Blockchain AcademicsBlockchain Academics
THORSwap Pressures Hacker with Bounty Deals After Founder’s Wallet Breach

THORSwap Pressures Hacker with Bounty Deals After Founder’s Wallet Breach

THORSwap offers repeated bounties to hacker who stole $1.3M from THORChain founder’s wallet, urging return of funds.

Blockchain Academics NewsroomSeptember 13, 20253 min read
Share

THORSwap, the decentralized exchange aggregator tied to THORChain, is intensifying efforts to recover more than $1.3 million stolen from a wallet believed to belong to John-Paul Thorbjornsen, THORChain’s founder. Over the past days, the project has issued repeated on-chain messages offering a bounty to the attacker, pledging not to pursue legal action if the funds are returned within 72 hours.

The incident was first flagged by blockchain security firm PeckShield, which suggested that the THORChain protocol itself had been compromised. That alarm sparked fears of yet another high-profile DeFi hack. However, the team quickly clarified that the breach affected a personal wallet, not the protocol or THORSwap’s infrastructure. “The rewards are tied solely to recovering stolen assets,” THORSwap’s pseudonymous CEO, Paper X, stressed in public statements.

The scale of the theft has raised eyebrows across the crypto community. According to on-chain records, the hacker siphoned approximately $1.35 million, including $1.03 million in Kyber Network tokens and $320,000 in THORSwap tokens. The assets were funneled through an address labeled “Exploiter 6,” later linked to another Ethereum account beginning with 0x7Ab. Independent investigator ZachXBT confirmed that the funds appear to have been converted into ETH, complicating recovery efforts.

The circumstances of the breach are equally unsettling. Thorbjornsen has stated that the compromise likely originated from a phishing attack involving a fake Zoom invitation sent through a hijacked Telegram account of a friend. The exploit targeted his MetaMask wallet and may have leveraged access to iCloud Keychain or Chrome profile data. Despite being logged out, the wallet was successfully drained, exposing weaknesses in personal security practices even among seasoned crypto founders.

For THORSwap, the decision to negotiate openly with the attacker reflects a pragmatic, if controversial, approach. The public bounty offers are unusual in their explicit promise of no prosecution, underscoring the community’s desire to resolve the situation without escalating to formal legal channels. This strategy highlights the complex dynamics of blockchain crime, where anonymity and cross-border challenges often render conventional enforcement ineffective.

Still, the breach has sparked renewed debate over wallet security standards. Thorbjornsen himself, long a proponent of threshold signature wallets that distribute key shares across devices, admitted the attack has shaken his confidence. The episode serves as a cautionary tale for both retail and institutional users: even advanced defenses can be undermined by social engineering or overlooked vulnerabilities.

As negotiations continue, the hacker’s next move remains uncertain. The bounty offers represent both an opportunity for restitution and a test of whether informal agreements can succeed in the volatile and largely unregulated world of decentralized finance. Regardless of the outcome, the attack underscores an uncomfortable truth—no matter how robust the technology, human error and deception remain critical weak points in the crypto ecosystem.

Discussion

Loading comments...