THORChain disclosed that one of its six Asgard vaults was compromised, enabling unauthorized outbound transactions before the network halted signing activity. Loss estimates ranged from about $10.7 million to more than $11 million, with stolen assets taken across at least nine blockchains including Bitcoin, Ethereum, BNB Smart Chain, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP. Investigators said the attacker initially dispersed funds across multiple chains and later consolidated proceeds into a two-address cluster, while THORChain said automated detection helped stop additional transfers.
The root cause remained under investigation, with THORChain examining possible issues in the GG20 implementation layer as well as potential infrastructure or operational compromise affecting node operators. The protocol paused signing-related churn activity, delaying validator rotation and other operations, and asked operators to review infrastructure, key management, and Bifrost logs tied to the affected vault. TRM Labs said no actor had been attributed at publication time, but urged compliance teams to quickly screen counterparties and flag deposits linked to tagged addresses as the stolen funds continue to move.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After detecting the unauthorized transfers on May 15, 2026, THORChain said its automated systems stopped further outbound activity, halted signing, and paused churn operations. The team began investigating possible causes including a GG20 implementation flaw, node operator infrastructure compromise, or other unauthorized-signing vectors, and asked operators to review security and provide Bifrost logs.
On May 15, 2026, an attacker compromised one of THORChain’s six Asgard vaults and executed unauthorized outbound transactions, draining roughly $10.7 million to more than $11 million across at least nine blockchains. Investigators said the attacker initially dispersed funds across chains before consolidating proceeds into a two-address cluster.
On May 13, 2026, reporting based on OpenLoop’s disclosures said the January breach affected 716,000 individuals, a figure recently reflected in the U.S. Department of Health and Human Services breach portal. The same reporting noted a hacker calling themselves Stuckin2019 claimed responsibility and alleged a larger theft of 1.6 million patient records, though OpenLoop confirmed 716,000 impacted individuals.
By March 17, 2026, OpenLoop had reported the incident to authorities, coordinated with federal law enforcement, and issued a breach notice. The notice said about 2,200 Rhode Island residents were affected and offered one year of IDX identity and credit monitoring.
OpenLoop said unauthorized access and data exfiltration occurred between January 7 and January 8, 2026. The company stated the incident did not involve electronic health records, Social Security numbers, or financial account information.
OpenLoop Health detected a cyber incident on January 7, 2026 and began investigating with external cybersecurity specialists. The company later determined an unauthorized third party had accessed certain systems and removed data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
5 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcetrmlabs.com
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.