Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
cryptocurrency-platform-riskoperational-disruptionthreat-infrastructure-tracking

THORChain Asgard Vault Breach Drained More Than $10 Million Across Nine Blockchains

Updated 1mo agoFirst seen May 15, 20265 sources

THORChain disclosed that one of its six Asgard vaults was compromised, enabling unauthorized outbound transactions before the network halted signing activity. Loss estimates ranged from about $10.7 million to more than $11 million, with stolen assets taken across at least nine blockchains including Bitcoin, Ethereum, BNB Smart Chain, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP. Investigators said the attacker initially dispersed funds across multiple chains and later consolidated proceeds into a two-address cluster, while THORChain said automated detection helped stop additional transfers.

The root cause remained under investigation, with THORChain examining possible issues in the GG20 implementation layer as well as potential infrastructure or operational compromise affecting node operators. The protocol paused signing-related churn activity, delaying validator rotation and other operations, and asked operators to review infrastructure, key management, and Bifrost logs tied to the affected vault. TRM Labs said no actor had been attributed at publication time, but urged compliance teams to quickly screen counterparties and flag deposits linked to tagged addresses as the stolen funds continue to move.

Share:
THORChain Asgard Vault Breach Drained More Than $10 Million Across Nine Blockchains
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 15, 20261mo ago

THORChain halts signing and pauses churn during investigation

After detecting the unauthorized transfers on May 15, 2026, THORChain said its automated systems stopped further outbound activity, halted signing, and paused churn operations. The team began investigating possible causes including a GG20 implementation flaw, node operator infrastructure compromise, or other unauthorized-signing vectors, and asked operators to review security and provide Bifrost logs.

THORChain exploit drains over $10.7M from an Asgard vault

On May 15, 2026, an attacker compromised one of THORChain’s six Asgard vaults and executed unauthorized outbound transactions, draining roughly $10.7 million to more than $11 million across at least nine blockchains. Investigators said the attacker initially dispersed funds across chains before consolidating proceeds into a two-address cluster.

May 13, 20262mo ago

OpenLoop confirms 716,000 people affected by January breach

On May 13, 2026, reporting based on OpenLoop’s disclosures said the January breach affected 716,000 individuals, a figure recently reflected in the U.S. Department of Health and Human Services breach portal. The same reporting noted a hacker calling themselves Stuckin2019 claimed responsibility and alleged a larger theft of 1.6 million patient records, though OpenLoop confirmed 716,000 impacted individuals.

Mar 17, 20263mo ago

OpenLoop reports breach to authorities and issues notification letter

By March 17, 2026, OpenLoop had reported the incident to authorities, coordinated with federal law enforcement, and issued a breach notice. The notice said about 2,200 Rhode Island residents were affected and offered one year of IDX identity and credit monitoring.

Jan 8, 20266mo ago

OpenLoop data theft occurs during January 7–8 intrusion window

OpenLoop said unauthorized access and data exfiltration occurred between January 7 and January 8, 2026. The company stated the incident did not involve electronic health records, Social Security numbers, or financial account information.

Jan 7, 20266mo ago

OpenLoop Health discovers unauthorized access to its systems

OpenLoop Health detected a cyber incident on January 7, 2026 and began investigating with external cybersecurity specialists. The company later determined an unauthorized third party had accessed certain systems and removed data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Threat actors
1 linked
Organizations
12 linked
THORChainDriftByBitPeckShieldTRM LabsKelpDAOIDXOpenLoop HealthTransUnionExperianEquifaxSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

THORChain Asgard Vault Breach Drained More Than $10 Million Across Nine Blockchains | Mallory