THORChain was hit by a coordinated exploit spanning Bitcoin, Ethereum, BNB Chain, and Base, with losses estimated at $10.8 million. The protocol moved quickly to halt all trading and signing operations, and its native token RUNE fell about 12% after the incident became public.
On-chain investigator ZachXBT and security firm PeckShield detected suspicious fund movements on all four networks at nearly the same time. Based on current tracking, wallets linked to the attacker are holding about 3,443 ETH, 36.85 BTC, and 96.6 BNB. Because the drain happened across multiple chains in one event, attention has shifted to a shared weakness in THORChain’s cross-chain routing layer rather than an isolated contract flaw on a single network.
Trading stopped as the attack vector remains unknown
As of publication, THORChain had not released a post-mortem, and the exact attack vector was still under investigation. For a protocol that manages multi-chain liquidity pools, downtime means cross-chain swaps are interrupted. Aggregators and front ends that depend on THORChain routing can also face immediate disruption. The team has contained activity for now, but the cause and full scope of the exploit have not yet been disclosed.
This is not the first major security incident involving THORChain. In July 2021, the protocol suffered two attacks within a single week, losing about $5 million and $8 million. Including the latest exploit, THORChain has faced at least three major security incidents in recent years.
Cross-chain infrastructure remains a prime target
Cross-chain bridges and liquidity protocols have remained one of DeFi’s most heavily targeted sectors. The source material says that since 2021, more than $2.8 billion has been stolen from this category of protocol. That total includes $625 million from Ronin Bridge and $320 million from Wormhole. These systems must keep state aligned across several blockchains, which creates a broader and more complex attack surface than single-chain applications.
The THORChain exploit fits that pattern. Four chains were affected in one coordinated incident, pointing to a common weakness at the infrastructure level. A clearer picture will depend on what the project discloses in its post-mortem.

