Security Firm Questions THORChain’s Decentralization Over Transaction Halting Ability
UpGateNegativeRegulation & policy

Security Firm Questions THORChain’s Decentralization Over Transaction Halting Ability

Reading time: 3 min

GoPlus Security has publicly challenged THORChain’s decentralization claims, citing the protocol’s ability to halt transactions and its role in processing funds linked to the Democratic People’s Republic of Korea (DPRK). The critique, which emerged on September 26, centers on THORChain’s threshold signature scheme (TSS) vaults, arguing they represent a fundamental difference from the architecture of Bitcoin and Ethereum.

According to GoPlus Security, THORChain’s TSS vaults allow validators shared control over outbound transfers and the capability to halt transactions. This contrasts with Bitcoin and Ethereum, where users hold their own private keys, and no validator committee can collectively freeze or halt fund movements. GoPlus asserts that THORChain halts require a minimum of three validators to enact and four to reverse. This technical distinction, GoPlus argues, means a system where validators can collectively halt transactions resembles a financial intermediary more than a base-layer blockchain.

Context: Bitget Hack and DPRK-Linked Funds

The security firm’s challenge gained prominence following the Bitget exchange hack, which resulted in losses of approximately $387.5 million. GoPlus identified funds processed through THORChain during the incident as ‘highly likely DPRK-linked.’ Specifically, around 101.5 BTC, valued at about $8.5 million, and approximately 27.63 million XRP, worth around $43 million, were processed via THORChain in the aftermath of the hack.

This is not the first time THORChain has been associated with funds linked to illicit activities. According to multiple trackers, since at least 2023, the protocol has processed over $1 billion in funds attributed to DPRK operations. The typical pattern observed involves converting stolen Ethereum into Bitcoin using THORChain’s cross-chain capabilities.

THORChain’s Architecture and Governance

THORChain operates as a cross-chain liquidity protocol utilizing its native token, RUNE. It features a validator set of approximately 100 nodes and is designed to allow users to swap assets across different blockchains without centralized intermediaries. The protocol employs a governance system called Mimir for parameter changes and emergency halts.

GoPlus Security’s argument suggests that THORChain’s architecture, which necessitates active validator participation in signing transactions and allows for collective control over outbound transfers, fundamentally differs from the permissionless nature often associated with networks like Bitcoin. This difference, GoPlus implies, challenges THORChain’s ability to claim a similar level of decentralization.

While THORChain’s defenders may argue that blocking specific transactions would compromise the protocol’s neutrality and turn validators into compliance officers, the technical architecture remains a point of contention. The distinction is significant, as regulatory frameworks increasingly differentiate between protocols based on their operational architecture rather than their stated goals.

Uncertainties and Implications

Uncertainties remain regarding the practical application of THORChain’s halting mechanism, such as whether validators have collectively refused to sign a transaction. The exact total amount of DPRK-linked funds processed by THORChain is also not definitively established. However, the core technical capability for validators to halt transactions, as highlighted by GoPlus Security, presents a significant point of discussion regarding THORChain’s decentralization claims and its potential classification within the evolving regulatory landscape.

Why This Matters

The materials describe a narrow update: GoPlus Security publicly questioned THORChain’s decentralization narrative on September 26, arguing that its threshold signature scheme (TSS) vaults, which allow validators shared control over outbound transfers and the ability to halt transactions, are structurally different from Bitcoin and Ethereum. Whether THORChain’s validators have ever collectively refused to sign a transaction.

Broader Context

Source materials place the factual news in this context: The critique didn’t arrive in a vacuum. It landed one day after the Bitget exchange hack, which resulted in losses of roughly $387.5 million.

Tags:UpGateNegativeRegulation & policy
Copied