THORChain suffered a $10.7M cross-chain exploit on May 15, 2026, triggering an emergency trading halt and a 12% RUNE collapse — exposing the systemic fragility of native cross-chain liquidity infrastructure at scale.
~$10.8M drained across Bitcoin, Ethereum, BNB Smart Chain, and Base in a single coordinated attack, representing over 27% of THORChain's total $39.5M TVL at the time of the incident.
On-chain investigator ZachXBT and security firm PeckShield identified two primary theft addresses holding 36.85 BTC, 3,443 ETH, and 96.6 BNB alongside USDT, USDC, WBTC, and multiple DeFi tokens before the protocol activated its emergency Mimir halt.
THORChain's emergency halt mechanism — while functional — underscores that native cross-chain AMM designs carry unique systemic risk: a single routing exploit can simultaneously drain liquidity across four sovereign blockchain networks with no universal recovery mechanism.
As of May 15, 2026, no post-mortem has been released; investigators believe it remains unclear whether THORChain's own code was the direct attack target or whether the protocol was used as a high-speed cross-chain passthrough to move pre-stolen funds — a distinction with enormous legal and reputational implications.
Recovery depends on the post-mortem findings: if the exploit was external (passthrough), RUNE could retrace quickly; if the router contracts were directly vulnerable, another prolonged protocol freeze and restructuring — similar to the 2025 lending shutdown — is likely.
THORChain occupies a structurally unique position in decentralized finance. Unlike bridge-based cross-chain protocols that wrap assets and rely on custodied or synthetic representations, THORChain's Continuous Liquidity Pool (CLP) model enables native asset swaps: actual Bitcoin moves, actual Ether moves, actual BNB moves — without wrapping, without pegged tokens, and without a single centralized custodian. RUNE, the native token, plays the mandatory role of settlement asset within every swap: every liquidity pool requires an equal-value RUNE counterpart, making RUNE's price a direct multiplier on the protocol's total liquidity depth.
This design is both THORChain's competitive moat and its greatest vulnerability surface. Because it handles native Layer-1 assets across multiple sovereign blockchains simultaneously, a single compromised router or observation node can drain real, unrecoverable assets from multiple chains in a single coordinated act. There is no equivalent of an "undo" button for native Bitcoin that has left a vault. The systemic risk profile of native cross-chain AMMs is therefore categorically different from that of wrapped-asset bridges — and the May 2026 exploit crystallized that risk at scale.
The macro backdrop amplifies the significance of this incident. Cross-chain liquidity infrastructure has experienced a resurgence in 2026 as institutional DeFi interest grows, regulatory frameworks for DeFi in the EU and US mature, and Layer-2 fragmentation creates demand for seamless asset routing. THORChain's daily DEX volume had been running at $36.81M with a weekly volume exceeding $946M — meaningful figures that reflect genuine user adoption. However, the protocol has been in a fragile recovery phase since January 2025, when its lending and savers products were shuttered after accumulating approximately $200M in bad debt — a governance crisis that exposed deep tensions between growth ambition and protocol solvency.
RUNE entered 2026 already down over 70% from its previous cycle highs. The token's market cap at the time of the exploit stood at roughly $169–205M, and TVL had compressed to $39.5M — a fraction of the multi-billion dollar figures seen at peak. Against this backdrop, the May 15 exploit is not merely a one-off security incident; it is the third major crisis to strike THORChain in five years, raising legitimate questions about whether the protocol's architecture can ever achieve the security properties required for institutional-grade deployment.
A final layer of context: THORChain had already drawn regulatory and ethical scrutiny for its role as a cross-chain routing conduit in multiple major hacks, including the routing of $175M from the Kelp DAO exploit, involvement in washing funds related to the Coinbase $300M insider theft, and alleged passthrough use for IoTeX bridge hack proceeds. These controversies have made THORChain a focal point for OFAC and FinCEN discussions around DeFi infrastructure compliance — adding a regulatory dimension to the security narrative that institutional participants cannot ignore.
May 14, 2026 (late evening UTC) — Pre-Exploit Activity Detected: On-chain monitoring tools begin flagging anomalous outflows from THORChain router contracts on Ethereum and BSC. The flows involve rapid sequential swaps of USDT, USDC, WBTC, DAI, AAVE, Chainlink (LINK), FOX, LUSD, XRUNE, and GUSD — a broad-spectrum asset extraction pattern consistent with automated MEV-style vault draining.
May 15, 2026 (early hours UTC) — ZachXBT Issues Public Alert: Blockchain investigator ZachXBT posts a high-urgency alert on social media: "IT APPEARS THORCHAIN WAS LIKELY EXPLOITED ON BITCOIN, ETHEREUM, BSC, BASE FOR $10.7M+" — the first public identification of the incident. ZachXBT notes he identified the event by tracking wallet activity that moved funds through THORChain's cross-chain liquidity routing. Initial loss estimates begin at $7.4M and are revised upward within hours.
May 15, 2026 (morning UTC) — PeckShield Confirms, THORChain Activates Emergency Halt: Security firm PeckShield independently confirms two primary theft addresses. THORChain's Mimir governance module flips both the HALT-TRADING and HALT-SIGNING parameters to active. A global node pause is initiated beginning at block 26190429, lasting approximately 12 hours and 42 minutes. Native RUNE transactions continue during the halt — only cross-chain swaps and observations are frozen. The halt effectively seals the protocol's remaining liquidity against further extraction.
May 15, 2026 (morning–afternoon UTC) — Funds Confirmed Across Four Chains: Arkham Intelligence data confirms the attacker's consolidated holdings: 36.85 BTC ($2.97M), 3,443 ETH ($7.77M), and 96.6 BNB (~$66K), with additional ERC-20 positions in USDT, USDC, WBTC, and multiple DeFi governance tokens. Total estimated losses reach $10.8M. The four-chain spread — Bitcoin, Ethereum, BNB Smart Chain, and Base — is deliberately diversified, complicating on-chain tracing and any potential asset recovery.
May 15, 2026 (afternoon UTC) — RUNE Price Impact Materializes: RUNE drops from approximately $0.58 to $0.50, an intraday decline of 12–15%, within minutes of ZachXBT's alert spreading across crypto social networks. Trading volume spikes to $30.5M over 24 hours as panic selling dominates. The token's market cap compresses to approximately $169.5M. The drop is amplified by the token's pre-existing weakness — RUNE was already down 70%+ year-over-year — leaving almost no fundamental support floor.
May 15–16, 2026 — Investigation Ongoing, No Post-Mortem Released: As of publication, THORChain has not released a formal post-mortem. On-chain investigators float a nuanced hypothesis: the exploited funds may not have originated from THORChain's own liquidity pools. Instead, the protocol may have been used as a cross-chain passthrough — a routing layer to rapidly move pre-stolen assets from other exploit sources across blockchains, taking advantage of THORChain's speed, native-asset capability, and privacy properties. If confirmed, this "passthrough hypothesis" would absolve the protocol's smart contracts of direct vulnerability but would intensify regulatory scrutiny of THORChain as a money-laundering vector.

THORChain's architecture is built on a Tendermint-based Layer-1 blockchain (the THORChain chain) that coordinates cross-chain liquidity via a network of validator nodes, each of which runs full nodes for every connected blockchain. Vaults — multi-party computation (MPC) wallets collectively managed by node operators — hold native assets on each chain. Inbound transactions are observed by nodes on the originating chain, validated on the THORChain layer, and outbound transactions are signed and broadcast to the destination chain by the asgard vault collective. The RUNE token acts as the universal quote asset: all pools are RUNE-denominated, and every swap routes through RUNE as an intermediary (Asset A → RUNE → Asset B).
This design creates multiple distinct attack surfaces. The router contract — a Solidity contract deployed on EVM-compatible chains (Ethereum, BSC, Base) that acts as the deposit address for swaps — represents the primary vulnerability point on EVM chains. If the router contract contains a reentrancy flaw, an incorrect access control check, or an exploitable callback pattern, an attacker can drain assets from the vault by constructing malicious inbound transactions that trigger unauthorized outbound signing. On Bitcoin, the vault is a multi-sig address; attacks against the BTC vault typically require compromising the MPC key ceremony or exploiting observation logic in the chain client.
The multi-chain nature of the theft — spanning Bitcoin (UTXO-based), Ethereum/Base (EVM), and BSC (EVM fork) — suggests one of three possible attack vectors: (1) A router contract exploit on EVM chains, with the BTC component representing a separate, coordinated liquidity drain using THORChain as the exit mechanism. (2) An observation manipulation attack, where fraudulent inbound transactions convince THORChain nodes that deposits occurred, triggering legitimate outbound signing that drains vault funds. (3) A passthrough scenario, where the attacker used THORChain as a multi-chain washing service to rapidly convert pre-stolen assets — no THORChain code was exploited, but the protocol's speed and native-asset capability were weaponized against THORChain's own liquidity providers and swap users.
The diversity of tokens extracted — USDT, USDC, WBTC, DAI, AAVE, LINK, FOX, LUSD, XRUNE, GUSD — is notable. A pure router drain would typically focus on the largest liquidity pools (BTC, ETH, stablecoins). The presence of small-cap DeFi tokens (FOX, XRUNE, GUSD) suggests either a sweep of all available vault contents, or that these tokens represent laundered proceeds from other exploits being cross-chain routed simultaneously. ZachXBT's framing of the incident as possibly "THORChain used as passthrough" rather than "THORChain router exploited" gains credibility from this token mix.
THORChain's Mimir governance system — the emergency halt mechanism — performed as designed: nodes collectively voted to freeze trading within hours of the alert, preventing additional drains. However, the halt also revealed a governance tension: Mimir parameters are set by node vote, meaning the halt required consensus among validator operators. In a fast-moving exploit, the ~12-hour window from attack initiation to full halt leaves substantial time for continued draining if attacker throughput is high. Future protocol designs may need cryptographic circuit-breakers that activate autonomously upon detecting anomalous outflow patterns, without requiring node consensus.
sequenceDiagram
participant Attacker
participant EVM_Router as EVM Router Contract<br/>(ETH/BSC/Base)
participant TC_Chain as THORChain Layer-1<br/>(Tendermint)
participant Node_Network as Validator Nodes<br/>(MPC Vaults)
participant BTC_Vault as Bitcoin Vault<br/>(Multi-sig)
participant ZachXBT as ZachXBT / PeckShield<br/>(On-chain Intel)
participant Mimir as Mimir Governance<br/>(Emergency Halt)
Attacker->>EVM_Router: Malicious inbound tx / passthrough swap
EVM_Router->>TC_Chain: Observation relayed by nodes
TC_Chain->>Node_Network: Authorize outbound signing
Node_Network->>Attacker: Native BTC / ETH / BNB released to theft wallet
Note over Attacker: 36.85 BTC + 3,443 ETH + 96.6 BNB + ERC-20s
Attacker->>Attacker: Funds dispersed across 4 chains
ZachXBT->>ZachXBT: Detects anomalous wallet flows
ZachXBT-->>TC_Chain: Public alert — $10.7M+ suspected
PeckShield-->>TC_Chain: Confirms theft addresses
TC_Chain->>Mimir: Halt-Trading + Halt-Signing params flipped
Mimir->>Node_Network: Global pause from block 26190429
Note over Node_Network: Halt lasts ~12h 42min
Node_Network-->>Attacker: Further draining blockedMetric | Value | Change | Source |
|---|---|---|---|
RUNE Price (post-exploit) | $0.50 | -12% to -15% (intraday) | CoinGecko / BingX |
RUNE Market Cap | ~$169.5M | -12% | CoinGecko |
THORChain TVL | $39.5M | Pre-exploit baseline | DefiLlama |
Estimated Exploit Loss | ~$10.8M | 27.3% of TVL | ZachXBT / Arkham |
ETH in Theft Wallets | 3,443 ETH (~$7.77M) | N/A | Arkham Intelligence |
BTC in Theft Wallets | 36.85 BTC (~$2.97M) | N/A | Arkham Intelligence |
BNB in Theft Wallets | 96.6 BNB (~$66K) | N/A | Arkham Intelligence |
THORChain Daily DEX Volume | $36.81M | Pre-exploit | DefiLlama |
THORChain Weekly DEX Volume | $946.31M | Pre-exploit | DefiLlama |
RUNE 1-Year Performance | -70%+ | Year-over-year | CoinGecko |
24H Trading Volume (post-exploit) | $30.5M | Elevated on panic | CoinMarketCap |
Annualized Protocol Fees | $17.7M | Pre-exploit annualized | DefiLlama |
The exploit's scale — approximately $10.8M — represents 27.3% of THORChain's $39.5M TVL at the time of the incident. This ratio is critically important for assessing counterparty risk: a protocol where a single exploit can drain more than a quarter of locked liquidity carries a tail risk profile incompatible with institutional-grade custody standards. For comparison, the Ronin Bridge hack drained approximately 73% of its TVL; the Wormhole exploit drained roughly 40%. THORChain's figure, while severe, sits in a category of "serious but not existential" — provided the protocol's core vault structure remains intact.
The RUNE token's market reaction — an immediate 12–15% decline settling around -12% — reflects rational risk-adjusted repricing, not panic overshoot. Given that RUNE was already down 70% year-over-year entering the incident, the token's market cap offers limited buffer against further confidence erosion. The annualized fee revenue of $17.7M against a market cap of ~$169.5M gives a price-to-revenue multiple of approximately 9.6x — reasonable for a functioning DeFi protocol, but vulnerable to compression if the exploit triggers sustained liquidity exodus or if node operators reduce stake. The halt lasting nearly 13 hours also directly reduces fee revenue for that period — a tangible economic cost to liquidity providers independent of any direct loss.
Maya Protocol is the most direct architectural competitor: a community-driven fork of THORChain's codebase that introduced its own CACAO liquidity token and supports chains not on THORChain's roadmap, including Dash and Kujira. Maya shares THORChain's core CLP design and therefore shares a similar security risk profile — a double-edged sword. The May 2026 incident may perversely benefit Maya in the short term as THORChain's liquidity is frozen, driving routing flows to Maya. However, any analysis confirming a flaw in the core CLP architecture would place Maya under equivalent scrutiny, given the shared codebase. Maya's TVL is substantially smaller, which limits both its attack surface and its liquidity depth — a trade-off between security exposure and usefulness.
Chainflip represents a technically distinct approach to native cross-chain swaps. Rather than THORChain's MPC vault model, Chainflip uses a Substrate-based blockchain with State Chain validators and a novel "just-in-time AMM" design optimized for reducing slippage on large trades. Backed by $16M in VC funding from Framework Ventures, Blockchain Capital, and Pantera Capital, Chainflip has the institutional relationships and runway to survive multiple market cycles. Crucially, Chainflip's architecture is architecturally separated enough from THORChain's that a THORChain router exploit does not necessarily imply Chainflip vulnerability — a meaningful competitive advantage in the post-exploit environment.
LayerZero-based bridges and OFT (Omnichain Fungible Token) protocols occupy a different product category — they primarily move wrapped or synthetic assets rather than native assets — but represent the dominant cross-chain volume by TVL. Protocols like Stargate and Across handle billions in bridging volume with a fundamentally different security model (relayers, oracles, security councils). After multiple bridge exploits in 2021–2023, many larger protocols have migrated toward LayerZero's decentralized verification approach. For users who prioritize security over native-asset purity, LayerZero-based solutions have a compelling track record relative to native AMM cross-chain protocols.
Centralized exchange cross-chain settlement (e.g., Binance Convert, Coinbase One-Click Exchange) remains the dominant method for retail cross-chain asset swaps by volume. For institutional participants, CEX-based cross-chain routing offers regulatory clarity, custodial insurance, and no on-chain exploit risk — at the cost of KYC requirements, counterparty credit risk, and centralized custody. The THORChain incident reinforces the institutional migration toward regulated, centralized cross-chain infrastructure for large positions, while native DEX alternatives face persistent security overhead.
The competitive implication for THORChain specifically is that the protocol's unique value proposition — truly native, permissionless, self-custodied cross-chain swaps — remains architecturally valid but security-challenged. No direct competitor currently offers the same native Bitcoin liquidity depth with equivalent decentralization. This creates a durable, if contested, niche — provided THORChain can resolve its security trajectory.
Liquidity Providers (LPs): The most directly impacted constituency. LPs who supplied native assets to THORChain's pools face potential impermanent loss amplified by both the exploit-driven RUNE price decline and the direct asset drains. THORChain's LP protection mechanisms include an impermanent loss protection system (ILP) that was partially suspended during the 2025 lending crisis. Whether ILP will apply to losses from the exploit — or whether the protocol will invoke its "insolvency protocol" — depends on the post-mortem findings. LPs should consider the halt as a de facto forced lock-up with uncertain exit timeline.
RUNE Token Holders: Retail and institutional RUNE holders face mark-to-market losses of 12–15% intraday, compounding on an existing 70% annual drawdown. The token's value is structurally tied to protocol TVL (since all pools require equal RUNE collateral), meaning any sustained LP exodus will mechanically suppress RUNE's price floor. However, if the post-mortem determines no protocol code vulnerability, RUNE could recover sharply — the halt mechanism itself is a functioning circuit-breaker, and protocol continuity is a positive signal.
Node Operators (Validators): THORChain node operators — who collectively manage the MPC vaults and receive RUNE bond rewards — face reputational and economic exposure if the exploit is tied to a compromise in vault signing. Node operators who were active during the exploit window may face social pressure within the community, even if technically compliant. The 12-hour halt cost nodes approximately $48,000 in forfeited fee income at current annualized run-rates — a manageable but non-trivial figure for smaller operators.
THORSwap and Ecosystem dApps: THORSwap — the primary consumer-facing DEX built on THORChain infrastructure — experienced a complete trading halt alongside the base protocol. Every ecosystem application (THORSwap, ShapeShift, SwapKit integrations) was effectively offline for ~13 hours. Revenue-generating dApps built on THORChain routing face reputational damage with their own users who experienced sudden, unexplained trading unavailability. This may accelerate multi-protocol routing integrations (THORChain + Chainflip fallback) as a business continuity hedge.
Regulators: The OFAC, FinCEN, and EU DORA teams monitoring DeFi infrastructure compliance will likely treat this incident as additional evidence for the risks of unregulated, permissionless cross-chain routing. Whether the exploit involved THORChain's own code or used it as a passthrough for criminal funds, both scenarios fit the regulatory narrative of DeFi infrastructure as a money-laundering vector. Expect enforcement guidance and potential action to reference this incident.
Institutional DeFi Funds: Funds with cross-chain exposure — particularly those using THORChain routing for treasury management or cross-chain arbitrage — should treat this as a Category 2 risk event (protocol suspended but not collapsed). The incident materially weakens the case for native cross-chain AMM exposure in institutional portfolio construction until a complete, audited post-mortem is published.
Direct Protocol Insolvency Risk — If the exploit represents a direct drain from THORChain's vault contracts (not a passthrough scenario), the $10.8M loss against $39.5M TVL is a 27.3% solvency impairment. THORChain has previously navigated solvency crises (the 2025 $200M bad debt event) through protocol-level restructuring and debt forgiveness, but repeated insolvency events erode long-term LP confidence irreparably. Severity: High. Probability: 30–40% (depending on post-mortem outcome).
Regulatory Action and Protocol Sanctions Risk — THORChain's history as a passthrough for stolen funds from multiple major hacks (Kelp DAO, Coinbase insider theft, IoTeX bridge) has placed it in direct OFAC focus. A confirmed connection between the May 2026 exploit funds and sanctioned wallets or state-sponsored actors (e.g., Lazarus Group, which has previously used THORChain) could trigger OFAC SDN listing of the protocol or its associated addresses. Node operators in regulated jurisdictions would face immediate legal exposure. Severity: Critical. Probability: 20–30%.
Sustained Liquidity Exodus Post-Halt — Even if the post-mortem is benign, LP confidence is a fragile resource. The 2025 lending shutdown triggered months of sustained TVL outflows. A second major crisis event within 18 months significantly raises the probability of a structural LP exodus that could reduce TVL to sub-$15M — below the level needed to generate competitive swap pricing. Severity: High. Probability: 45–55%.
MPC Vault Compromise Cascading Risk — THORChain's multi-party computation vault system, if the signing key ceremony or vault rotation logic contains a flaw exploitable across chains simultaneously, could in theory allow a sophisticated attacker to drain all vaults in a coordinated fashion. The four-chain simultaneous nature of this exploit — while possibly explained by passthrough use — is also consistent with a coordinated multi-chain vault compromise. A full vault compromise at today's TVL would represent total protocol loss. Severity: Catastrophic. Probability: 10–15%.

For funds with existing RUNE exposure, the binary outcome of the post-mortem warrants a wait-and-observe position rather than either panic liquidation or immediate averaging down. The 12–15% intraday drawdown has already priced in a meaningful portion of the bad news, and RUNE's market structure — already at multi-year lows on a 70% annual decline — leaves limited additional downside if the post-mortem clears the protocol's core contracts. Conversely, the risk of regulatory escalation (OFAC SDN listing of THORChain-related addresses) represents a discontinuous, non-linear downside that cannot be hedged through position sizing alone. Funds operating in regulated jurisdictions should consult compliance counsel before increasing RUNE exposure in this environment.
For cross-chain infrastructure builders and protocol architects, the THORChain incident reinforces a design principle that the field has been slow to adopt: autonomous circuit-breakers at the smart contract level. The 12-hour node-vote halt process is governance-dependent; a world-class security system should be able to detect anomalous vault outflow patterns autonomously and pause affected contracts within seconds, not hours. THORChain's next upgrade cycle should prioritize real-time anomaly detection at the router contract level — potentially through integration with decentralized security oracle networks (Forta, BlockSec Watch) — as a non-negotiable prerequisite for institutional trust.
For ecosystem participants — THORSwap, ShapeShift, and other THORChain-dependent dApps — the incident provides a clear strategic imperative: diversify routing infrastructure. Single-protocol dependency on THORChain creates a single point of failure that directly maps to user-facing downtime and reputational risk. SwapKit's multi-protocol routing model (THORChain + Maya + Chainflip + NEAR Intents) is the correct architectural response, and ecosystem partners not yet implementing fallback routing should treat this incident as a forcing function. Protocols with multi-chain routing redundancy not only improve uptime but may also capture THORChain's displaced volume during halt periods — a short-term revenue opportunity that reinforces long-term competitive positioning.
30 days: THORChain will publish a post-mortem within 2–4 weeks. If the post-mortem confirms the passthrough hypothesis (no protocol code directly compromised), RUNE will recover 50–70% of its drawdown as market sentiment resets. If it confirms a router vulnerability, expect a second governance crisis, a node vote on protocol upgrades, and RUNE to test $0.35 support. Trading volume will remain depressed regardless of outcome while LPs reassess risk parameters.
180 days: THORChain's medium-term trajectory depends on two catalysts: (1) a successful security audit of its router contracts and MPC vault signing protocol by a top-tier firm (Trail of Bits, Certora, or similar), and (2) whether OFAC takes any action related to the passthrough-for-stolen-funds allegations. If both resolve favorably, TVL can recover toward $50–60M as protocol confidence rebuilds. If OFAC acts, THORChain faces an existential legal challenge that no amount of technical upgrades can resolve — similar to the Tornado Cash precedent but with a functioning, non-privacy-focused protocol.
365 days: Structurally, THORChain holds a unique and defensible position as the only sufficiently decentralized protocol enabling native Bitcoin liquidity in cross-chain AMM pools at scale. No competitor has replicated this capability with comparable node decentralization. If the protocol survives the immediate crisis, completes a credible security overhaul, and avoids regulatory collapse, the one-year outlook is constructive: growing Layer-2 fragmentation, Bitcoin ETF-adjacent DeFi demand, and institutional cross-chain treasury management needs all point toward TAM expansion for native cross-chain AMMs. However, "if" is doing significant work in that sentence — THORChain has now exhausted most of the goodwill typically extended to early-stage infrastructure protocols, and a third major crisis would likely be terminal for the protocol as currently constituted.
CoinDesk — "Thorchain halts trading after $10 million cross-chain exploit, RUNE token drops 12%" (May 15, 2026): https://www.coindesk.com/tech/2026/05/15/thorchain-halts-trading-after-usd10-million-cross-chain-exploit-rune-token-drops-12
The Block — "THORChain pauses trading as security researchers flag suspected $10M multi-chain exploit": https://www.theblock.co/post/401462/thorchain-pauses-trading-as-security-researchers-flag-suspected-10m-multi-chain-exploit
Decrypt — "THORChain's RUNE Token Plunges Double Digits After $10M Exploit, Trading Halt": https://decrypt.co/367943/thorchains-rune-token-plunges-double-digits-after-10m-exploit-trading-halt
Crypto.news — "ZachXBT warns THORChain losses may top $10M after halt": https://crypto.news/zachxbt-warns-thorchain-losses-may-top-10m-after-halt/
Cryptopolitan — "THORChain suffers $10M multi-chain hack, Rune tanks 11%": https://www.cryptopolitan.com/thorchain-multi-chain-hack-rune-tanks/
CoinGape — "BREAKING: THORChain Suffers $10M Exploit Across Bitcoin, Ethereum, BSC, Base Chains": https://coingape.com/thorchain-suffers-10m-exploit-across-bitcoin-ethereum-bsc-base-chains/
AMBCrypto — "THORChain exploit hits Bitcoin, Ethereum, and BSC — Hackers steal over $10M": https://ambcrypto.com/thorchain-exploit-hits-bitcoin-ethereum-and-bsc-hackers-steal-over-10-mln/
BanklessTimes — "ZachXBT Says THORChain Likely Exploited Across Four Chains for $10.7M": https://www.banklesstimes.com/articles/2026/05/15/zachxbt-says-thorchain-likely-exploited-across-four-chains-for-10-7m/
Yahoo Finance — "ZachXBT Flags Multi-Chain THORChain Exploit as Stolen Funds Surge Past $10 Million": https://finance.yahoo.com/markets/crypto/articles/zachxbt-flags-multi-chain-thorchain-102205506.html
DefiLlama — "Thorchain DEX TVL, Fees, Revenue, Volume": https://defillama.com/protocol/thorchain-dex
CoinGecko — "THORChain Price: RUNE/USD Live Price Chart, Market Cap": https://www.coingecko.com/en/coins/thorchain
BingX News — "RUNE Drops 15% After ZachXBT Says THORChain May Have Been Exploited": https://bingx.com/en/news/post/rune-drops-after-zachxbt-says-thorchain-may-have-been-exploited
Maya Protocol — "THORChain and Maya: A Comparative Analysis": https://www.mayaprotocol.com/blog-maya-academy/thorchain-and-maya-a-comparative-analysis
dexrank — "THORChain Review 2026: Is Native Cross-Chain Worth the Risk?": https://dexrank.com/reviews/thorchain/