THORChain has approved ADR028, paving the way for a controlled network restart following the May 15 exploit that resulted in a $10.7 million loss from one of its vaults. The exploit, which targeted a GG20 Threshold Signature Scheme vulnerability, prompted an emergency halt and trading pause across the network. In response, THORChain nodes have been upgraded to v3.18.1 to protect remaining vaults, with further updates planned. ADR028 ensures the restart will occur without minting new RUNE, focusing on protocol-owned liquidity to cover losses. The recovery plan includes a bounty for the attacker to return funds and full slashing of the attacker's node. Security audits are ongoing, with the tss-lib repository temporarily closed to facilitate this process.