Market Cap: $2.2043T 0.58%
Volume(24h): $56.8553B 3.76%
  • Market Cap: $2.2043T 0.58%
  • Volume(24h): $56.8553B 3.76%
  • Fear & Greed Index:
  • Market Cap: $2.2043T 0.58%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Cryptocurrency News Articles

THORSwap, THORChain, and Bounties: Navigating Crypto Security in the Wild West

Sep 12, 2025 at 08:15 pm

A deep dive into the recent THORSwap and THORChain incidents, exploring bounty programs and the broader implications for crypto security.

THORSwap, THORChain, and Bounties: Navigating Crypto Security in the Wild West

THORSwap, THORChain, and Bounties: Navigating Crypto Security in the Wild West

The world of decentralized finance (DeFi) moves fast, and recent events surrounding THORSwap, THORChain, and their bounty programs highlight both the promise and the perils of this exciting frontier. With a $1.2 million exploit linked to THORChain's founder, the spotlight is once again on security.

The $1.2 Million Incident: A Personal Wallet Breach

Recently, THORSwap issued a bounty offer following a $1.2 million exploit. Initial reports suggested a THORChain protocol vulnerability, but it was later clarified that the attack targeted a personal wallet belonging to THORChain co-founder John-Paul Thorbjornsen.

Blockchain security firm PeckShield flagged the incident, which sent ripples through the crypto community. According to on-chain messages, THORSwap offered a reward for the return of the stolen funds, promising no legal action if the assets were returned within 72 hours. The message was simple: “Bounty offer: Return $THOR for reward. Contact @thorswap.finance or THORSwap discord for OTC deal.”

Social Engineering and Security Lapses

The breach appears to have been the result of a sophisticated social engineering attack. Blockchain analyst ZachXBT suggested North Korean hackers were involved, alleging that $1.35 million was stolen from Thorbjornsen’s wallet via a Telegram scam involving a deepfake Zoom call.

Thorbjornsen admitted that the MetaMask wallet linked to the attack was unprotected and stored in a logged-out Chrome profile. This contained both staked assets and personal funds. He speculated that 0-day exploits may have been used to access his iCloud Keychain or Chrome profile.

THORSwap's Response and Clarification

THORSwap was quick to clarify that the THORChain protocol itself was not compromised. CEO Paper X stated that the incident was isolated to a user's personal wallet and did not affect the THORChain or THORSwap infrastructure.

The focus shifted to recovering the stolen assets, which included $1.03 million in Kyber Network tokens and $320,000 in THORSwap tokens. The bounty offer was a proactive attempt to recover the funds without further complications.

Recurring Security Concerns with THORChain

This isn't the first time THORChain has faced security challenges. THORChain has dealt with multiple exploits since 2021, including attacks that drained about $13 million in just a few weeks. There was also the network insolvency announcement earlier this year that revealed a $93 million shortfall and hundreds of millions in debts. These incidents raise questions about the robustness of the platform.

Cross-Chain Swaps and Inherent Risks

Cross-chain swaps, while innovative, introduce inherent security risks. These systems act as bridges between different blockchains, often becoming vulnerable points of attack. The Bybit exploit earlier this year saw roughly $1.2 billion in stolen Ethereum flow through ThorChain, highlighting how these platforms can be used to obfuscate illicit funds.

Broader Implications for Crypto Security

This incident serves as a stark reminder of the importance of robust personal wallet security. As the crypto landscape evolves, so do the tactics of malicious actors. Thorbjornsen’s advice to avoid storing sensitive keys on cloud services like iCloud or Google Drive is crucial.

The industry is continually experimenting with security enhancements like zero-knowledge proofs, multi-party computation wallets, and AI-driven monitoring. However, attackers often stay one step ahead. The consensus is that users need to use multi-device threshold signature wallets, such as Vultisig, to protect assets more securely.

Final Thoughts: DeFi's Ongoing Balancing Act

So, where does this leave us? DeFi is still a bit like the Wild West, full of potential but also fraught with risk. While million-dollar losses might seem modest compared to billion-dollar hacks, they send a clear message: proceed with caution. Keep those keys safe, stay vigilant, and remember that in the world of crypto, security is everyone's responsibility. Stay safe out there, folks!

Original source:coincentral

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Aug 13, 2026