Incident case

THORChain 2021 ETH Router exploit 2

A second July 2021 attack used a fake router and malicious refund memo to make Bifrost accept a fabricated deposit event, draining economically significant ERC-20 assets from THORChain's Ethereum-side liquidity.

reviewedcurrent

Incident facts

Incident title
THORChain 2021 ETH Router exploit 2
Bridge
THORChain
Incident date
2021-07-22
Incident type
Exploit
Major incident
Yes
Affected chains
THORChain, Ethereum
Affected assets
USDC, USDT, Unknown
Attack category
Message Verification Failure
Reported loss
Approximately $8 million
Recovery
Unknown
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Resolution
Final outcome known
Last reviewed
2026-07-28
Last verified
2026-07-28

Timeline events

  • Second THORChain ETH Router exploit disclosed2021-07-22

    A second July 2021 ETH Router incident removed an ERC-20 asset basket from protocol liquidity.

    Exploit DisclosedHigh
  • THORChain returned to staged trading after remediation2021-10

    After audits, router changes, node upgrades, and treasury-led loss coverage, THORChain resumed functions and trading in stages.

    Bridge ReopenedMedium
  • THORChain reported 2021 exploit users fully reimbursed2022-05-11

    THORChain stated that after the chain restarted, liquidity providers and node operators affected by the 2021 exploits were fully reimbursed approximately 16 million dollars in aggregate.

    Reimbursement CompletedHigh

Evidence records

Known unknowns