The theft of a single Asgard vault puts THOChain in a passive position
In mid-May, a theft incident targeting a single Asgard vault caught THOChain unprepared. About $10.7 million in assets have disappeared, transactions have been suspended, and communities face difficult choices.
Today, the restart path is activated. At the governance level, proposal ADR028 was approved, developers deployed v3.19 migration code, and leadership guided the community towards controllable reopening. The question is whether these measures will be enough to allow RUNE to rebuild trust.
The following will sort out the decision content, loss bearers, changes at the agreement level, and how to evaluate this restart.
Background review
THORChain operates one of the few cross-chain automated market maker networks, routing native assets between L1s through vaults managed by a set of rotating verification nodes. This powerful function comes with the attack surface. In May 2026, an Asgard vault was breached, triggering an emergency procedure and suspending the entire network. The team sorted and handled problems while planning a restart plan.
The credibility of a THORChain restart depends on two things: how the losses are apportioned, and whether the reinforcement measures reduce the risk of duplication without damaging core functionality.
The team\'s \"Bug Report #1\" confirmed the amount of the loss and the immediate remediation path, and the governance ultimately agreed on ADR028-a phased restart plan funded by the Agreement\'s Own Liquidity (POL) rather than issuing additional tokens. The timeline points to resumption of transactions as early as mid-June, depending on final inspections and node coordination.
What happened: Asgard vault was stolen
A single vault was exposed, not a global collapse
ThorChain\'s preliminary incident report pointed out that on May 15, 2026, an Asgard vault was unauthorized theft, resulting in a loss of approximately US$10.7 million. The details were released in the form of \"Vulnerability Report #1\" on May 20. The team listed the v3.18.1 patch as an immediate containment measure and identified ADR-028 as a long-term recovery mechanism.
Preliminary containment and response posture
After the vault was stolen, the agreement immediately suspended the risk exposure function and coordinated code and process reviews among nodes. The goal is to isolate incidents, prevent them from spreading to other vaults, and develop a migration plan that is consistent with governance decisions. The team emphasized not to rush for success to avoid adding compound errors in the process of securely restoring the network.
ADR028 and the non-issuance restart plan
Use of POL rather than dilution tokens
On May 27, node operators approved ADR028, authorizing a phased restart plan that would use the agreement\'s own liquidity to cover losses and explicitly avoid casting or selling new RUNEs. The proposal also opens a hacker reward window to incentivize money back.
The promise of \"no additional issuance\" is of great significance to token holders. It eliminates the common response after a hack-replenishing capital by issuing additional supplies-and transfers costs to the agreement balance sheet, which could have a knock-on effect on liquidity depth and earnings.
How to unfold the restart step
According to the latest news from the team, the order is designed as follows: safety first, then functionality, and finally breadth:
-Lock the loss accounting method through ADR028 and implement it during the migration.
-Release and adopt a new version (v3.18.1 for instant containment;v3.19 for full restarts that include storage migration).
-Coordinate node upgrades and verify key repairs to ensure consistent treasury control.
-Resume trading cautiously, monitor pool and vault behavior, and adjust parameters if necessary.
-Re-open chain integration in phases, prioritizing projects that have been audited and queued.
-Maintain a bounty window for possible recovery of funds and offset the use of POL.
This prioritization attempts to avoid systemic risks while restoring the core user experience and mobile connectivity.
v3.19 Migration and Hardening Work
From Planning to Implementation
In the May 29 \"Restart Path\" update, THORChain identified v3.19 as a restart version, which includes storage migration that implements the ADR028 loss method. The blog post points out that developers addressed a gap of about $700,000 in the migration logic-\"Codehans filled the $700,000 gap\"-and moved forward.
Operational fixes and expected recovery times
As of June 11, nodes have adopted v3.19, and v3.19.1 has also been launched to complete verification key and Gaia fixes. Leadership said the deal could resume in the next week-Chad Barraford said he was \"leaning towards Tuesday or Wednesday\"-provided final verification passes. The same update lists Zcash as \"within a week or two\" and sets the Monero integration target for July 1 to 15.
This rhythm emphasizes a security-first reopening strategy, adding integration only after the vault and key processing are repaired and stable.
Restart timeline and concerns
Key dates and decisions
May 15, 2026: Asgard vault theft (approximately US$10.7 million)-event date cited from vulnerability report; single vault impact.
May 20, 2026: Release of Vulnerability Report #1-Confirmed Loss Amount; Overview of v3.18.1 Patch and ADR-028 Recovery Path.
May 27, 2026: ADR028 approved-phased restart; use of POL; avoid casting RUNE; open bounty window.
May 29, 2026: Restart Path (v3.19)-Migration Implementation ADR028;Codehans solves a US$700,000 logical gap.
June 11, 2026: Nodes adopt v3.19, v3.19.1 in progress-Verify Key/Gaia Repair; transactions are expected to resume in the middle of the week;Zcash is followed;Monero targets early to mid-July.
Signals of a return of trust
In the first few weeks after trading resumes, focus on several operational and market indicators rather than just price:
- Pool depth and rotation stability of major trading pairs compared to pre-suspension levels.
-Spread and slip points for cross-chain swaps during peak periods.
-Node participation and pledge health after upgrade is completed.
-Events or anomalies reported during treasury operations, especially during chain rotations.
-The rate at which third-party integrations (wallets, aggregators) re-enable THORChain routing.
What does it mean for RUNE who pays?
Loss allocation without additional issuance
ADR028 decided to use POL instead of casting or selling a new RUNE, avoiding the direct risk of dilution. Costs falling on the agreed balance sheet may reduce existing liquidity, which in turn affects pool depth. A shallower pool could increase the slip point and temporarily compress trading volume until market makers and liquidity providers re-enter.
Impact on LPs and node operators
Liquidity providers will weigh benefits against perceived security. If POL absorbs losses, LP may not face principal reductions directly related to the vulnerability, but a thinner agreement has its own foundation that could change reward dynamics. Node operators must complete upgrades, verify key distribution, and closely monitor vault behavior; the professionalism of this group is a leading indicator of network security.
RUNE\'s supply narrative
Not casting RUNE helps maintain the credibility of the token. But not issuing additional shares does not mean there is no impact: opportunity costs are borne by agreed capital that could have been used to promote growth or stimulate incentives. Over time, assuming trading volume recovers, the agreement can supplement POL with fees and prudent treasury management.
Market structure and liquidity recovery
After trading resumes, arbitrageurs are likely to test the boundaries between cross-chain and centralized exchanges. If treasury processing and settlement delays are improved under v3.19.x, the spread should be normalized. Note that conservative parameter settings-such as swap limits and current limits-initially limit throughput as a safety measure, and then relax as confidence increases.
Automatic response table
Automatic response table containing timestamps, Mimir keys, and block numbers shows chain-level pauses, which are triggered by the solvency checker-demonstrating how THORChain automatically suppresses events.
Operational Outlook: Integration and guardrails
Privacy chain is coming soon
Re-enables Zcash \"in a week or two\" and sets Monero targets July 1 to 15, demonstrating confidence in vault operations under the updated version. These integrations are complex-especially in terms of key management and cost estimation-so their secure activation is a milestone in restart maturity.
Process hardening beyond code
In addition to patches, expect more conservative operational practices: a stricter key verification process, phased chain releases, and closer monitoring of treasury transitions. Bounties and disclosure channels after incidents can shorten the feedback loop for vulnerabilities and encourage white-hat cooperation.
Risks and possible mistakes
-Residual vulnerabilities: There may be adjacent variants in the vulnerability vector that circumvent current mitigations.
-Liquidity shocks: Using POL to cover losses may weaken the agreement\'s inherent depth and increase slip points during reopening.
-Governance frictions: If parameters remain restrictive for a long time, LPs and traders may shift trading volume elsewhere.
-Integration risk: Re-enabling Zcash/Monero introduces a new attack surface in key processing and expense logic.
-Bounty Uncertainty: Hacker bounty results are unpredictable and may not effectively offset losses.
-Node Coordination: Any delay or configuration errors in the verification key step may disrupt vault control during the rotation.
-Reputational baggage: Even if the restart goes smoothly, some platforms or wallets may delay reactivation, thus curbing transaction volume.
No patch is everything; the next 30 to 60 days depend on disciplined operations, parameter adjustments and transparent incident reporting.
FAQs
What happened in the THORChain $10.7 million incident?
Around May 15, 2026, an Asgard vault was stolen without authorization. THORChain\'s vulnerability report #1, published on May 20, confirmed approximately $10.7 million in damage and outlined v3.18.1 as an immediate patch and ADR-028 as a recovery framework.
What is ADR028 and why is it important?
ADR028 is a phased restart roadmap for governance approval. It apportioned losses by agreeing to own liquidity rather than forging or selling a new RUNE, and opened a bounty window to encourage money back. ADR028 was approved by the node on May 27, 2026.
Will ThorChain cast a new RUNE to cover the loss?
No. ADR028 clearly avoids casting or selling new RUNEs. Losses are covered by the agreement\'s own liquidity, which protects holders from direct dilution but may temporarily reduce pool depth.
When will transactions resume?
As of June 11, 2026, nodes have adopted v3.19 and v3.19.1 is being distributed for verification key and Gaia repairs. Leadership said it expected transactions to resume within the next week, depending on final inspections. If safety testing is needed, the timeline may be delayed.
How will liquidity providers be affected?
By using POL to allocate losses, LP avoided principal reductions under ADR028 that were directly related to the vulnerability. However, the inherent depth of thinner agreements could affect slippage and earnings until liquidity is rebuilt and trading volumes return to normal.
What is the integration status of Zcash and Monero?
The June 11 update places Zcash in \"within a week or two\" after the transaction resumes and sets the Monero target for July 1 to 15, provided that vault operations and key management under v3.19.x are successful.
What should users and traders pay attention to after restarting?
Focus on pool depth, swap slip points, node engagement, and any reported vault anomalies. Early reopening may contain conservative constraints; as stability is demonstrated, these constraints can be relaxed.
Disclaimer : This article is for information reference only. Does not constitute and should not be used as legal, tax, investment, financial or other advice.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
RUNE