/tss-lib or ZenGo-X/multi-party-ecdsa.
Major custody and MPC services that already migrated to newer threshold schemes (CGGMP21, DKLs): Fireblocks, Coinbase Custody, Taurus, Silence Laboratories. The industry has been quietly moving away from GG20 for two years.
Thorchain just gave everyone still on it a reason to move faster.
.@THORChain is a massive project with an incredible team. I genuinely hope they emerge from this crisis even stronger. In the age of artificial intelligence, staying online is the new challenge.
bRUNE just received a MASSIVE upgrade 🚀
→ RUNE allocated only to bondable nodes
→ Cap raised to 5M bRUNE
→ Standby nodes now eligible when preflight-ready
50 node operators gave feedback
@RujiraNetwork responded
Go take a look for yourself 👉 https://t.co/ytBUsumMaX
I hate to be the bearer of bad news, it seems one of the @THORChain TSS vaults has been drained, so far looks like $7m in damage
The network has halted churning and signing and the discord is on lockdown mode (discord is safe)
Maya has also halted, will update 🧵in comments
Important Announcement
Trading on THORChain is currently halted after a vault was compromised. Initial indications are user funds are safe and only protocol owned funds are affected.
The network automatically detected abnormal behavior and halted signing activity, which alerted the broader community and prevented further outbound transactions.
The investigation is still ongoing to determine the root cause. Contributors are actively working on the issue and we will report updates as we progress toward a solution.
What we currently know:
* One of the six Asgard vaults appears to have been compromised.
* Current estimates place the loss at approximately $10.7m USD
* The network automatically detected the abnormal behavior and halted signing activity, preventing further outbound activity.
* Nodes securing the vault were subject to their bonded RUNE being slashed as a result of the unauthorized outbound transactions.
* Churn activity has been paused while the investigation and remediation efforts are ongoing.
* Onboarding additional chains and operations requiring churns will be delayed until the network is stabilized.
* Initial indications show no individual user swaps were affected.
We are asking all node operators to immediately review their infrastructure, hosts, key management systems, and operational security for any signs of compromise or abnormal behavior, and to report anything suspicious in Discord.
Node operators participating in the affected vault are requested to securely provide Bifrost logs to the dev team for analysis using 'make relay' .
.@jpthor of @THORChain just live-demoed a Rune to Monero swap! It’s not live on Mainnet yet, but it appears to be functioning with real Monero! 🤯
None of this would have been possible without the contributions @kayabaNerve has made. The Monero fam is patiently waiting for the launch of @SeraiDEX, but it’s hard not to also be excited about Monero going live on THORChain very soon!! 🔥
Once live, proceed with caution. To be honest, THOR has to really prove itself here, but I, for one, am thrilled to see this integration finally happen. Thank you to JP, @CBarraford, @BooneW, and everyone who made this happen!! 💪💪🙏
When you swap in @TrustWallet, that's @THORChain
When you swap in @Ledger from a hardware wallet, also @THORChain
OKX Web3. Bitget Wallet. BitPay. Same infrastructure underneath
$14 billion in cumulative volume
One protocol behind it all ⚡️
People assume $XMR integration on @THORChain will have a positive price impact on $RUNE
But what if the biggest price impact will actually be on $XMR?
This will be the first time people can really swap $XMR <> any asset permissionless and anonymous ( buy XMR on CEX is doxxing )
Therefore interest to buy and hold Monero may get a huge impuls of interested and buyers. All speculation of course.
Also $XMR swaps on Thorchain will make $BTC swaps private too. Interesting side effect that might lead to a lot of BTC > XMR > BTC swaps on Thorchain.