Útočník spojený s exploitací Coldcard přesunul během pěti dnů asi 97,09 BTC, tedy zhruba 45 % ukradených prostředků, přes THORChain a CoinJoin. Galaxy uvedla, že jde o zpeněžení části kořisti.
The hacker behind the third wave of Coldcard hardware wallet exploits has started cashing out, routing approximately 97.09 BTC, worth about $7.8 million, through cross-chain swaps and mixing services over a five-day window. Galaxy Research flagged the movement on September 7, noting it represents roughly 45% of the Wave 3 stolen funds.
The funds first hit THORChain on September 2, where they were swapped into Ether. By September 5 and 6, additional portions had been run through CoinJoin transactions, a Bitcoin privacy technique that bundles multiple users’ transactions together to obscure the trail. The attacker appears to be working through the largest vaults first, a prioritization strategy that suggests deliberate planning rather than panicked liquidation.
A firmware flaw five years in the making A firmware update shipped by Coinkite in March 2021 (version 4.0.1 onward) introduced a bug that caused Coldcard devices, primarily the Mk3 and later models, to default to a software-based pseudo-random number generator when creating wallet seeds. The hardware random number generator was effectively bypassed.
Advertisement
The result: seeds generated with only 40 to 72 bits of effective entropy. For context, modern cryptographic standards typically call for 128 to 256 bits. Skilled attackers could reconstruct private keys entirely offline through brute-force computation.
Coinkite eventually patched the firmware, but any wallet seed generated during the vulnerable window remains compromised regardless of whether the device itself has been updated. The company has urged affected users to generate entirely new seeds and migrate their funds.
The full scope: 1,789 BTC across 8,865 addresses Galaxy Research, led by analyst Alex Thorn, has been tracking the Coldcard exploit chain since the attacks began on July 30, 2026. Total confirmed losses stand at approximately 1,789 BTC, valued at around $114.7 million at the time of theft. More than 8,865 addresses have been affected, with the median victim losing more than 1 BTC. An additional cluster of 58 addresses has been identified that could push total losses to roughly 1,806 BTC.
The attacks came in waves. The first wave alone extracted 1,082.65 BTC in just 41 minutes, a staggering pace that points to automated scripts scanning the blockchain for weak keys. Galaxy’s research suggests at least 15 different attackers were involved across the waves, which ran from July 30 through August 6. Activity dropped sharply after that.
Of the total haul, 82% of stolen Bitcoin remains sitting in attacker-controlled wallets. Only 18% has shown movement consistent with laundering. Galaxy’s team has engaged directly with over 190 victims and shared identified attacker addresses with law enforcement agencies and industry partners.
THORChain’s uncomfortable spotlight The attacker’s choice of THORChain as a laundering vehicle is notable but not surprising. The decentralized cross-chain liquidity protocol enables swaps between native assets on different blockchains without requiring a centralized intermediary. THORChain’s permissionless architecture means it can’t freeze or reverse transactions the way a centralized exchange can.
The subsequent use of CoinJoin adds another layer of obfuscation. By mixing the converted funds with legitimate Bitcoin transactions, the attacker makes chain analysis significantly harder, though not impossible. Firms like Chainalysis and Elliptic have developed increasingly sophisticated tools for de-mixing CoinJoin outputs, and law enforcement has successfully traced CoinJoin-laundered funds in prior cases.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
THORChain po dlouhém výpadku znovu provedl churn a průměrná doba tvorby bloku se zlepšila asi o 300 milisekund. POL zároveň běží, přičemž 20 % systémových výnosů míří do TRON $USDT poolu.
THORSday Community Podcast #231 ft. codehans1, Devel484, CBarraford, KentonC137 & patriotsounds | September 3, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRTHORChain completed a long-awaited churn, but the stability focus continues for another week before reassessment. Monero remains built and working on stagenet, with its mainnet launch still waiting. A Gaia pause interrupted the next churn during the show.Protocol-owned liquidity is active, with 20% of system income being routed toward POL. Denny showed almost $22,000 on day three, with deposits going into the TRON $USDT pool.Rujira's app layer has resumed with two contracts still disabled. Hans wants emergency halts followed by prompt contact with the affected team and a clear route to resolution.Devel argues base-layer limit orders could improve quotes and execution for all swappers. Chad and Hans question the complexity and priority; Rujira's oracle-based DCL offers another approach to keeping trading value inside the ecosystem.Chad is building better metrics and log access for AI-assisted maintenance. Kenton reported stronger AI discovery, while ADR30's delegated node permissions still needed more votes.1. Churn Returns, but Stability Still Sets the PaceTHORChain finally churned again, bringing relief after the extended disruption. Devel said the change in the active node set immediately improved average block times by about 300 milliseconds as troubled nodes left and healthy ones entered.
That progress does not end the stability-first period discussed last week. Chad's Thursday engineering call favored another week of focused fixes, followed by reassessment. Outstanding Solana issues were one reason to continue.
"I'm hesitant to say that we've completed our stability without achieving stability." (Chad)For Monero followers, the message was explicit: the integration is built, functioning and working on stagenet. The team has not abandoned it. Monero and Zcash remain behind the decision to resume adding chains, with no new launch date given.
During the show, a Gaia pause complicated the next churn. Chad said a security concern was being investigated; details were still emerging. It illustrated a dependency he wants to revisit: adding a chain currently requires a churn. As more chains and signing schemes make that process more complex, he wants to remove avoidable dependencies on it. That is a proposed direction, not a completed redesign.
2. POL Starts Building Pool Depth Every BlockProtocol-owned liquidity, or POL, supplied the week's other concrete milestone. The setting was 20% of system income, and Denny showed almost $22,000 accumulated on day three. Allocations happen every block; the current destination was the TRON $USDT pool.
The discussion described pool selection as being recalculated each churn cycle, directing new liquidity toward an eligible pool based on its activity. The purpose is to build depth that stays under protocol ownership. Raynalytics' POL Income dashboard tracks the allocations, deposits and pool priorities.
"Its only interest is to just supply more liquidity and more depth to the pools." (Chad)Denny explored whether this made THORChain resemble an ETF or an index fund. Chad drew a boundary around that analogy: holding $RUNE does not give someone a direct redeemable share of the POL portfolio. The intended benefit is indirect, through deeper pools, more useful trading capacity and the fees that activity can generate.
Kenton floated a possible future distribution to $TCY holders if POL became sufficiently large. Chad treated that as an option, not a commitment. Treasury rebalancing was also raised, including Oleg's suggested $500,000 move toward TRON stablecoin liquidity. No allocation decision was announced.
3. Rujira Resumes With Two Contracts Still PausedThere is a material update to Saturday's discussion of the app-layer pause: Rujira is running again. Hans said the bond contract and its trading pair remained disabled while the team double-checked the relevant query paths.
He said the non-determinism issue had been fixed in v3.20, with further checks intended to establish that nothing remained. The broader lesson concerns separation: complex financial logic can sit on the app layer, but the base-layer queries it calls must still behave deterministically and contract execution must be bounded.
Hans accepted that emergency controls need to be usable immediately. His proposed follow-through was to pull the lever when necessary, contact the relevant team, and establish a clear path to resolution.
"We weren't really sure what the correct process to get things reenabled was." (Hans)The group also discussed malicious use of pause powers. Chad described counter-votes and possible governance action against offending nodes; these were responses to a hypothetical attack, not an announced automatic penalty.
Hans explained one safeguard in Rujira's credit-account design: collateral can still be sent to a position's address when app-layer execution is paused, including supported secured assets. That can help protect a position during market moves, but it does not restore every action. App-layer-only positions cannot necessarily be sold while their contracts are halted.
4. BLO's Promise Meets the Cost of More ComplexityDevel's base-layer limit-order proposal, or BLO, produced the episode's longest debate. The disagreement centered on whether the execution benefits justify adding another trading mechanism alongside THORChain's AMM pools.
Chad evaluates a feature by implementation effort, risk and expected return. BLO would add code, maintenance obligations and operational questions about how two liquidity mechanisms interact. He remains open to it, but gives it a lower priority while stability work continues. Hans shared those concerns, drawing on years of building on-chain order books and the pitfalls of rounding, iteration limits and execution time.
Devel's case is that the initial users may be a small group of arbitrageurs, while the beneficiaries are everyone whose swaps reach the base layer.
"It improves the quote, it improves the result, it improves the speeds, it reduces refunding." (Devel)He said existing limit swaps have details that make them unattractive for arbitrageurs. BLO is designed around that workflow, with the aim of winning more quotes for ordinary users. Devel and the Maya Protocol team would likely provide much of the implementation, although core review and testing would still be necessary.
Oleg Petrov from SwapKit supplied a concrete example through chat: a user wanted a fast $20 million swap involving shallow pools. BLO could let market makers post liquidity and serve it in smaller chunks. Chad challenged the assumption that enough capital would be waiting there. Devel agreed that makers would need time to reallocate funds. The example shows the opportunity and the unresolved liquidity problem; it is not a claim that BLO already solves large swaps.
Hans also explained Dynamic Concentrated Liquidity, or DCL, which Rujira is developing. Instead of quoting only along a fixed curve, it uses the strategy's average entry price and THORChain's enshrined oracle price to adjust bids and asks. Its aim is to retain more trading profit and liquidity within the ecosystem.
Devel questioned whether external arbitrageurs would capture opportunities before the oracle-driven strategy reacts. Hans welcomed the resulting price competition. Neither DCL's profitability nor BLO's adoption was presented as proven. The designs could also interact: Hans said the app layer could use base-layer order functionality if it becomes available.
5. AI Maintenance Needs Better VisibilityHans and Chad agreed that agents can already use open blockchain interfaces. An agent can generate keys and broadcast transactions; a special agent-branded chain is not a prerequisite. A convenient cross-chain command-line wallet could help, but Hans noted that agents can also work with multiple existing tools.
Chad's immediate work is more operational. He wants protocol metrics pushed into Midgard, where statistical analysis can flag unusual values. An agent could then connect those anomalies to code and logs, investigate causes and potentially open a proposed fix.
The second piece is a THORNode API for querying logs over a block range. Together, these would give developers and agents more context without requiring every investigator to run a node. Devel said he already uses a restricted MCP server to give an agent log access, and had built monitoring that notified him when a churn succeeded.
There are limits. Data from one node may not explain why another node has a different app hash. Bifrost logs also remain a separate operator-controlled source. Chad discussed possible private, opt-in sharing later, while stressing that sensitive log contents require care. Broader visibility is work underway, not a deployed autonomous maintenance system.
6. Better AI Discovery, but a Weak August Fee-Test SampleKenton showed the swap site's score on Ora, reporting an improvement from 18/100 two months earlier to 89/100. He credited SEO work and the Unstoppable Wallet developers, and said he and Randy were now seeing daily API-key requests, including projects finding THORChain through AI search. Some requests were spam or individual inquiries, so this is evidence of visibility, not a count of signed integrations.
He is also replacing older “liquidity protocol” descriptions with “decentralized exchange” where possible, so search systems associate THORChain with a term people actually use.
"We have to stop inventing words that nobody uses." (Kenton)Distribution work continues through DeFi Llama: the first paid article has launched, with roughly monthly articles planned over the next year. Blockworks also announced its dashboard. Referral tracking links were still being finished.
On execution, Kenton reported fixes for THORChain Swap, including $USDT allowance handling and THORName address entry. He asked users to retest Bitcoin Taproot flows, including a reported Ledger issue, rather than treating every route as independently verified.
The dynamic-fee experiment had a less encouraging month. Chad reported roughly $187,000 of ShapeShift volume for THORChain in August, about 6.1% of the total. He considered the sample too small for a strong conclusion and wants to add higher-volume affiliates after the stability period, with Edge Wallet mentioned as a possibility. Better discovery and better routing economics still need to turn into sustained flow.
7. ADR30 and the Next Wave of Node OperatorsADR30 remained around 37% support during the recording. The Liquify proposal would let a node owner delegate selected tasks to other addresses without handing over the key controlling the bond. A team could separate routine operation from custody, making the setup more practical for professional infrastructure providers. The vote was still open; follow it on the governance tracker.
The standby queue was another sign of activity. Denny highlighted Runetard for helping bond providers become independent node operators and encouraged other multi-node operators to consider doing the same.
The group was cautious about accelerating churn merely to clear the backlog. Chad and Devel preferred gradual changes while reliability improves. Devel also highlighted the rule that the lowest-bonded node no longer has to leave unless the active set is at capacity, allowing smaller operators to remain when they perform well.
What to WatchNext Thursday's stability review: whether remaining issues are resolved enough to resume new-chain launches, including Monero and Zcash.POL deployment: how much income accumulates, where deposits land and how pool priorities change across churn cycles.Rujira's remaining pauses: completion of the contract checks and clearer communication around future emergency halts.BLO and DCL evidence: implementation review, testing, execution benefits and how much liquidity each design can attract.AI maintenance tooling: delivery of metrics and log access, with clear boundaries around operator-specific data.Conversion into flow: whether AI discovery, paid distribution and a broader dynamic-fee sample produce sustained activity.ADR30 and node growth: further votes, successful churns and independent operators entering the active set.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
Hackeři z Coldcard Wave 3 poprvé přesunuli ukradené prostředky a část z nich převedli do ETH přes THORChain. Zhruba 90 % prostředků zůstává nepřevedeno.
Galaxy Digital Head of Research Alex Thorn stated that attackers behind the Coldcard Wave 3 recently transferred stolen funds for the first time, converting a portion of the assets to ETH via cross-chain decentralized exchange THORChain. This marks the first instance of funds from the Wave 1, Wave 2, or Wave 3 attacks being moved from the attackers’ initial wallet addresses to other on-chain addresses. Currently, approximately 90% of the stolen funds from Wave 3 remain untransferred. On-chain activity indicates the attackers encountered apparent issues when conducting conversions via THORChain, with some transactions being repeatedly refunded, though they continue to attempt converting the remaining funds.
Relevant content
The Crypto Fear & Greed Index has risen to 65, with the market remaining in "greed" territory.
According to data from Alternative, today’s Crypto Fear & Greed Index dropped to 65, up from 63 yesterday, with market sentiment remaining in the "Greed" territory. Note: The index ranges from 0 to 100, and its components include: volatility (25%), trading volume (25%), social media buzz (15%), market surveys (15%), Bitcoin’s market dominance (10%), and Google Trends analysis (10%).
10 minutes ago
Chasing the rally of the 'NiuLai' token, crypto KOL XXAntiWar transfers 17.57 million tokens to seven addresses.
According to on-chain analyst Ai Yi (@ai_9684xtpa), crypto KOL XXAntiWar, who chased the rally during the bull market, has transferred 17.57 million tokens to 7 addresses via multiple intermediaries in recent days, and is currently still in unrealized loss. Thus, while Fomo shows XXAntiWar has liquidated all positions, this is actually because new holding addresses have not been recorded.
10 minutes ago
An institution transferred 39,500 ETH worth approximately $95 million to a CEX.
According to Yuqing Monitoring, an institutional entity transferred 39,500 ETH (valued at approximately $95 million) to multiple CEXs over the past day. Over the past four days, its total transfers to CEXs have reached 142,800 ETH (worth around $345 million), while it still holds 29,735 ETH (approximately $70.9 million).
10 minutes ago
South Korea’s foreign exchange reserves posted a record increase of $14.33 billion in August.
South Korea’s foreign exchange reserves rose by $14.33 billion in August, marking the largest single-month increase in history, driven mainly by a sharp rise in commercial banks’ foreign currency deposits at the Bank of Korea (BOK). The BOK said in a Thursday statement that as of the end of August, the country’s foreign exchange reserves climbed to $442.28 billion from $427.95 billion at the end of July. The central bank added that August’s reserve growth stemmed primarily from a surge in foreign currency deposits held by financial institutions, while a weaker U.S. dollar against other currencies also boosted investment income and valuation gains on overseas assets denominated in foreign currencies. The improved reserves have strengthened South Korea’s financial buffer, as the won weakened several times in the first half of the year, drawing market attention to the country’s external financing conditions. Earlier this year, the won fell to its lowest level since 2009, prompting South Korean authorities to repeatedly warn against excessive exchange rate volatility and seek to curb capital outflows driven by massive retail investor investments in overseas assets.
10 minutes ago
Berkshire Hathaway plans to hold stakes in Japan's five major trading houses for the long term, with related stocks rising collectively.
Japanese trading house stocks rose on Thursday after Greg Abel, CEO of Berkshire Hathaway, said the firm plans to keep its stakes in these trading houses for decades to come. The trading house sector was among the top gainers in the Topix index on Thursday. Mitsubishi Corp. jumped as much as 4.5%, hitting its highest level since May; Sumitomo Corp., Mitsui & Co., Itochu Corp., and Marubeni all rose more than 2.5%. Berkshire currently holds roughly a 10% stake in each of the five trading houses. Abel, who took over as CEO from Warren Buffett in January this year, told CNBC in an interview on Wednesday that Berkshire’s holdings in the Japanese trading houses are "long-term investments" and the company intends to hold them for decades. Since Berkshire disclosed its stakes in 2020, the share prices of these Japanese trading houses have benefited from their association with Buffett. A market analyst at Tokai Tokyo Research Institute noted that Abel’s renewed show of confidence "may rekindle investors’ interest in buying trading house stocks."
10 minutes ago
Ansem: Robinhood’s Stock Price Bottoming Out and Consolidating, Expected to Hit New High in Q4
Crypto KOL Ansem wrote in a post that traditional finance (TradFi) firms consistently lag behind when integrating new crypto operations, as their suited executives often take too long to access relevant data. He believes Robinhood (HOOD) is a strong investment pick, noting its stock has been consolidating from the bottom, while the company is adding a key new revenue stream through its Layer 2 blockchain business. Robinhood’s stock is projected to hit a new all-time high in the fourth quarter, rising 50% from its current level.
THORChain spustil veřejný dashboard s přehledem výnosů, objemu obchodů i stakingových dat. V červenci 2026 po obnovení obchodování vytvořil 950 tis. USD na poplatcích a zobchodoval asi 797 mil. USD.
THORChain now has a public-facing dashboard that puts its revenue, trading volume, staking data, and network distribution metrics on full display. The move is part of a broader transparency push that includes a collaboration with DeFiLlama and independent analytics from data analyst Raynalytics.
The numbers behind the comeback In July 2026, its first full month after restarting trading, the protocol generated $950K in fees, placing it 12th among all decentralized exchanges. Trading volumes during that same month hit approximately $797M.
As of mid-August 2026, THORChain’s cumulative fees have reached $173M, while total swap volume has crossed $124B.
Advertisement
The protocol’s core value proposition has always been enabling native asset swaps without wrapped tokens or bridges. You send real BTC and receive real ETH, with liquidity providers and node operators earning fees from every transaction.
DeFiLlama enters the picture THORChain began collaborating with DeFiLlama back in April 2026, working on data integration and dashboard improvements. That collaboration culminated in DeFiLlama launching its own THORChain Ecosystem Dashboard in August 2026, covering key financial metrics and analytics.
Part of the joint effort has also been directed toward building an institutional investment dashboard, giving compliance teams access to clean data and verifiable metrics.
Context: why transparency matters now Earlier in 2026, the protocol suspended trading after a security exploit forced the team to pause operations. The $950K in July fees and $797M in trading volume suggest the rebuilding is working, with liquidity providers returning and fee distribution flowing to node operators and liquidity providers.
What this means for the broader DEX landscape Unlike Uniswap or Curve, which operate within single ecosystems, THORChain facilitates swaps across entirely separate blockchains, enabling users to move between Bitcoin and Ethereum without relying on centralized exchanges or wrapped assets. Landing at 12th among DEXs by fees in its first month back demonstrates that demand for native cross-chain swaps persisted despite the trading pause.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Rujira je globálně pozastavena, zatímco tým THORChain zkoumá obavy z non-determinismu. Spor se vede o to, zda stačilo pozastavit jen rizikový kontrakt, nebo celý app layer.
THORChain x Rujira Podcast #230 ft. PragmaticMonkey, KentonC137 & patriotsounds | August 29, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRRujira's app layer was globally paused while THORChain's base-layer team investigates non-determinism concerns. Pragmatic Monkey argued that the known risky contract could have remained paused while other app-layer activity resumed, but Kenton stressed that the full technical picture was still emerging.The dispute was not only about uptime. A global pause leaves users unable to manage positions and removes the app layer from price dislocations that can generate revenue for Rujira and THORChain.Pragmatic Monkey said a prior restart produced more than $500,000 in volume and about $18,000 of revenue in a few blocks. Those are his internal figures from a prior event, not a forecast for the next restart.The episode's shared conclusion was straightforward: stability takes priority, but emergency decisions need a clearer communication and coordination process.Custom Concentrated Liquidity is live. Dynamic Concentrated Liquidity is being tested, while Sonar remains a possible future mobile product rather than a committed launch.IntroductionTwo days after THORChain's stability-first update, a separate problem came into view: Rujira's app layer was not merely slowing new work, it was globally paused.
Pragmatic Monkey joined Kenton and Denny to explain why Rujira contributors were frustrated. The immediate question was technical, but the bigger question was operational: when a decentralized network needs an emergency control, who communicates the scope, the rationale and the path back online?
1. The App Layer Is Paused While the Base Layer StabilizesPragmatic Monkey said the chain had encountered several non-determinism issues, the kind that can cause nodes to disagree about the state of the network. One app-layer yield contract was the observed trigger when it was enabled. The base layer had returned after the contract was paused, he said, but the wider app layer remained halted.
His position was not that stability should be sacrificed for activity. Rujira's team supports the broader decision to slow releases and focus on making the base layer robust. The disagreement was over scope. Pragmatic Monkey said the affected contract had already been isolated successfully, so a contract-level pause could let other app-layer positions and strategies operate while the investigation continued.
"We own this system together." (Pragmatic Monkey)Kenton did not present the case as settled. He said he did not have all the technical information and pointed to the possibility of further concerns that justified testing before a restart. That distinction matters. The episode records Rujira's argument for a narrower pause, not a confirmed finding that a global pause was unnecessary.
For users, however, the difference is tangible. A global halt can leave collateralized positions inaccessible while markets move. Current positions were described as standard CDPs rather than perps, which lowers but does not remove liquidation risk. The same control model would be much harder to defend once high-leverage products exist.
2. Decentralization Needs an Emergency ProcessThe episode became a live governance discussion. Pragmatic Monkey said Rujira had no warning that the full app layer would remain paused when the base layer restarted. Kenton agreed that communication needed to improve, while also resisting a judgment before the contributing developers had explained their reasoning.
"Real decentralization should not mean no coordination." (Pragmatic Monkey)The network's ability to halt a contract or the app layer is a strength in a genuine emergency. The problem is making that power predictable for users, builders and node operators. Rujira's proposed minimum is not centralized control. It is an agreed process: identify the risk, use the narrowest safe scope, tell affected teams and users what happened, and state the conditions for reopening.
Kenton framed the tension with an emergency-brake analogy. A brake belongs on the train, but it should be pulled for an emergency, not as an ordinary operating decision. The practical follow-up is to determine whether the available evidence required a global halt and to make the next decision easier to understand in real time.
"We have to find some chain of command or some procedure or something like that that we can all agree to." (Kenton)This is also a reminder of how THORChain governance works. Node operators can coordinate a different outcome when the necessary threshold is reached. That is decentralized control, but it does not eliminate the need for shared norms around safety-critical actions.
3. A Restart Can Be an Economic EventThe cost of the pause is not limited to unavailable positions. Rujira's architecture can capture price differences between its app-layer markets and THORChain's base-layer pools. When those markets restart out of sync, the resulting dislocations can create arbitrage opportunities that flow through the protocol instead of entirely to external traders.
Pragmatic Monkey showed a prior restart in which, he said, Rujira processed more than $500,000 of volume and generated roughly $18,000 in revenue in a few blocks. He said nearly all of that revenue came from arbitrage, despite total app-layer TVL remaining below $2 million at the time. Under Rujira's 50/50 revenue split, he estimated about $9,000 went to THORChain from that event.
"We made $18,000 of revenue in just a few blocks." (Pragmatic Monkey)Those figures describe a prior event with its own market conditions, not an estimate for a future restart. But they explain Rujira's urgency. A wide price gap can be an opportunity to internalize value for liquidity providers and the protocol. Keeping the app layer closed means that opportunity is instead left to whatever external arbitrage can access the base-layer markets.
The same argument has limits. A restart must not be rushed merely to capture revenue. The point is that an app-layer pause changes market access and economic outcomes, so its scope and duration deserve the same transparent treatment as its security rationale.
4. CCL Is Live. DCL and Sonar Remain Work in ProgressThe original plan for the show was a demonstration of Custom Concentrated Liquidity, or CCL. That product is live and lets users provide liquidity within a chosen range. A broader walkthrough is being rescheduled.
The next product, Dynamic Concentrated Liquidity, or DCL, is earlier. As covered in the Podcast #223 recap, DCL is designed to move beyond a fixed range. Pragmatic Monkey said the new strategy would use an oracle price and a user's average entry price, buying only when it lowers that average and selling above it at a target spread.
That does not make DCL live. The first contract version was only days into testing, and Pragmatic Monkey was still examining how it behaves in a sustained one-way market. A strategy that protects an average entry price can also go long periods without trading, which is good for capital preservation but less useful for steady market making and protocol volume.
"More stability, more robustness, and then we can move on to actually try to continue building the cool apps." (Pragmatic Monkey)The group also discussed Sonar, a future Rujira mobile product. It is not an active release. Rujira's immediate priority is improving its web and mobile-web experience, while a rebuilt mobile app remains a possibility when capacity permits.
What to WatchThe app-layer restart: what the base-layer and Maya teams conclude about broader non-determinism risk, and whether the app layer can return with the affected contract still paused.Emergency coordination: whether contributors establish a clearer process for scoped halts, communication and restart conditions.User-position safeguards: how the pause model evolves before higher-risk products such as perps are introduced.Restart economics: whether a future synchronized restart again creates internalized arbitrage revenue, and how that value is distributed.DCL testing: whether the strategy can balance average-entry protection with enough activity to be useful for market making.Sonar: whether mobile-web improvements lead to a formal plan for a Rujira mobile app.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
Monero ($XMR) v srpnu 2026 vzrostlo o více než 45 % a zaznamenalo nejsilnější měsíční výkonnost za více než čtyři roky. Růst podpořilo spuštění nativních swapů XMR na THORChain 3.20.
Monero ($XMR) has posted its strongest monthly performance in more than four years, gaining over 45% in August 2026 and rising roughly 10% in a single 24-hour window. The last time the privacy-focused cryptocurrency delivered a comparable monthly gain was April 2021.
THORChain 3.20 Brings Native XMR Swaps The rally coincides with a significant protocol upgrade from THORChain. The timing matters:
That is a notable shift for Monero holders in particular.
Derivatives Market Signals Strong Demand The price action has been accompanied by a sharp move in derivatives markets. during the move, a dynamic that can amplify upward price momentum as bearish bets are forcibly closed.
The THORChain upgrade offers a structural reason for renewed interest beyond short-term speculation. A decentralized, non-custodial alternative for XMR swaps could help sustain demand if that trend continues.
THORChain 3.20 přidává nativní směny Monero (XMR) a Zcash (ZEC) za Bitcoin (BTC), Ethereum (ETH) a stablecoiny bez wrapped verzí. Uživatelé tak mohou obchodovat přímo, bez centralizované burzy a bez předání úschovy.
George Town, Cayman Islands, 25th August 2026, ChainwireBy Chainwire
2 min read
Create an account to save your articles.
Add on Google
Add Decrypt as your preferred source to see more of our stories on Google.
George Town, Cayman Islands, August 25th, 2026, Chainwire
THORChain, a decentralized exchange, announced the launch of THORChain 3.20, an upgrade introducing native support for Monero (XMR) and Zcash (ZEC) swaps.
Until now, moving between privacy coins such as XMR or ZEC and the crypto market has required users to rely on centralized exchanges, custodial services, or additional intermediary steps. With THORChain 3.20, users can natively swap XMR and ZEC against assets including Bitcoin (BTC), Ethereum (ETH), and stablecoins directly through THORChain.
No wrapped versions of XMR or ZEC are required. Users do not need to create an account or hand custody of their assets to a centralized entity. This is a significantly more direct route between privacy-focused cryptocurrencies and the most widely used assets in crypto.
For Monero holders, access to the broader crypto market has become an increasingly important issue as XMR continues to be removed or restricted by centralized exchanges. THORChain’s integration provides an alternative based on native assets and self-custody rather than requiring users to deposit their coins with an exchange.
The release is one of THORChain’s most significant upgrades to date. In addition to Monero and Zcash integration, version 3.20 introduces several broader changes to the protocol, including Protocol-Owned Liquidity (POL) and the new Stable Reserve, alongside renewed support for Solana, Base, and BNB. The Stable Reserve introduces stablecoin-to-stablecoin swaps with no liquidity fees, and Protocol-Owned Liquidity gives THORChain additional mechanisms for deploying protocol capital across the network.
The move builds on THORChain’s core proposition of allowing users to exchange native cryptocurrencies across otherwise disconnected blockchain networks without handing control of their assets to an intermediary.
THORChain already enables native cross-chain swaps across assets including Bitcoin and Ethereum. The addition of privacy-focused networks expands that model into an area of the crypto market where decentralized access has been far more limited until today.
About THORChain
THORChain is a decentralized exchange that enables users to swap native digital assets across different blockchain networks without relying on wrapped assets or centralized custodians. It allows users to exchange assets including Bitcoin, Ethereum, and other supported cryptocurrencies while maintaining a self-custodial experience.
RUNE za posledních 24 hodin vyskočil o více než 26 % po spuštění upgradu THORChain v3.20, který umožňuje swap Monero a Zcash za BTC, ETH a stablecoiny. Býci zároveň testovali rezistenci na úrovni 0,65 USD.
THORChain [RUNE] surged by more than 26% in the past 24 hours, ranking first among all gainers in the top 200 cryptos by market cap.
The hype around a network upgrade alongside a broader, stronger crypto market drove the token’s price. As a result, RUNE’s daily trading volume matched the uptick in price, recording a 3x increase, but remained fairly low, in excess of $20 million.
Here is how the THORChain v3.20 upgrade fueled the sudden surge:
THORChain v3.20 upgrade goes live as short liquidations spike The network announced that the THORChain v3.20 upgrade went live on the 26th of August. This upgrade allows swapping Monero [XMR] and Zcash [ZEC] for Bitcoin [BTC], Ethereum [ETH], and stablecoins.
The upgrade has expanded THORChain’s addressable market as it brings privacy users to a direct connection to crypto. The upgrade comes three months after an attacker exploited THORChain for over $10 million across BTC, ETH, and BSC.
That could increase the chain’s swap volume, with Ethereum and Bitcoin consistently dominating as per data from DefiLlama. The chain averaged $7 million in daily BTC swaps and $10 million in daily ETH swaps.
Source: DeFiLlama Thus, it is safe to say the rally was driven by a surge in sentiment following the upgrade and increased user base.
The surge in daily buying volume triggered liquidation of perpetual short orders. As per CoinGlass data, RUNE short positions worth 10x those of longs were wiped out.
Source: CoinGlass With a stronger crypto market and altcoins gaining ground, RUNE could truly shift its market structure. Let’s find…
Can RUNE bulls flip $0.65 into support? The 200-day EMA shows that RUNE price action has turned bullish on a long-term daily scale. The altcoin was still bearish looking at the horizontal structural levels.
RUNE was still trading below the $0.65 zone, which was the last lower high of the bearish trend. The market structure has shifted from the EMA perspective, but it is yet to confirm by flipping the $0.65 resistance into support.
Bulls tested the $0.65 supply zone but met instant rejection. It is still unclear if they got the zeal to breach the resistance.
Source: RUNE/USDT on TradingView However, the CVD showed bulls were positioning with 1.78 million RUNE bought on Binance as of the time of press. Moreover, the Sentiment was at 80, indicating the crowd was convinced the altcoin rally may be sustainable.
Still, it is worth noting that the rally may be short-lived since it is sentiment-driven. Otherwise, if the market structure is shifting, then RUNE may be positioning for more gains.
Final Summary RUNE rallies by more than 26% in 24 hours after the THORChain v3.20 upgrade, leading all of the top 200 cryptos by market cap. RUNE bulls tested the $0.65 resistance level, which, if flipped into support, would shift the market structure to bullish.
THORChain po verzi v3.20 a chystaném hotfixu v3.20.1 na jeden až dva týdny pozastavil nová spuštění kvůli stabilitě. Zcash, $XMR, test rev-share ve SwapKitu i protokolově vlastněná likvidita jsou jen odloženy, ne zrušeny.
THORSday Community Podcast #229 ft. CBarraford, KentonC137 & patriotsounds | August 27, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DRTHORChain has put new launches on an initial one-to-two-week pause to prioritize stability after v3.20 and the pending v3.20.1 hotfix. Zcash, $XMR, protocol-owned liquidity deployment and the SwapKit rev-share test are all delayed, not cancelled.The team traced the immediate instability to app-layer calls through non-deterministic API endpoints. A temporary app-layer pause remains technically possible, but no decision to use it was made during the episode.ADR30 was at 38% approval when recorded. It would let node operators delegate selected administrative commands without handing over control of funds.THORChain is considering what an AI-native protocol interface should look like. An unpublicized MCP server already exists in GitLab, while a command-line wallet for agents is only a possible direction.Memoless registrations were paused after a spam attempt. The team is weighing pricing, rate limits and registration-design changes, while stressing that a user must still follow the correct inbound flow.1. Stability Comes Before the Next LaunchTHORChain had just shipped v3.20, but the episode opened with the harder follow-up: the network needed a v3.20.1 hotfix and a period of focused stability work before the roadmap could advance again.
Chad Barraford said the immediate issue came from the Rujira app layer sometimes querying API endpoints whose results could vary between requests. That variation can change gas consumption. In a consensus system, even a tiny difference in execution is unacceptable, so the team chose to pause new work while it fixed the current failure mode and watched the chain closely.
"We've had too much instability recently to just kind of keep on slogging forward." (Chad)The current patch was expected within roughly 24 hours, contingent on testing and node adoption. But the broader pause is not merely a hotfix window. The team wants at least one or two weeks to assess stability, then decide whether it can resume the roadmap or needs more time.
That means Zcash and Monero are waiting, alongside new feature rollouts, protocol-owned liquidity deployment and rev-share. The message is deliberately cautious: $XMR and Zcash are delayed, not abandoned. Churns should still resume during the stability period, but new chain launches are not the near-term priority.
The community also asked whether the app layer itself could be paused temporarily. Chad confirmed that it is technically possible, but said the team did not yet think it was necessary. The identified patch may be enough, though that judgment could change as more information arrives.
2. AI Strategy Is Still Taking ShapeBefore the technical updates, Denny highlighted a self-funded AI video from French Chad that had reached nearly 9,000 impressions. The anecdote led into a broader question: if agents increasingly initiate crypto activity, what should THORChain build for them?
Kenton said work on AI-engine optimization was beginning to show results in AI search. Chad took the longer view. He expects agents to account for a growing share of transactions, but he does not think the correct protocol strategy is obvious yet.
"The hard thing is figuring out what our strategy should be in that context." (Chad)Some ingredients already exist. Chad said a developer has been working on an open-source MCP server in THORChain's GitLab, though it had not been publicized. Agents can already broadcast a transaction with the necessary memo, so basic agent use does not require a new protocol feature.
The more ambitious possibility is an AI-friendly, command-line wallet with structured JSON output. Instead of asking an agent to operate a graphical wallet, it could hold assets, inspect transaction history and submit transactions through an interface designed for software. That idea is not a product commitment, and it may not be THORChain-specific. It is a direction the team is evaluating as the capabilities and economics of AI change.
Chad also clarified the role of Huginn. It is designed to operate independently, not as a chat assistant that a developer prompts directly. A GitLab issue can be assigned to Huginn, which then works through that task on its own schedule.
https://raynalytics.net/network-status/governance3. ADR30 Separates Operations From Fund ControlADR30 was at 38% approval during the show. The proposal would let a node operator delegate selected operational commands to another address without giving that address control of the node's funds or private keys.
That makes it a quality-of-life change rather than an economic redesign. An operator could split routine duties among people or systems while retaining the key material that matters for custody. The proposal was associated with Liquify, and Chad said he saw no material protocol-design risk beyond the normal need to implement and review the code correctly.
"The security, all that remains the same." (Chad)The vote was not presented as complete. Operators and bond providers still need time to review proposals, coordinate internally and vote. The conversation also returned to a possible future ADR that would require validators to participate in ADR votes, including an abstain option, so governance does not remain idle by default.
Other proposals remain in the queue, including free stablecoin swaps, per-asset minimum fee settings and Devel's limit-order idea. They can wait. The team was clear that stability outranks adding more work to the release path.
4. SwapKit Rev-Share Is Close, but Not ActiveThe planned rev-share arrangement with SwapKit is technically close on both sides. Chad said THORChain's work is ready for additional staging tests, while SwapKit's implementation was nearing completion. Under the proposed test, a portion of fees would go to a SwapKit-controlled bucket, where the partner could use it to compete for more external wallet flow.
"We'll start with 20%, we'll see how that goes." (Chad)That 20% figure is a starting point for a test, not a live setting. The team intends to judge the arrangement by the resulting data, then increase, decrease or stop it if the outcome does not justify the share.
Rev-share can be enabled through an operational Mimir vote, which ordinarily needs three agreeing nodes. But no activation should be read into that mechanism. The same stability pause affecting $XMR and Zcash also pushes the rev-share test back by at least one or two weeks.
The episode also touched on protocol-owned liquidity. v3.20 was meant to help direct system income into selected pools, but that work is now subject to the same pause. The team may later prioritize stablecoins, $XMR, Zcash or other pools, but no new allocation is expected while stability work takes precedence.
5. Memoless Swaps Are Paused While the Team Reworks DefensesThe memo registration feature used for memoless swaps was turned off after someone began repeatedly registering short memo identifiers in an attempt to capture an incorrectly sent inbound transaction. Each pool has roughly 100,000 possible identifiers, and the attacker tried to flood that space with registrations.
Chad's key distinction was important: the attempt can only succeed when someone sends funds to THORChain without including a memo and without registering the intended memo first. It is not a conventional compromise of a correctly formed THORChain Swap.
"The protocol gained money in this particular attack as of now." (Chad)The attacker pays to keep registrations active and, at the time of the episode, was operating at a loss. That does not make the design question irrelevant. The team is deciding whether to restart the feature as it is, make registrations more expensive as space fills, cap registrations per block, bind a registration more closely to the sending address, or include the expected amount in the registration. Each option creates different wallet and user-experience edge cases.
For now, the status is a pause and an active design discussion, not a finalized fix. The practical guidance remains the same: use an interface that constructs the transaction correctly, read its warnings and send a small test transaction before committing a meaningful amount. Self-custody gives users control, but it also makes transaction discipline non-optional.
What to Watchv3.20.1 and uptime: whether the hotfix is adopted cleanly and the team sees the stable operation it wants before reopening the roadmap.New-chain timing: when Zcash and $XMR return to the launch queue after the initial one-to-two-week stability review.ADR30: whether the delegation proposal clears its node vote and how quickly the remaining governance queue moves afterward.AI interfaces: whether the MCP server is publicized, and whether the agent-friendly command-line wallet concept becomes a concrete build.Memoless redesign: which registration defense the team chooses and when THORChain Swap can safely re-enable the flow.More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
THORChain čeká na schválení verze v3.19.0 od validátorů, aby mohl spustit postupný restart po exploitu za 10,7 milionu USD. Aktualizace přidává karanténu kompromitovaného vaultu a kontroly keyshare před obnovením podpisů.
THORChain has moved into the next phase of its recovery from the May 15 vault exploit.
Summary
Validators must approve v3.19.0 before THORChain begins its staged restart and fully restores network services. The upgrade adds compromised-vault quarantine and temporary keyshare checks before signing resumes across the network. ADR-028 applies the recovery plan without minting new RUNE or diluting existing token holders further. Validators are now reviewing version 3.19.0, which combines security patches with the ADR-028 loss-recovery plan.
The release also introduces a mechanism that can quarantine a compromised vault. THORChain said this would stop an affected vault from processing transactions while keeping its activity visible to the network.
Validators review THORChain v3.19.0 “The next major step in the recovery process is now underway,” THORChain said in its sixth incident update. Validators must vote to approve v3.19.0 before the network can begin the staged upgrade.
THORChain Incident Update #6
The next major step in the recovery process is now underway. Validators are being asked to review, approve, and prepare for the v3.19.0 upgrade, which contains the TSS security patches and ADR028 implementation designed to address the economic impact…
— THORChain (@THORChain) June 8, 2026 The release contains patches for the threshold signature system used to control THORChain vaults. It also implements ADR-028, the governance plan approved after the exploit. The protocol said the upgrade would move the network closer to restoring normal operations.
Version 3.19.0 includes a new Compromised Vault Mimir setting. Once enabled, the setting will isolate the drained vault from transaction processing without removing it from network monitoring.
Keyshare checks come before signing resumes THORChain plans to validate the ADR-028 data migration after validators complete the upgrade. Every node must then verify the integrity of its keyshares through a temporary protocol called keyverify.
Keyshares allow validators to sign vault transactions together without one operator holding the full private key. The added check aims to confirm that the remaining shares are intact before signing restarts.
After those checks, validators will unhalt signing and start a churn. Churning replaces the active validator set and transfers assets into newly generated vaults. The network will wait for that process to finish before restoring other services.
Secured and Trade assets will return first. Liquidity-provider actions will follow, while trading will resume at the end of the 11-step process. Each stage depends on the previous checks completing successfully.
ADR-028 covers losses without new RUNE As previously reported by crypto.news, THORChain validators approved ADR-028 in May. The plan uses protocol-owned liquidity to absorb losses before allocating any remaining shortfall across synthetic asset holders.
The framework does not mint or sell new RUNE. It also avoids direct dilution for existing holders. Future system income will help rebuild protocol-owned liquidity after the restart.
THORChain also activated a bounty window for the attacker and approved the full slashing of the linked node. The protocol said innocent nodes that shared the affected vault would remain protected.
Full restart still depends on validators The May 15 exploit drained about $10.7 million from one of THORChain’s five vaults. THORChain’s report said a newly added node exploited a weakness in the GG20 threshold signature implementation. Four other vaults remained unaffected.
Automatic solvency checks detected the imbalance and halted signing within minutes. Node operators later paused trading, chain observation and churning while developers investigated the attack.
Validator approval of v3.19.0 would begin the final technical sequence, but it would not restore every service at once. THORChain will reopen signing, asset functions, liquidity actions and trading in stages after completing the vault, migration, keyshare and churn checks.
THORChain po více než měsíci obnovil obchodování, swapy i likviditní operace po exploitu za 10,7 milionu USD. Síť mezitím dokončila bezpečnostní upgrady a migraci starých trezorů.
THORChain has resumed activity after over a month of security verifications and upgrades, following a $10.7 million exploit that prompted a trading halt on May 15.
In a Tuesday X post, THORChain said it restored its network, including trading, signing, swaps and liquidity provider actions.
On Sunday, the protocol said it had confirmed the safety of most of its vaults through the KeyVerify protocol and retired the remaining legacy vaults as part of a migration to a new set of vaults. THORChain called the upgrade the “most significant milestone” in its recovery process. It also said it completed verification of every node's keyshare on Friday.
THORChain is one of the crypto industry's largest cross-chain trading protocols, enabling swaps between networks such as Bitcoin and Ethereum. The protocol has drawn scrutiny from blockchain investigators because hackers have used it to move stolen funds between blockchains.
Source: THORChain
THORChain ships security upgrades and migrates old vaultsTHORChain attributed the exploit to a vulnerability in its GG20 threshold signature scheme, which is used to secure protocol vaults by distributing key control across multiple node operators. According to the protocol, the flaw allowed a malicious node operator to reconstruct a full private key through what it described as “progressive key material leakage,” enabling the theft of $10.7 million.
The protocol implemented an emergency patch on May 20 to protect the remaining vaults before releasing an upgrade on June 9, which included a fix for the exploited vulnerability. A follow-up upgrade was rolled out on June 11 with additional stability improvements and fixes to the KeyVerify protocol.
THORChain network overview, node upgrades. Source: THORChain Explorer
With the recovery process largely complete, THORChain has also outlined plans for new network integrations.
THORChain said it will launch native swaps and vaults for privacy-preserving cryptocurrency Zcash (ZEC) within the next two weeks, followed by Monero (XMR).
It also plans to launch support for the Bittensor (TAO) token in about six weeks after the network’s restart.
Magazine: 53 DeFi projects infiltrated, 50M NEO tokens could be ‘given back’: Asia Express
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
THORChain pozastavil obchodování a swapy po exploitu za více než 10 milionů USD napříč Bitcoinem, Ethereum, BSC a Base. RUNE během několika hodin spadl o 12 %.
THORChain, a decentralized cross-chain liquidity protocol, has paused trading after blockchain security researchers flagged an exploit worth over $10 million. The protocol has reportedly suffered an exploit across Bitcoin, Ethereum, BSC and Base. As a result, RUNE price crashed 12% in a few hours.
THORChain Hit By $10M Crypto Losses in Exploit On-chain investigator ZachXBT on May 15 flagged an exploit on THORChain, claiming losses exceeding $10 million. The funds are stolen across multiple major blockchains, including Bitcoin, Ethereum, BNB Smart Chain (BSC), and Base.
In response, THORChain has halted all trading and swaps via its emergency protocol to contain the damage. The exploit involved large unauthorized outflows from THORChain’s router contracts across the affected chains.
Many security researchers and analytics platforms such as PeckShieldAlert revealed the attacker’s wallets. Notably, the wallets hold 36.85 BTC, 3,443 ETH, and 96.6 BNB, along with other tokens like USDT, USDC, and WBTC, according to Arkham data.
THORChain Exploiter Wallet’s Crypto Assets. Source: Arkham The incident triggered THORChain’s built-in halt mechanism, where nodes pause operations upon detecting the exploit to protect liquidity providers (LPs). This is reportedly the second notable security event for THORChain this year, amplifying concerns about DeFi interoperability risks.
Recently, KelpDAO suffered a hack worth $290 million. The attacker drained rsETH through KelpDAO’s LayerZero-powered cross-chain bridge, risking contagion to other DeFi protocols such as Aave.
RUNE Price Crashes 12% amid Market Reaction RUNE price fell 12% in just a few hours, with the price currently trading at $0.520. The 24-hour low and high are $0.502 and $0.597, respectively. Furthermore, trading volume has increased by almost 140% over the last 24 hours as investors book profits amid a decline in prices.
In contrast, CoinGlass data showed massive buying in the derivatives market. At the time of writing, the total THORChain futures open interest jumped more than 6% to $24.80 million in just an hour. RUNE futures open interest spiked 19% in the past 4 hours, with an almost 17% and 19% jump on Binance and Bybit, respectively.
THORChain Futures Open Interest. Source: Coinglass If you’re looking for more cross-chain swap protocols, here are our reviews for the top 9 among the best cross-chain swap platforms in 2026.
IoTeX uvedl, že po útoku na ioTube je přes 86 % CIOTX zamčeno nebo zmrazeno a jen 0,4 % zůstává v ohrožení. Útočníci odcizili 410 milionů CIOTX a asi 4,4 milionu USD v aktivech.
PANews reported on February 23 that the IoTeX team tweeted that on February 21, they discovered an attack on the Ethereum side of their multi-chain bridge ioTube. The attackers stole 410 million CIOTX tokens and approximately $4.4 million in assets through four steps. Currently, over 86% of the CIOTX has been locked or frozen, 12.8% (52.4 million CIOTX) is being frozen in cooperation with Binance and other platforms, and only 0.4% (1.7 million CIOTX) remains at risk after being exchanged on DEXs. Regarding the bridge's reserve funds, the attackers exchanged the stolen reserve tokens (including USDC, USDT, WBTC, WETH, and other assets) for approximately 2,183 ETH . Of this, 1,572 ETH has been transferred to the Bitcoin network via THORChain.
The IoTeX team has taken emergency measures, including distributing patch fixes, freezing related addresses, and working with exchanges to freeze funds. The ioTube bridge service will be restored after an independent security audit, along with a compensation plan and security upgrades. The team is committed to ensuring the safety of community assets and will release a more detailed compensation plan and hold a community AMA within the next 48 hours.
Previously reported, IoTeX suffered a loss of approximately $2 million in assets and is expected to be operational within 48 hours . Upbit has added IoTeX (IOTX) to its transaction alert list .
WOO X přišel o zhruba 14 milionů USD při útoku připisovaném aktérovi napojenému na KLDR. Hacken uvádí, že většina prostředků už byla převedena do Bitcoinu.
On July 24, 2025, Taiwan-based trading platform WOO X became the latest victim in a bruising summer of crypto breaches when attackers made off with roughly $14 million in unauthorized withdrawals from nine user accounts, forcing the exchange to pause withdrawals while it investigated and promised to reimburse affected users.
New chain-analysis shared by Yehor Rudytsia, Head of Forensics and Incident Response at Hacken, paints the post-heist picture as far more organized than a one-off theft. According to Rudytsia, the exploit, which Hacken dates to July, resulted in total losses of about $14 million and was carried out by a DPRK-linked actor tracked in law-enforcement circles as “TraderTraitor.”
Hacken says it is actively monitoring the on-chain movements and is supporting recovery efforts by flagging malicious addresses to the wider security community. The laundering choreography, as mapped by Hacken, left half the stolen funds on EVM networks and the rest on Tron and Bitcoin.
In the last 24 hours, on-chain traces show that the bulk of the EVM-side proceeds, more than $7 million, were routed through THORChain and swapped into Bitcoin, a technique observers have increasingly flagged as a common laundering path after major exchange thefts earlier this year. Rudytsia noted that THORChain’s native cross-chain swap functionality has repeatedly been used to convert large sums of ETH and ERC-20 tokens into BTC, making it attractive to sophisticated operators moving stolen assets across ecosystems.
On-chain Evidence Hacken’s report also documents the handling of the Tron-denominated portion (about $2.5 million in TRX). Those funds, the team found, were converted into USDT, bridged to Ethereum via LayerZero infrastructure, and from there, some of the bridged USDT was again pushed to Bitcoin through THORChain.
On-chain evidence of a nine-figure USDT transfer arriving on Ethereum from a LayerZero executor appears in public transaction records from October 1, 2025, which match the pattern Hacken described.
Complicating the trail, part of the funds that surfaced on Ethereum were sent to a wallet previously tied to the BingX hot-wallet exploit in 2024, itself attributed by investigators to North Korean-linked groups, suggesting either reuse of laundering infrastructure or coordination across multiple thefts.
The address that received those transfers is publicly visible on Ethereum explorer records, and investigators say the link deepens the picture of an organized laundering chain connecting multiple high-profile incidents.
Taken together, the movements indicate that roughly $8–9 million from the WOO X breach was bridged on the same day from Ethereum to Bitcoin, almost entirely via THORChain, leaving an estimated 90% of the stolen value now sitting on Bitcoin addresses as perpetrators accelerate conversion into the oldest and most liquid on-chain asset.
Security teams monitoring the flows warn that once funds consolidate on Bitcoin, conventional tracing and intervention become harder and the risk of eventual cash-out increases. Rudytsia told Blockchain Reporter that Hacken is continuing to monitor the accounts and will push flagged addresses to exchanges and compliance partners in the hope of freezing or otherwise freezing flow paths where possible.
For now, the case is a fresh reminder that as cross-chain tooling gets more powerful, it also gives sophisticated attackers faster, lower-friction routes to turn stolen tokens into harder-to-trace assets, and that forensic work on multiple chains, together with cooperation from on- and off-ramp services, remains the only immediate line of defence in today’s time.
AUTHOR
Mushumir Butt is a seasoned crypto journalist with over three years of experience reporting on the world of blockchain and cryptocurrency. At Blockchain Reporter, he delivers insightful news, in‐depth project reviews, and precise price analysis and predictions. With a strong background in SEO and digital marketing, Mushumir excels at breaking down complex trends into clear, accessible content, ensuring readers stay ahead in the fast‐paced crypto space.
Aave po hlášení chyby dočasně pozastavil trh Aave V2 Ethereum a zmrazil některá aktiva na Avalanche. Na Aave V3 pak zmrazil konkrétní aktiva na Polygonu, Arbitru a Optimismu. Podle protokolu nejsou žádné prostředky v ohrožení.
Decentralized finance (DeFi) platform Aave has suspended operations in a number of markets after receiving a problem report on a certain function of the protocol.
DeFi Protocol Discovers Vulnerability; Is User Funds At Risk? On Saturday, November 4, decentralized lending protocol Aave announced – via a post on X (formerly Twitter) that it has paused the Aave V2 Ethereum market and suspended certain assets on Avalanche. In addition, the protocol has frozen specific assets on Aave V3 on Polygon, Arbitrum, and Optimism.
Today we received a report of an issue on a certain feature of the Aave Protocol. After validation by community developers, the guardian has taken the following temporary prevention measure (no funds are at risk):
— Aave (@aave) November 4, 2023
According to the protocol’s announcement, these actions serve as a temporary precautionary measure following a problem report on a specific feature.
Furthermore, Aave said in the post that the Aave V3 markets on Ethereum, Base, and Metis and the V2 markets on Polygon and Avalanche are unaffected. Meanwhile, no funds on any of the markets were at risk, according to DeFi lending protocol.
🚨🚨 🚨 On 11-04 17:38:35 UTC, Aave Guardian has taken necessary protection measurements to pause AaveV2 protocol (and all Aave pools are safe): https://t.co/3xJzfiejig
Given the protocol is “forked” by multiple third parties and the exact details are not disclosed yet, it is… pic.twitter.com/OkO1EZv6pW
— PeckShield Inc. (@peckshield) November 4, 2023
While Aave did not specify what the issue is or the feature that caused the problem, the protocol said it would release a detailed explanation once there is a full resolution. The statement read:
A governance proposal to restore the normal operation of the protocols will be submitted shortly. A detailed postmortem will be released once the issue is fully resolved.
Aave further clarified that users supplying or borrowing from a frozen assets pool can still withdraw and repay positions. However, these users can’t supply or borrow more funds from the frozen assets pool until the issue is resolved. The protocol added:
On paused assets, no action can be done until unpaused.
AAVE Price Remains Steady Despite Protocol Vulnerability There is no evidence to suggest that the problem has had any impact on the value of the protocol’s native token, AAVE. As of this writing, the token is valued at $90.15, reflecting a negligible 0.9% price dip in the past 24 hours.
Nevertheless, the token is outperforming on a bigger timeframe. Over the past week, AAVE’s price has swelled by more than 10%, touching the $100 mark – for the first time since February – at some point during the week.
Although the price of AAVE has been moving mostly sideways in the past few days, a resolution of the current issue might trigger renewed momentum for the token. Hence, there is a chance that the cryptocurrency might revisit $100 again, especially considering the optimistic climate of the crypto market.
AAVE price slows down upward momentum on the daily timeframe | Source: AAVEUSDT chart on TradingView Featured image from Binance Academy, chart from TradingView
THORSwap nabídla několik bounty odměn útočníkům, kteří napadli osobní peněženku, zřejmě patřící zakladateli THORChain John-Paul Thorbjornsenovi. ZachXBT uvedl, že z ní severokorejští hackeři ukradli 1,35 milionu USD.
PANews reported on September 12th that according to The Block, on-chain detective ZachXBT revealed that THORSwap has issued multiple bounty offers over the past few days to hackers who attacked a user's personal wallet. The victim may be THORChain founder John-Paul Thorbjornsen. An on-chain update on Friday indicated that returning THOR tokens would earn a reward, with no legal action taken within 72 hours. Contact information was also provided. PeckShield initially reported that the THORChain protocol had been attacked, resulting in losses of approximately $1.2 million, but later corrected the claim to be targeting user wallets. ZachXBT stated that the victim was likely John-Paul Thorbjornsen's wallet, from which North Korean hackers stole $1.35 million on Tuesday. Thorbjornsen admitted that the attack originated from a fake Zoom link sent from a friend's hacked Telegram account. He stated that his old MetaMask wallet, which had been emptied, was in another logged-out Chrome profile, with the key stored in iCloud Keychain, making it possible for the attacker to access it through a zero-day vulnerability. This reinforces his belief that threshold signature wallets are the only true defense.