Skip to main content
Back to news
SafetyMajor story — Significance is rated automatically and is not a price signal.

THORChain Hit by $10M Exploit Linked to a Malicious Node and MPC Flaw — Here's What Went Wrong

(133 days ago) · 1 source · Summarized by CryptoBipto

THORChain suffered a significant exploit reportedly worth around $10 million, traced back to a malicious validator node and a vulnerability in the GG20 multi-party computation (MPC) protocol. The flaw allowed a private key leak, enabling the attacker to drain funds. The incident has raised fresh concerns about the security of cross-chain decentralized protocols.

WHY IT MATTERS

Imagine a group of people each holding one piece of a combination to a vault — no single person can open it alone. That's how multi-party computation (MPC) is supposed to work in crypto: multiple nodes each hold a fragment of a private key, so no one node can steal the funds. In this case, a flaw in the specific method THORChain used (called GG20) allowed a bad actor running one of those nodes to essentially figure out the full combination and drain the vault. This matters because many crypto platforms rely on similar technology to keep funds safe, and this exploit shows that even sophisticated cryptographic systems can have hidden weaknesses. If you use decentralized exchanges or cross-chain bridges, it's a reminder that smart contract risk isn't the only danger — the underlying key management can be vulnerable too.

The THORChain exploit highlights a critical vulnerability in the GG20 threshold signature scheme, a type of multi-party computation (MPC) protocol used to secure private keys across multiple nodes.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

SOURCES

  • Source

RELATED

RUNEDeFi SecurityMPC VulnerabilityCross-Chain ProtocolsExploitValidator Nodes