How the attack worked
" -> "איך התקיפה עבדה
" Then: "The attacker didn't break the cryptography in one shot. Instead, they abused the protocol's round structure — repeatedly failing signing rounds to extract partial key information. Over 864 attempts, the cumulative leakage gave them enough to reconstruct the full key. The exploit took about 60 hours, suggesting a patient, methodical approach rather than a brute-force smash-and-grab. THORChain's post-mortem didn't specify whether the vulnerability has been fully patched, but the exchange has since paused and resumed operations.
" Translation: "התוקף לא שבר את ההצפנה בניסיון אחד. במקום זאת, הוא ניצל את מבנה הסבבים של הפרוטוקול – כישלון חוזר ונשנה של סבבי חתימה כדי לחלץ מידע חלקי על המפתח. במשך 864 ניסיונות, הדליפה המצטברת נתנה לו מספיק כדי לשחזר את המפתח המלא. הניצול ארך כ-60 שעות, מה שמרמז על גישה סבלנית ומתודית ולא על פריצה אלימה. הבדיקה שלאחר המוות של THORChain לא ציינה אם הפרצה תוקנה במלואה, אך הבורסה מאז השהתה וחידשה את פעילותה.
" Next: "TSS vs. multisig trade-offs
" -> "הפשרות בין TSS ל-multisig
" Then: "The THORChain incident highlights a known weakness in TSS: protocol-level round abuse and denial-of-service risks. Multisig, by contrast, is provable on-chain — every signature is visible, and quorum enforcement happens in the script. But multisig comes with its own costs. A 2-of-3 P2SH setup eats about 296 vBytes per input; a 3-of-5 P2WSH runs ~350 vB. With Taproot and Schnorr, schemes like FROST or MuSig2 can shrink that to ~57.5 vB, cutting fees roughly 80% in higher-threshold setups. That's a big deal for high-throughput chains. But the trade-off is that TSS looks like a single signature on-chain, making it harder for auditors to verify policy without strong off-chain logs and attestations.
" Translation: "האירוע ב-THORChain מדגיש חולשה ידועה ב-TSS: סיכוני ניצול סבבים ברמת הפרוטוקול והתקפות מניעת שירות. לעומת זאת, multisig ניתן להוכחה על השרשרת – כל חתימה נראית, ואכיפת קוורום מתרחשת בסקריפט. אבל ל-multisig יש עלויות משלו. הגדרה של 2 מתוך 3 ב-P2SH צורכת כ-296 vBytes לקלט; 3 מתוך 5 ב-P2WSH עולה כ-350 vB. עם Taproot ו-Schnorr, סכמות כמו FROST או MuSig2 יכולות לצמצם זאת לכ-57.5 vB, מה שמקצץ עמלות בכ-80% בהגדרות סף גבוהות יותר. זה משמעותי לשרשראות עם תפוקה גבוהה. אבל הפשרה היא ש-TSS נראה כמו חתימה אחת על השרשרת, מה שמקשה על מבקרים לאמת מדיניות ללא לוגים והצהרות חזקים מחוץ לשרשרת.
" Next: "Wallet compromise was the costliest vector in the first half of 2026, according to CertiK's H1 review. The firm counted $1.3 billion lost across 344 incidents, with wallet-related attacks accounting for $444.5 million across just 33 cases. That's about a third of all losses from less than 10% of incidents. The THORChain exploit fits that pattern — a wallet-level vulnerability, not a smart contract bug or a bridge hack. For teams choosing between TSS and multisig, the decision often comes down to fee sensitivity versus auditability. TSS suits low-fee, high-throughput flows where the wallet acts as an externally owned account (EOA). Multisig suits conservative ops where on-chain policy visibility and simple recovery matter more than saving a few dollars per transaction.
" Translation: "פריצת ארנקים הייתה הווקטור היקר ביותר במחצית הראשונה של 2026, לפי סקירת H1 של CertiK. החברה מנתה 1.3 מיליארד דולר שאבדו ב-344 אירועים, כאשר התקפות הקשורות לארנק היוו 444.5 מיליון דולר ב-33 מקרים בלבד. זה כשליש מכלל ההפסדים בפחות מ-10% מהאירועים. הניצול ב-THORChain מתאים לתבנית זו – פרצה ברמת הארנק, לא באג בחוזה חכם או פריצת גשר. עבור צוותים שבוחרים בין TSS ל-multisig, ההחלטה מסתכמת לעתים קרובות ברגישות לעמלות מול יכולת ביקורת. TSS מתאים לזרימות בעלות עמלות נמוכות ותפוקה גבוהה שבהן הארנק פועל כחשבון בבעלות חיצונית (EOA). Multisig מתאים לפעולות שמרניות שבהן נראות מדיניות על השרשרת ושחזור פשוט חשובים יותר מאשר חיסכון בכמה דולרים לכל עסקה.
" Next: "On Ethereum, TSS can appear as a single EOA, avoiding contract execution overhead — but that also means giving up contract-level guardrails and visibility for treasuries. Privacy is cleaner with TSS because everything looks like a single key; with multisig, unless using Taproot carefully, some policy aspects can leak when spending. The THORChain case shows that the protocol-level attack surface of TSS is real, and not just theoretical. Whether the industry responds with better round-abuse protections or a shift back toward on-chain multisig for high-value wallets remains an open question.
" Translation: "ב-Ethereum, TSS יכול להופיע כ-EOA יחיד, ומונע תקורה של ביצוע חוזה – אבל זה גם אומר ויתור על גדרות הגנה ברמת החוזה ועל נראות עבור קופות. הפרטיות נקייה יותר עם TSS כי הכל נראה כמו מפתח יחיד; עם multisig, אלא אם כן משתמשים ב-Taproot בזהירות, חלק מהיבטי המדיניות יכולים לדלוף בעת הוצאת כספים. המקרה של THORChain מראה שמשטח התקיפה ברמת




