THORChain Proposes ADR028 After $10.7M Hack: POL Absorbs Loss, Attacker's RUNE Slashed

THORChain Proposes ADR028 After $10.7M Hack: POL Absorbs Loss, Attacker's RUNE Slashed

N
News Editor 01
2026-07-22 06:39:13
THORChain unveils ADR028 recovery plan, using Protocol-Owned Liquidity to cover $10.7M hack loss, slashing the attacker's staked RUNE and burning surplus, while trading resumes only after bug fix and node churn. Node operators are now voting.
THORChainADR028cross-chain hackRUNEDeFi

On May 15, THORChain suffered a $10.7 million exploit via a GG20 TSS vulnerability. One week later, the community published recovery proposal ADR028, now pending a vote by node operators. The plan uses Protocol-Owned Liquidity (POL) as the first loss absorber, slashes the attacker's staked RUNE entirely, burns remaining surplus, and restores trading only after the bug is fixed and a node churn completes.

POL Takes the First Hit, Income Redirected for Refill

The proposal states that POL will cover the initial loss, potentially dropping to zero. Any remaining shortfall is spread among synthetic asset (Synth) holders, with the exact split still under evaluation. Future system income will be partly redirected to gradually replenish POL. This approach shields regular users from direct losses while maintaining the protocol's permissionless ethos.

Attacker's RUNE Fully Slashed and Burned

There is no ambiguity around the attacker. Innocent nodes sharing the same Asgard vault as the attacker are protected, but the attacker's staked RUNE is fully slashed. The recovered RUNE pairs with assets from the affected vault; any excess RUNE is burned. THORChain also offered a bounty for returning funds, with the plan rolling back proportionally if funds are partially returned. The protocol reaffirms its neutral, permissionless stance—trading will not censor the attacker's Swaps post-recovery.

Trading Resumes Only After Fix and Churn

On the technical side, caution prevails. The current GG20 Threshold Signature Scheme (TSS) will be temporarily retained and patched. Trading will not restart until the vulnerability is fully fixed and the network completes a Churn (node rotation). Future releases will adopt a slower, security-first cadence. Node operators are now voting on the direction and principles of ADR028; specific figures are preliminary and will be adjusted via on-chain Mimir voting. The primary goal is to reopen the network as soon as possible—a yes vote authorizes the dev team to proceed.

After the attack, RUNE dropped over 26% in seven days, now trading around $0.43.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.