Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.
Back to news
securityhigh impact

THORChain Hit by $10M Exploit Linked to a Malicious Node and MPC Flaw — Here's What Went Wrong

82d ago · 1 source

THORChain suffered a significant exploit reportedly worth around $10 million, traced back to a malicious validator node and a vulnerability in the GG20 multi-party computation (MPC) protocol. The flaw allowed a private key leak, enabling the attacker to drain funds. The incident has raised fresh concerns about the security of cross-chain decentralized protocols.

WHY IT MATTERS

Imagine a group of people each holding one piece of a combination to a vault — no single person can open it alone. That's how multi-party computation (MPC) is supposed to work in crypto: multiple nodes each hold a fragment of a private key, so no one node can steal the funds. In this case, a flaw in the specific method THORChain used (called GG20) allowed a bad actor running one of those nodes to essentially figure out the full combination and drain the vault. This matters because many crypto platforms rely on similar technology to keep funds safe, and this exploit shows that even sophisticated cryptographic systems can have hidden weaknesses. If you use decentralized exchanges or cross-chain bridges, it's a reminder that smart contract risk isn't the only danger — the underlying key management can be vulnerable too.

Read the full analysis with a CryptoBipto membership

Create a free account and subscribe to unlock deep-dive analysis on every story.

Get started

SOURCES

RELATED

RUNEDeFi SecurityMPC VulnerabilityCross-Chain ProtocolsExploitValidator Nodes

Educational only — not financial advice.