Thorchain, a popular decentralized finance (DeFi) protocol, has been exploited twice in the past two weeks, resulting in combined losses exceeding $10 million. The second attack, which drained over $8 million from the protocol’s ETH Router contract and Bifrost component, was followed by a message from the hacker embedded in the transaction input data. The attacker detailed the exact steps required to execute the exploit and criticized Thorchain for not implementing a bug bounty program or hiring external auditors to review code managing nine-figure total value locked (TVL).
Two Exploits in Quick Succession
The first incident occurred days earlier, with the hacker stealing approximately 4,000 ETH worth of assets. The second attack specifically targeted the ETH Router contract and Bifrost component, leading to over $8 million in losses. According to the hacker’s on-chain message, the vulnerability had been known beforehand and was entirely preventable. The attacker pointed out that Thorchain used unsafe fund-transfer methods in its Solidity smart contract code, a practice commonly warned against by developers.
Hacker’s Detailed Instructions
The malicious actor did not leave quietly. Instead, the hacker left a step-by-step guide in the transaction input data, laying bare the exploitation process. Stolen assets included: 966.62 ACLX, 20,866,664.53 XRUNE, 1,672,794.01 USDC, 56,104 SUSHI, 6.91 YFI, and 990,137.46 USDT. Initially, Thorchain developers believed the loss was only $800,000 and thought it was a whitehat operation, but the actual figure was much larger.
Market Impact and Recovery Plan
Following the news, Thorchain’s native token RUNE fell nearly 25%, trading around $4.17 at the time of writing. Thorchain has since announced a recovery plan to reimburse affected users. More importantly, the protocol has decided to engage security firms for a full code audit and implement stronger defenses to prevent similar exploits in the future.
This incident has reignited debates within the DeFi community about the importance of security audits and bug bounty programs. What do you think of this “honest hacker”? Share your thoughts below.

