Loading market data...

THORChain TSS Exploit Drains $10M, Raises Questions About Threshold Signature Security

THORChain TSS Exploit Drains $10M, Raises Questions About Threshold Signature Security

How the attack worked

->

Cómo funcionó el ataque

Then:

The attacker didn't break the cryptography in one shot. Instead, they abused the protocol's round structure — repeatedly failing signing rounds to extract partial key information. Over 864 attempts, the cumulative leakage gave them enough to reconstruct the full key. The exploit took about 60 hours, suggesting a patient, methodical approach rather than a brute-force smash-and-grab. THORChain's post-mortem didn't specify whether the vulnerability has been fully patched, but the exchange has since paused and resumed operations.

Translation:

El atacante no rompió la criptografía de una sola vez. En cambio, abusó de la estructura de rondas del protocolo, fallando repetidamente las rondas de firma para extraer información parcial de la clave. Después de 864 intentos, la filtración acumulada les dio suficiente para reconstruir la clave completa. El exploit tomó alrededor de 60 horas, lo que sugiere un enfoque paciente y metódico en lugar de un ataque de fuerza bruta. El informe post-mortem de THORChain no especificó si la vulnerabilidad ha sido completamente parcheada, pero el exchange desde entonces ha pausado y reanudado sus operaciones.

Next:

TSS vs. multisig trade-offs

->

Compensaciones entre TSS y multisig

Then:

The THORChain incident highlights a known weakness in TSS: protocol-level round abuse and denial-of-service risks. Multisig, by contrast, is provable on-chain — every signature is visible, and quorum enforcement happens in the script. But multisig comes with its own costs. A 2-of-3 P2SH setup eats about 296 vBytes per input; a 3-of-5 P2WSH runs ~350 vB. With Taproot and Schnorr, schemes like FROST or MuSig2 can shrink that to ~57.5 vB, cutting fees roughly 80% in higher-threshold setups. That's a big deal for high-throughput chains. But the trade-off is that TSS looks like a single signature on-chain, making it harder for auditors to verify policy without strong off-chain logs and attestations.

Translation:

El incidente de THORChain resalta una debilidad conocida en TSS: el abuso de rondas a nivel de protocolo y los riesgos de denegación de servicio. La multisig, por el contrario, es demostrable en cadena: cada firma es visible y el cumplimiento del quórum ocurre en el script. Pero la multisig tiene sus propios costos. Una configuración 2-de-3 P2SH consume alrededor de 296 vBytes por entrada; una 3-de-5 P2WSH usa ~350 vB. Con Taproot y Schnorr, esquemas como FROST o MuSig2 pueden reducirlo a ~57.5 vB, recortando las tarifas aproximadamente un 80% en configuraciones de umbral más alto. Eso es un gran problema para cadenas de alto rendimiento. Pero la compensación es que TSS parece una única firma en cadena, lo que dificulta que los auditores verifiquen la política sin registros y atestaciones fuera de la cadena sólidos.

Note: "vBytes" might be left as "vBytes" or "vB" but we can keep as is. "P2SH" etc. We'll keep. Next:

Wallet compromise was the costliest vector in the first half of 2026, according to CertiK's H1 review. The firm counted $1.3 billion lost across 344 incidents, with wallet-related attacks accounting for $444.5 million across just 33 cases. That's about a third of all losses from less than 10% of incidents. The THORChain exploit fits that pattern — a wallet-level vulnerability, not a smart contract bug or a bridge hack. For teams choosing between TSS and multisig, the decision often comes down to fee sensitivity versus auditability. TSS suits low-fee, high-throughput flows where the wallet acts as an externally owned account (EOA). Multisig suits conservative ops where on-chain policy visibility and simple recovery matter more than saving a few dollars per transaction.

Translation:

El compromiso de billeteras fue el vector más costoso en la primera mitad de 2026, según el informe H1 de CertiK. La firma contó $1.3 mil millones perdidos en 344 incidentes, con ataques relacionados con billeteras representando $444.5 millones en solo 33 casos. Eso es aproximadamente un tercio de todas las pérdidas en menos del 10% de los incidentes. El exploit de THORChain encaja en ese patrón: una vulnerabilidad a nivel de billetera, no un error de contrato inteligente ni un hackeo de puente. Para los equipos que eligen entre TSS y multisig, la decisión a menudo se reduce a la sensibilidad a las tarifas frente a la auditabilidad. TSS es adecuado para flujos de bajo costo y alto rendimiento donde la billetera actúa como una cuenta de propiedad externa (EOA). La multisig es adecuada para operaciones conservadoras donde la visibilidad de la política en cadena y la recuperación simple importan más que ahorrar unos pocos dólares por transacción.

Note: "externally owned account" -> "cuenta de propiedad externa" but often "cuenta externa" or "EOA" is used. We'll keep EOA in parentheses. Next:

On Ethereum, TSS can appear as a single EOA, avoiding contract execution overhead — but that also means giving up contract-level guardrails and visibility for treasuries. Privacy is cleaner with TSS because everything looks like a single key; with multisig, unless using Taproot carefully, some policy aspects can leak when spending. The THORChain case shows