THORChain, the decentralized cross-chain liquidity protocol, has been exploited for approximately $10.7 million across Bitcoin, Ethereum, BNB Chain, and Base. The protocol paused trading and triggered an emergency network shutdown following the attack — a move that immediately drew sharp criticism given THORChain’s long-standing positioning as a censorship-resistant, permissionless protocol.

The exploit was first flagged by on-chain investigator zachXBT, with PeckShield subsequently confirming the figures: approximately 36.75 BTC worth $3 million, plus roughly $7 million in assets from BNB Chain, Ethereum, and Base. The stolen funds have been traced to two primary addresses on-chain, publicly identified in real time by security researchers.

THORChain’s team has not yet issued a public statement on the exploit.

What Was Stolen and Where It Went

PeckShield’s analysis confirmed total losses of approximately $10 million at initial reporting, with zachXBT subsequently updating the figure to $10.7 million as additional affected assets were identified across chains. The funds currently sit across the identified theft addresses — on Bitcoin and EVM-compatible chains — and have not yet been significantly moved, based on available on-chain data at the time of writing.

RUNE, THORChain’s native token, dropped 15% immediately following news of the exploit. The combination of an emergency halt, unconfirmed exploit details, and the protocol’s silence created exactly the kind of uncertainty that triggers rapid selling pressure in a market already sensitive to DeFi security news in 2026.

The protocol’s decision to pause trading raises a question that the community is now asking loudly: if THORChain has an emergency shutdown capability, why has it historically been deployed only when the protocol’s own assets are at risk — and not when it was being used to launder hundreds of millions in stolen funds?

The Irony Nobody Is Letting Go

The timing and context of this exploit are uncomfortable for THORChain in ways that go beyond the dollar amount. Earlier, THORChain processed approximately $800 million in volume over 36 hours as the Lazarus Group — North Korea’s state-sponsored hacking collective — used the protocol to convert approximately $175 million in stolen ETH from the KelpDAO exploit into Bitcoin. THORChain earned roughly $910,000 in fees from that activity.

At the time, the protocol’s censorship-resistant, permissionless design was cited as the reason no intervention was possible. The protocol cannot discriminate between users. It has no kill switch. It is decentralized infrastructure that processes whatever transactions are submitted to it.

Then its own funds were at risk — and the kill switch appeared immediately.

The observation circulating across crypto X is pointed: a protocol that positioned itself as unable to stop Lazarus Group from laundering $175 million in stolen funds managed to halt all trading within hours of being exploited itself. Whether that reflects a genuine architectural distinction or a selective application of decentralization principles is a conversation THORChain will need to have publicly.

What THORChain Actually Is — and Why It Keeps Appearing in These Stories

THORChain is a decentralized, autonomous cross-chain liquidity protocol that enables users to swap native assets — actual Bitcoin, actual Ethereum, actual BNB — directly across different blockchains without using wrapped tokens or centralized intermediaries. It is, in the simplest framing, Uniswap for native Bitcoin. Where Uniswap allows asset swaps within the Ethereum ecosystem, THORChain enables direct swaps between native BTC and native ETH — something no other permissionless protocol does at scale.

That capability is genuinely valuable for legitimate DeFi users. It is also uniquely attractive for anyone trying to move and obscure large quantities of stolen funds across chains. Converting stolen ETH into native Bitcoin through a permissionless protocol with no KYC, no transaction screening, and no ability to freeze or reverse transactions is close to ideal from a money laundering perspective — and Lazarus Group has exploited that capability repeatedly.

THORChain has become one of the most frequently cited protocols in post-hack fund tracing precisely because of its cross-chain architecture. The Bybit hack funds moved through it. The KelpDAO funds moved through it. The protocol sits at the center of the most significant crypto theft investigations of 2026 — not as a victim, but as infrastructure.

May 2026’s DeFi Security Record Keeps Getting Worse

This is the latest in a string of DeFi exploits that has made May 2026 one of the most damaging months in the industry’s security history. TrustedVolumes lost $6.7 million last week. The cumulative toll from DeFi exploits since January now exceeds $6 billion — with April and May alone accounting for a disproportionate share of the damage.

The THORChain exploit differs from most of May’s incidents in one significant way: it targets protocol-level infrastructure rather than a market maker, bridge, or individual contract. Cross-chain liquidity pools are among the most complex and highest-value targets in DeFi — and the combination of multi-chain exposure and the scale of funds that flow through them makes them structurally attractive for sophisticated attackers.

The investigation is ongoing. THORChain has not confirmed the attack vector, the total losses, or a timeline for resuming normal operations. The on-chain addresses holding the stolen funds remain publicly visible and are being actively monitored by the security community