Thorchain has been hacked six times in five years, and not once the same way. Each one through a different layer of the architecture.
2021 - Smart contract bug in the ETH Router. Attackers tricked Bifrost into reading manipulated msg.value events. ~$15.5M across three exploits.
2022 - Validator software bug. Non-deterministic behavior across nodes triggered a 20-hour outage.
2023 - TSS keygen vulnerability. Devs admitted a malicious validator could have drained vaults during a prior key generation. Network halted preemptively.
2025 (Jan) - Economic design failure. THORFi's lending model required RUNE to keep outperforming BTC/ETH. It didn't. $200M trapped.
2025 (Sep) - Social engineering. DPRK ran a Telegram deepfake on co-founder JP, extracted his MetaMask keys from iCloud Keychain. $1.35M lost.
2026 - TSS cryptography flaw. A malicious validator exploited the GG20 implementation, leaked key material across signing sessions, reconstructed the vault key. $10.7M drained.
Plus: ~$605M of Bybit/Lazarus stolen funds laundered through in 2025. Validators voted to block, reversed under "code is law" pressure.
Six distinct vectors: smart contract code, validator software, TSS keygen, economic design, social engineering, TSS cryptography. ~$227M directly lost or trapped. The architecture keeps finding new ways to fail.