← All stories
⚖️

THORChain decentralization debate and stolen-funds handling

GoPlus Security has reignited a debate over THORChain’s claim to decentralization by highlighting structural aspects of its threshold-signature (TSS) vaults and emergency governance that differentiate it from base-layer networks such as Bitcoin and Ethereum. The security firm argues that THORChain’s design—where roughly one hundred validator nodes collectively sign outbound transfers from shared Asgard vaults—gives node operators the practical ability to pause or halt signing in ways that do not exist on Bitcoin or Ethereum, where private key custody rests with individual users.

The criticism followed the Bitget exchange breach that resulted in roughly $387.5 million in losses and accelerated after on-chain tracing showed attacker flows moving into THORChain. GoPlus reported that approximately 101.5 BTC (about $8.5 million) and roughly 27.63 million XRP (about $43 million) passed through THORChain during the incident. Bitquery data showed 126.71 BTC settled on September 25, with over 80% routed via THORChain channels that day. Bitget has raised its confirmed tally of assets transferred to attacker-controlled addresses to approximately $387.5 million, announced recovery bounties, and planned staged withdrawal restorations; it has not publicly confirmed DPRK attribution for the September attack.

At the center of the dispute are THORChain’s documented emergency controls and its Mimir parameter system. Operators can initiate a make pause that lasts 720 blocks (~one hour) and extend halts; three node votes can trigger operational Mimir parameters, four can overturn them, and certain economic changes require a two-thirds supermajority. GoPlus and other critics point to THORChain’s May exploit—when roughly $10.7 million was drained from a vault—as evidence that the protocol can and has coordinated deep pauses. During that incident automated solvency monitoring first detected irregular balances, pausing trading and signing, and around 18–20 nodes layered pause commands; the network remained offline for about five weeks before swaps, signing and liquidity operations resumed after code patches and governance-approved recovery steps.

Supporters of THORChain argue that blocking specific flows compromises neutrality and turns validators into compliance agents; detractors counter that the protocol has repeatedly demonstrated the technical ability to stop activity when its own funds were at risk, raising a double-standard question when victimized exchanges ask for assistance. Historical attribution debates—such as the FBI’s 2025 Bybit notice attributing that theft to DPRK-linked actors and urging private-sector blocking—feed into the disagreement, as do probing on-chain figures about volume and fee revenue during laundering periods. The debate thus hinges on whether capability, governance will, or adherence to permissionless principles should determine whether THORChain refuses service to addresses flagged as carrying stolen funds.