Revisiting the $10.7M THORChain Hack with LLMs: Cryptographic Flaws Explained

banteg · x · 2026-08-12

Security researcher banteg detailed how they used LLMs (suspected to be DeepSeek 5.6 and Kimi) to assist in security research, successfully revisiting the $10.7M THORChain vault compromise.

The post breaks down how the attacker combined three implementation flaws in tss-lib:

These flaws allowed the attacker to reconstruct the vault's full ECDSA private key and sign transactions directly. The author also noted that LLMs still hit safety refusals during analysis, requiring workarounds to salvage session transcripts.

Original post →

More from Safety

Safety channel →