Live financial news intelligence

Track market-moving stories before they get noisy

Real-time pulse of financial headlines curated from 5 premium feeds.

Latest market signal Czech Filtered by asset RUNE
Coverage 92,268 Raw stories ingested 7,951 rewritten in CS_CZ • 0 to rewrite (last 2 days).
Agents 7 waiting Pipeline agents
  • FMP Stock News Fetch every minute 37s ago
  • FMP Forex News Fetch every 5 min 2m ago
  • CoinGecko News Fetch every 5 min 2m ago
  • FIO Stock News Fetch every 10 min 6m ago
  • Patria Stock News Fetch every 10 min 6m ago
  • Editorial rewrite Rewrite every minute 37s ago
  • Asset sync Assets every 1 hour 26m ago

Latest coverage

Market News Feed

Scan headlines quickly, then expand any story for source context.

View
Language
Relevance
Clear
Details Date Content Source Relevance
2026-06-25 08:00 1mo ago
2026-06-09 07:25 1mo ago
THORChain čeká na schválení restartu od validátorů po exploitu
RUNE THORchain
CoinGecko News 92
Original source text
THORChain has moved into the next phase of its recovery from the May 15 vault exploit. 

Summary

Validators must approve v3.19.0 before THORChain begins its staged restart and fully restores network services. The upgrade adds compromised-vault quarantine and temporary keyshare checks before signing resumes across the network. ADR-028 applies the recovery plan without minting new RUNE or diluting existing token holders further. Validators are now reviewing version 3.19.0, which combines security patches with the ADR-028 loss-recovery plan.

The release also introduces a mechanism that can quarantine a compromised vault. THORChain said this would stop an affected vault from processing transactions while keeping its activity visible to the network.

Validators review THORChain v3.19.0 “The next major step in the recovery process is now underway,” THORChain said in its sixth incident update. Validators must vote to approve v3.19.0 before the network can begin the staged upgrade.

THORChain Incident Update #6

The next major step in the recovery process is now underway. Validators are being asked to review, approve, and prepare for the v3.19.0 upgrade, which contains the TSS security patches and ADR028 implementation designed to address the economic impact…

— THORChain (@THORChain) June 8, 2026 The release contains patches for the threshold signature system used to control THORChain vaults. It also implements ADR-028, the governance plan approved after the exploit. The protocol said the upgrade would move the network closer to restoring normal operations.

Version 3.19.0 includes a new Compromised Vault Mimir setting. Once enabled, the setting will isolate the drained vault from transaction processing without removing it from network monitoring.

Keyshare checks come before signing resumes THORChain plans to validate the ADR-028 data migration after validators complete the upgrade. Every node must then verify the integrity of its keyshares through a temporary protocol called keyverify.

Keyshares allow validators to sign vault transactions together without one operator holding the full private key. The added check aims to confirm that the remaining shares are intact before signing restarts.

After those checks, validators will unhalt signing and start a churn. Churning replaces the active validator set and transfers assets into newly generated vaults. The network will wait for that process to finish before restoring other services.

Secured and Trade assets will return first. Liquidity-provider actions will follow, while trading will resume at the end of the 11-step process. Each stage depends on the previous checks completing successfully.

ADR-028 covers losses without new RUNE As previously reported by crypto.news, THORChain validators approved ADR-028 in May. The plan uses protocol-owned liquidity to absorb losses before allocating any remaining shortfall across synthetic asset holders.

The framework does not mint or sell new RUNE. It also avoids direct dilution for existing holders. Future system income will help rebuild protocol-owned liquidity after the restart.

THORChain also activated a bounty window for the attacker and approved the full slashing of the linked node. The protocol said innocent nodes that shared the affected vault would remain protected.

Full restart still depends on validators The May 15 exploit drained about $10.7 million from one of THORChain’s five vaults. THORChain’s report said a newly added node exploited a weakness in the GG20 threshold signature implementation. Four other vaults remained unaffected.

Automatic solvency checks detected the imbalance and halted signing within minutes. Node operators later paused trading, chain observation and churning while developers investigated the attack.

Validator approval of v3.19.0 would begin the final technical sequence, but it would not restore every service at once. THORChain will reopen signing, asset functions, liquidity actions and trading in stages after completing the vault, migration, keyshare and churn checks.
2026-06-25 08:00 1mo ago
2026-06-23 10:00 1mo ago
THORChain obnovil obchodování po exploitu za 10,7 milionu USD
RUNE THORchain
CoinGecko News 92
Original source text
THORChain has resumed activity after over a month of security verifications and upgrades, following a $10.7 million exploit that prompted a trading halt on May 15.

In a Tuesday X post, THORChain said it restored its network, including trading, signing, swaps and liquidity provider actions.

On Sunday, the protocol said it had confirmed the safety of most of its vaults through the KeyVerify protocol and retired the remaining legacy vaults as part of a migration to a new set of vaults. THORChain called the upgrade the “most significant milestone” in its recovery process. It also said it completed verification of every node's keyshare on Friday.

THORChain is one of the crypto industry's largest cross-chain trading protocols, enabling swaps between networks such as Bitcoin and Ethereum. The protocol has drawn scrutiny from blockchain investigators because hackers have used it to move stolen funds between blockchains.

Source: THORChain

THORChain ships security upgrades and migrates old vaultsTHORChain attributed the exploit to a vulnerability in its GG20 threshold signature scheme, which is used to secure protocol vaults by distributing key control across multiple node operators. According to the protocol, the flaw allowed a malicious node operator to reconstruct a full private key through what it described as “progressive key material leakage,” enabling the theft of $10.7 million.

The protocol implemented an emergency patch on May 20 to protect the remaining vaults before releasing an upgrade on June 9, which included a fix for the exploited vulnerability. A follow-up upgrade was rolled out on June 11 with additional stability improvements and fixes to the KeyVerify protocol.

THORChain network overview, node upgrades. Source: THORChain Explorer

With the recovery process largely complete, THORChain has also outlined plans for new network integrations.

THORChain said it will launch native swaps and vaults for privacy-preserving cryptocurrency Zcash (ZEC) within the next two weeks, followed by Monero (XMR).

It also plans to launch support for the Bittensor (TAO) token in about six weeks after the network’s restart.

Magazine: 53 DeFi projects infiltrated, 50M NEO tokens could be ‘given back’: Asia Express  

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
2026-06-25 07:40 1mo ago
2026-05-15 11:43 2mo ago
THORChain po exploitu pozastavil obchodování, RUNE klesl o 12 %
BBTC Binance Wrapped Bitcoin BTC Bitcoin ETH Ethereum RUNE THORchain
CoinGecko News 92
Original source text
THORChain, a decentralized cross-chain liquidity protocol, has paused trading after blockchain security researchers flagged an exploit worth over $10 million. The protocol has reportedly suffered an exploit across Bitcoin, Ethereum, BSC and Base. As a result, RUNE price crashed 12% in a few hours.

THORChain Hit By $10M Crypto Losses in Exploit On-chain investigator ZachXBT on May 15 flagged an exploit on THORChain, claiming losses exceeding $10 million. The funds are stolen across multiple major blockchains, including Bitcoin, Ethereum, BNB Smart Chain (BSC), and Base.

In response, THORChain has halted all trading and swaps via its emergency protocol to contain the damage. The exploit involved large unauthorized outflows from THORChain’s router contracts across the affected chains.

Many security researchers and analytics platforms such as PeckShieldAlert revealed the attacker’s wallets. Notably, the wallets hold 36.85 BTC, 3,443 ETH, and 96.6 BNB, along with other tokens like USDT, USDC, and WBTC, according to Arkham data.

THORChain Exploiter Wallet’s Crypto Assets. Source: Arkham The incident triggered THORChain’s built-in halt mechanism, where nodes pause operations upon detecting the exploit to protect liquidity providers (LPs). This is reportedly the second notable security event for THORChain this year, amplifying concerns about DeFi interoperability risks.

Recently, KelpDAO suffered a hack worth $290 million. The attacker drained rsETH through KelpDAO’s LayerZero-powered cross-chain bridge, risking contagion to other DeFi protocols such as Aave.

RUNE Price Crashes 12% amid Market Reaction RUNE price fell 12% in just a few hours, with the price currently trading at $0.520. The 24-hour low and high are $0.502 and $0.597, respectively. Furthermore, trading volume has increased by almost 140% over the last 24 hours as investors book profits amid a decline in prices.

In contrast, CoinGlass data showed massive buying in the derivatives market. At the time of writing, the total THORChain futures open interest jumped more than 6% to $24.80 million in just an hour. RUNE futures open interest spiked 19% in the past 4 hours, with an almost 17% and 19% jump on Binance and Bybit, respectively.

THORChain Futures Open Interest. Source: Coinglass If you’re looking for more cross-chain swap protocols, here are our reviews for the top 9 among the best cross-chain swap platforms in 2026.
2026-06-25 07:31 1mo ago
2026-02-23 07:20 5mo ago
IoTeX: 86 % CIOTX je po útoku na ioTube zamčeno
BTC Bitcoin ETH Ethereum IOTX IoTeX RUNE THORchain USDC USD Coin WETH WETH
CoinGecko News 92
Original source text
PANews reported on February 23 that the IoTeX team tweeted that on February 21, they discovered an attack on the Ethereum side of their multi-chain bridge ioTube. The attackers stole 410 million CIOTX tokens and approximately $4.4 million in assets through four steps. Currently, over 86% of the CIOTX has been locked or frozen, 12.8% (52.4 million CIOTX) is being frozen in cooperation with Binance and other platforms, and only 0.4% (1.7 million CIOTX) remains at risk after being exchanged on DEXs. Regarding the bridge's reserve funds, the attackers exchanged the stolen reserve tokens (including USDC, USDT, WBTC, WETH, and other assets) for approximately 2,183 ETH . Of this, 1,572 ETH has been transferred to the Bitcoin network via THORChain.

The IoTeX team has taken emergency measures, including distributing patch fixes, freezing related addresses, and working with exchanges to freeze funds. The ioTube bridge service will be restored after an independent security audit, along with a compensation plan and security upgrades. The team is committed to ensuring the safety of community assets and will release a more detailed compensation plan and hold a community AMA within the next 48 hours.

Previously reported, IoTeX suffered a loss of approximately $2 million in assets and is expected to be operational within 48 hours . Upbit has added IoTeX (IOTX) to its transaction alert list .
2026-06-25 07:14 1mo ago
2025-10-01 22:22 9mo ago
WOO X přišel o 14 milionů USD při útoku napojeném na KLDR
BTC Bitcoin ETH Ethereum HAI Hacken RUNE THORchain WOO Woo Network
CoinGecko News 78
Original source text
Table of contents

On July 24, 2025, Taiwan-based trading platform WOO X became the latest victim in a bruising summer of crypto breaches when attackers made off with roughly $14 million in unauthorized withdrawals from nine user accounts, forcing the exchange to pause withdrawals while it investigated and promised to reimburse affected users.

New chain-analysis shared by Yehor Rudytsia, Head of Forensics and Incident Response at Hacken, paints the post-heist picture as far more organized than a one-off theft. According to Rudytsia, the exploit, which Hacken dates to July, resulted in total losses of about $14 million and was carried out by a DPRK-linked actor tracked in law-enforcement circles as “TraderTraitor.”

Hacken says it is actively monitoring the on-chain movements and is supporting recovery efforts by flagging malicious addresses to the wider security community. The laundering choreography, as mapped by Hacken, left half the stolen funds on EVM networks and the rest on Tron and Bitcoin.

In the last 24 hours, on-chain traces show that the bulk of the EVM-side proceeds, more than $7 million, were routed through THORChain and swapped into Bitcoin, a technique observers have increasingly flagged as a common laundering path after major exchange thefts earlier this year. Rudytsia noted that THORChain’s native cross-chain swap functionality has repeatedly been used to convert large sums of ETH and ERC-20 tokens into BTC, making it attractive to sophisticated operators moving stolen assets across ecosystems.

On-chain Evidence Hacken’s report also documents the handling of the Tron-denominated portion (about $2.5 million in TRX). Those funds, the team found, were converted into USDT, bridged to Ethereum via LayerZero infrastructure, and from there, some of the bridged USDT was again pushed to Bitcoin through THORChain.

On-chain evidence of a nine-figure USDT transfer arriving on Ethereum from a LayerZero executor appears in public transaction records from October 1, 2025, which match the pattern Hacken described.

Complicating the trail, part of the funds that surfaced on Ethereum were sent to a wallet previously tied to the BingX hot-wallet exploit in 2024, itself attributed by investigators to North Korean-linked groups, suggesting either reuse of laundering infrastructure or coordination across multiple thefts.

The address that received those transfers is publicly visible on Ethereum explorer records, and investigators say the link deepens the picture of an organized laundering chain connecting multiple high-profile incidents.

Taken together, the movements indicate that roughly $8–9 million from the WOO X breach was bridged on the same day from Ethereum to Bitcoin, almost entirely via THORChain, leaving an estimated 90% of the stolen value now sitting on Bitcoin addresses as perpetrators accelerate conversion into the oldest and most liquid on-chain asset.

Security teams monitoring the flows warn that once funds consolidate on Bitcoin, conventional tracing and intervention become harder and the risk of eventual cash-out increases. Rudytsia told Blockchain Reporter that Hacken is continuing to monitor the accounts and will push flagged addresses to exchanges and compliance partners in the hope of freezing or otherwise freezing flow paths where possible.

For now, the case is a fresh reminder that as cross-chain tooling gets more powerful, it also gives sophisticated attackers faster, lower-friction routes to turn stolen tokens into harder-to-trace assets, and that forensic work on multiple chains, together with cooperation from on- and off-ramp services, remains the only immediate line of defence in today’s time.

AUTHOR

Mushumir Butt is a seasoned crypto journalist with over three years of experience reporting on the world of blockchain and cryptocurrency. At Blockchain Reporter, he delivers insightful news, in‐depth project reviews, and precise price analysis and predictions. With a strong background in SEO and digital marketing, Mushumir excels at breaking down complex trends into clear, accessible content, ensuring readers stay ahead in the fast‐paced crypto space.
2026-06-24 23:08 1mo ago
2023-11-05 09:39 2yr ago
Aave dočasně pozastavil trh po hlášení chyby
AAVE Aave ADA Cardano AVAX Avalanche ETH Ethereum LEND Aave [OLD] RUNE THORchain
CoinGecko News 86
Original source text
Decentralized finance (DeFi) platform Aave has suspended operations in a number of markets after receiving a problem report on a certain function of the protocol.

DeFi Protocol Discovers Vulnerability; Is User Funds At Risk? On Saturday, November 4, decentralized lending protocol Aave announced – via a post on X (formerly Twitter) that it has paused the Aave V2 Ethereum market and suspended certain assets on Avalanche. In addition, the protocol has frozen specific assets on Aave V3 on Polygon, Arbitrum, and Optimism. 

Today we received a report of an issue on a certain feature of the Aave Protocol. After validation by community developers, the guardian has taken the following temporary prevention measure (no funds are at risk):

— Aave (@aave) November 4, 2023

According to the protocol’s announcement, these actions serve as a temporary precautionary measure following a problem report on a specific feature. 

Furthermore, Aave said in the post that the Aave V3 markets on Ethereum, Base, and Metis and the V2 markets on Polygon and Avalanche are unaffected. Meanwhile, no funds on any of the markets were at risk, according to DeFi lending protocol.

🚨🚨 🚨 On 11-04 17:38:35 UTC, Aave Guardian has taken necessary protection measurements to pause AaveV2 protocol (and all Aave pools are safe): https://t.co/3xJzfiejig

Given the protocol is “forked” by multiple third parties and the exact details are not disclosed yet, it is… pic.twitter.com/OkO1EZv6pW

— PeckShield Inc. (@peckshield) November 4, 2023

While Aave did not specify what the issue is or the feature that caused the problem, the protocol said it would release a detailed explanation once there is a full resolution. The statement read:

A governance proposal to restore the normal operation of the protocols will be submitted shortly. A detailed postmortem will be released once the issue is fully resolved.

Aave further clarified that users supplying or borrowing from a frozen assets pool can still withdraw and repay positions. However, these users can’t supply or borrow more funds from the frozen assets pool until the issue is resolved. The protocol added: 

On paused assets, no action can be done until unpaused.

AAVE Price Remains Steady Despite Protocol Vulnerability There is no evidence to suggest that the problem has had any impact on the value of the protocol’s native token, AAVE. As of this writing, the token is valued at $90.15, reflecting a negligible 0.9% price dip in the past 24 hours.

Nevertheless, the token is outperforming on a bigger timeframe. Over the past week, AAVE’s price has swelled by more than 10%, touching the $100 mark – for the first time since February – at some point during the week.

Although the price of AAVE  has been moving mostly sideways in the past few days, a resolution of the current issue might trigger renewed momentum for the token. Hence, there is a chance that the cryptocurrency might revisit $100 again, especially considering the optimistic climate of the crypto market.

AAVE price slows down upward momentum on the daily timeframe | Source: AAVEUSDT chart on TradingView Featured image from Binance Academy, chart from TradingView
2026-06-24 22:29 1mo ago
2025-09-12 10:39 10mo ago
THORSwap nabízí odměny po krádeži z peněženky zakladatele
RUNE THORchain THOR THORSwap
CoinGecko News 78
Original source text
PANews reported on September 12th that according to The Block, on-chain detective ZachXBT revealed that THORSwap has issued multiple bounty offers over the past few days to hackers who attacked a user's personal wallet. The victim may be THORChain founder John-Paul Thorbjornsen. An on-chain update on Friday indicated that returning THOR tokens would earn a reward, with no legal action taken within 72 hours. Contact information was also provided. PeckShield initially reported that the THORChain protocol had been attacked, resulting in losses of approximately $1.2 million, but later corrected the claim to be targeting user wallets. ZachXBT stated that the victim was likely John-Paul Thorbjornsen's wallet, from which North Korean hackers stole $1.35 million on Tuesday. Thorbjornsen admitted that the attack originated from a fake Zoom link sent from a friend's hacked Telegram account. He stated that his old MetaMask wallet, which had been emptied, was in another logged-out Chrome profile, with the key stored in iCloud Keychain, making it possible for the attacker to access it through a zero-day vulnerability. This reinforces his belief that threshold signature wallets are the only true defense.