BlockBeats news, September 27 — THORChain, as a cross-chain decentralized liquidity protocol, has suffered multiple security incidents since 2021. In July 2021, two consecutive "fake deposit" attacks resulted in combined losses of approximately $16 million; on May 15, 2026, a malicious node operator exploited a vulnerability in the GG20 threshold signature scheme to reconstruct vault private keys and drained approximately $10.7 million in assets from a single Asgard vault, involving Bitcoin, Ethereum, BNB Chain, Base, and multiple other chains. Combined with incidents such as the theft from the founder's personal wallet, cumulative losses have approached $25 million. The protocol subsequently suspended trading for 39 days, resuming operations only after security upgrades.
More notably, THORChain, due to its ability to enable direct cross-chain swaps without wrapped assets (especially ETH to BTC), has become an important channel for hacker money laundering. After Bybit was hacked for approximately $1.4 billion in February 2025 (the largest crypto theft in history), North Korea's Lazarus Group moved approximately $1.2 billion (85%) of the stolen funds through THORChain, with node operators earning millions of dollars in fees; in the April 2026 KelpDAO hack of approximately $300 million, about $175 million in funds also flowed through the platform. In addition, THORChain has appeared in cases involving the FTX hacker, WazirX, Atomic Wallet, and others. According to analysis, across at least 7 confirmed money laundering incidents between 2023 and 2026, the volume of illicit transactions processed through THORChain amounted to approximately $9.27 billion, with the protocol and liquidity providers earning approximately $12.47 million in fees.
After Bitget CEO formally demanded that THORChain refuse to provide services to attacker addresses, THORChain responded that its protocol, like Bitcoin, Ethereum, and BNB Chain, is a decentralized, permissionless network.
Previously, under pressure, the THORChain community voted to discuss whether to block relevant addresses, but ultimately declined to intervene on the grounds of "decentralization and no censorship," with the lead developer even resigning over the matter. Supporters argue this is the essence of open infrastructure; critics point out that the protocol has in effect provided a convenient channel for criminal funds, sparking fierce controversy over DeFi neutrality and responsibility. This series of events highlights the long-term tension between convenience and security compliance in cross-chain protocols.

