THORChain’s v3.20 Upgrade Strengthens Cross-Chain Security

Five months after an attacker drained $10.7 million from one of its vaults, THORChain is back online with encrypted validator keys and a permission system built to contain the next…

Abstract network of glowing connected nodes representing the THORChain v3.20 upgrade's cross-chain security

Priya runs a small import business and moves stablecoins across BNB, Base, and Solana every week to pay overseas suppliers. For five months, that route sat frozen: THORChain halted trading on all three chains after an attacker drained $10.7 million from one of its vaults in May, forcing her to route payments through slower, pricier channels instead. On August 25, 2026, the cross-chain protocol activated its THORChain v3.20 upgrade, adding new encryption for validator keys and reopening trading on all three chains at once.

The timing matters. Back in May, an attacker infiltrated one of THORChain’s Asgard vaults and drained $10.7 million. The network halted trading on BNB, Base, and Solana while engineers rebuilt the security model from the ground up. Five months later, that rebuild shipped.

What Changed in the THORChain v3.20 Upgrade

The upgrade encrypts TSS keyshares, the fragments validators use to jointly sign cross-chain transactions. Before, a compromised node could expose more than its own piece of the signing process. Now each keyshare stays locked down individually, so one bad node can’t cascade into a bigger breach.

THORChain also shipped ADR-030, a new permission system that lets node operators delegate specific duties without handing over full control of their validator. That change narrows the blast radius if a single operator gets compromised or acts maliciously.

Trading on BNB, Base, and Solana came back online in the same release. The protocol also restored network churn, the rotation process that cycles validators in and out, which is a core piece of how THORChain stays decentralized over time.

Beyond Security: New Swap Capabilities

The update isn’t only about locking things down. THORChain expanded Memoless Swaps to ERC-20 tokens, added support for MorpheusAI’s MOR token, and introduced experimental stablecoin-to-stablecoin swaps that execute at a flat 1:1 rate with no slippage or liquidity fees when reserves allow it. For someone like Priya, that flat rate means a supplier gets paid in full instead of losing a percentage point or two to slippage on every transfer, savings that add up fast across weekly payments.

Engineers also pushed forward work on Monero and Zcash integration, tackling the key generation and vault rotation steps those privacy coins need before they can trade natively on the network. CryptoTimes covered the full release notes shortly after the upgrade went live.

Why This Matters for Cross-Chain Security

Cross-chain protocols carry more risk than single-chain networks by design. They hold assets from multiple blockchains and coordinate signatures across all of them. That complexity is exactly what attackers exploited in May. THORChain’s response shows a credible path forward: patch the specific weakness, rebuild the trust mechanisms, and resume operations gradually instead of rushing back online.

Other networks have followed a similar playbook this year. XRP Ledger’s recent security upgrade fixed critical bugs before reviving batch transactions, and BNB Chain’s Pasteur hard fork closed a bridge vulnerability while boosting throughput. Across the industry, protocols are treating security incidents as forcing functions for real architectural fixes, not just quick patches.

For THORChain, the real test comes next: whether the new encryption and permission model holds up under the kind of sustained attack that took down its old one.

Related Reading