THORChain trading is back after a $10.7M exploit. The shutdown was the warning.
The vault migration narrows one failure path, but THORChain's job is still harder than a normal DEX because it routes value across chains that don't share the same rules.

CryptoVibe Desk · thorchain · defi · exploits

- →THORChain resumed all trading on June 23 after a $10.7M exploit and more than one month offline.
- →The fix matters, but cross-chain vaults remain a bigger attack surface than single-chain swap contracts.
- →Watch before August whether XMR routing returns without another vault pause, emergency halt, or migration rollback.
- vault migration → A vault migration moves user funds from old shared wallets into new ones after a security change.
- cross-chain DEX → A cross-chain DEX lets users swap coins from different blockchains without using a normal exchange account.
- XMR → XMR is Monero, a privacy coin designed to hide sender, receiver, and amount details.
THORChain turned trading back on June 23. The restart came after a $10.7M exploit and more than one month of halted network activity, according to CoinTelegraph and CryptoNews.
The important part is not that trading resumed. It is that THORChain needed a full stop, security upgrades, and a vault migration to get there. For a cross-chain DEX, that is the architecture speaking through the incident.
At the contract level, THORChain is not just matching two assets inside one chain. It coordinates vaults, signing logic, chain-specific rules, and external assets. That means one weak assumption can sit outside the clean part of the swap path. The vault migration may close the exploited path, but it doesn't make the system simple.
This is a boundary problem. Ethereum contracts can fail in ugly ways, but the state lives in one machine. THORChain has to reason across several machines with different finality, different mempools, and different failure modes. If you're using it because it feels like one swap button, remember what sits behind that button.
RUNE traded near $0.419 at the time of resumption on June 23, per CryptoNews. That number is less useful than the halt duration. A network that has to stop for more than a month after an exploit is telling users where the real risk lives.
CryptoNews cited XMR routing as part of the recovery path, but the exact design has not been confirmed publicly. Privacy-coin routing is useful, but it gives defenders less visibility when something goes wrong. The tradeoff is privacy for harder monitoring.
The code may now do what the recovery plan says. The missing piece is a public, official post-mortem that names the vulnerability class and the specific checks added. Until then, the market only knows the outcome: $10.7M lost, more than one month paused, trading back on for now.
THORChain's problem is not that cross-chain swaps are impossible. It is that every extra chain adds another place where assumptions can break. The vault migration narrows the wound. It doesn't remove the attack surface.
THORChain resumed XMR routing without publishing the vulnerability class or the specific checks added. Users routing privacy-coin swaps are trusting a retrofit they cannot verify. For a protocol that just went dark for a month, skipping the post-mortem is the second mistake.
Before August 2026, watch whether THORChain processes XMR-routed swaps for seven straight days without another vault pause, emergency halt, or migration rollback.
Primary links and supporting reads used by the desk for this story.
Forward this.











