PANews reported on May 16 that THORChain released an update on the hacking incident on its X platform. Preliminary evidence suggests that a node that recently joined the network was likely taken over by a malicious operator. The operator exploited the GG20 TSS vulnerability to obtain the vault participants' key information, ultimately reconstructing the vault's private key and executing unauthorized withdrawal transactions.
Currently, multiple THORChain nodes are offline, causing the network to be suspended. RUNE transfers are expected to resume in approximately 12 hours, but the specific situation depends on the decisions of the nodes. Functions such as trading, liquidity provider operations, and signing will remain unavailable, and full network restoration is expected to take several days. Recovery plans are under discussion and may include reducing the staking of affected nodes and other remedial measures proposed by the community.




