todayonchain.com

THORChain's $10M Exploit Caused by MPC Vulnerability, Private Key Leak

Cointelegraph
THORChain suffered a $10.7 million exploit due to a GG20 threshold signature vulnerability that allowed a malicious node operator to reconstruct a private key.

Summary

THORChain recently confirmed that a malicious node operator exploited a vulnerability in the GG20 threshold signature scheme, leading to the theft of approximately $10.7 million. The flaw allowed the attacker to reconstruct a full private key through progressive key material leakage. The protocol's automated solvency checks successfully halted further trading and prevented additional losses, with the community now debating a recovery proposal (ADR-028) that avoids selling RUNE tokens while focusing on protocol-owned liquidity.

(Source:Cointelegraph)