Skip to content
decentralization

THORChain decentralization challenged over DPRK flows

GoPlus challenged THORChain’s decentralization claims, citing validator halt powers and past DPRK-linked fund flows through the protocol.

By 6 min read
THORChain decentralization challenged over DPRK flows
THORChain decentralization challenged over DPRK flows

GoPlus challenged THORChain’s decentralization claims, citing validator halt powers and past DPRK-linked fund flows through the protocol.

Share

GoPlus Security has challenged THORChain’s decentralization claims, arguing that its validator-controlled vaults and emergency mechanisms give node operators powers that differ from Bitcoin and Ethereum.

Summary

  • GoPlus argues THORChain validators can halt signing, challenging comparisons with Bitcoin and Ethereum decentralization models.
  • THORChain documentation allows emergency pauses, chain-specific signing halts and Mimir votes when funds face risks.
  • FBI attributed the 2025 Bybit theft to North Korea and urged services to block transactions.
  • THORChain halted its network after a May exploit drained approximately $10.7 million from one vault.
  • GoPlus claims Bitget-linked funds have moved through THORChain while North Korean attribution remains unconfirmed publicly.

GoPlus Security said on Sept. 27 that THORChain should not compare its cross-chain architecture directly with decentralized Layer 1 networks when explaining why stolen funds cannot be blocked. The firm pointed to THORChain’s threshold-signature vaults, active validator set and emergency governance controls.

Its criticism follows renewed scrutiny over stolen funds routed through THORChain after the Bitget breach. GoPlus claims around 101.5 BTC linked to the incident had already exited through the protocol, while another 27.63 million XRP was being routed toward Bitcoin.

Bitget has not publicly confirmed that North Korean actors carried out its September attack. The exchange said investigators had seen preliminary IP and VPN similarities associated with previous North Korean-linked activity, but attribution remained unconfirmed, as crypto.news reported after the Bitget breach.

❗️ #THORChain has never been strictly decentralized@THORChain comparing itself to decentralized L1s like BTC and ETH does not hold. Do not enable criminals — or put the industry at risk — just to take swap fees on stolen funds.

1️⃣ Custody: TSS vaults ≠ base-layer consensus… https://t.co/x23ZWABnNb pic.twitter.com/D3wD9qG3hX

— GoPlus Security 🚦 (@GoPlusSecurity) September 27, 2026

You might also like:

Coldcard hacker uses THORChain to swap stolen BTC

THORChain validators can halt signing during emergencies

GoPlus based part of its argument on controls documented by THORChain itself. THORChain’s emergency procedures state that a node operator can issue a make pause command when funds face a critical threat. One pause lasts 720 blocks, or roughly one hour, while additional nodes can extend the halt.

Node operators can then vote on more targeted measures through Mimir, the protocol’s on-chain parameter system. THORChain documentation lists trading halts, chain-specific stops and signing controls among the available emergency actions.

GoPlus argued that these controls distinguish THORChain from Bitcoin or Ethereum base-layer consensus. THORChain uses threshold signatures to authorize outbound transactions from shared vaults, meaning participating nodes collectively manage the signing process for cross-chain swaps.

THORChain describes the same mechanism as a security design intended to distribute control among independent node operators rather than place vault keys with one entity.

The protocol’s own May exploit report says operational Mimir parameters can activate after three node votes. Four votes can overturn the decision, while another five can reinstate it. Economic parameters require a two-thirds supermajority.

GoPlus cited those features when arguing that THORChain has mechanisms capable of stopping specific flows when operators believe funds are at risk.

May exploit showed THORChain can coordinate a halt

THORChain used those controls during its own security incident on May 15.

A malicious validator exploited weaknesses in the protocol’s GG20 Threshold Signature Scheme and reconstructed the private key for one Asgard vault. Approximately $10.7 million was drained before the network fully stopped.

Automatic solvency monitoring first detected irregular vault balances and halted signing and trading on several chains. Node operators then coordinated through Discord and used manual pauses and Mimir votes to stop trading, signing, chain observation and validator churning.

THORChain’s official exploit report says roughly 18 to 20 nodes stacked pause commands during the response. A complete controlled halt was reached within around two hours after community members raised the alarm.

The network remained offline for roughly five weeks. Trading resumed June 23 after patched signing code, vault checks and governance-approved recovery procedures were introduced.

As crypto.news reported when trading resumed, THORChain restored swaps, signing, churning and liquidity operations after completing its restart process.

GoPlus referred to that intervention as evidence that THORChain operators possess working tools for stopping network activity when security concerns reach an emergency threshold.

Bybit laundering dispute remains central to the argument

The disagreement over illicit transactions dates back to the February 2025 Bybit hack. The FBI formally attributed the theft of approximately $1.5 billion in virtual assets from Bybit to North Korea. Its public notice identified the activity as part of the TraderTraitor campaign.

The agency specifically encouraged exchanges, bridges, RPC operators, DeFi services and blockchain companies to block transactions involving addresses connected with the stolen assets.

Much of the stolen Ethereum was later converted into Bitcoin through cross-chain services. Bybit CEO Ben Zhou said around 72% of roughly $900 million in converted assets had passed through THORChain.

Crypto.news reported in March 2025 that the attackers converted most of the stolen 499,000 ETH within ten days, with THORChain handling a large share of the swaps.

Early in that laundering period, THORChain recorded $2.91 billion in trading volume and roughly $3 million in fee revenue over five days, according to on-chain data cited by crypto.news.

GoPlus’s new post uses a later estimate of roughly $5.9 billion in volume and $5.5 million in fees. Those figures are the security firm’s calculation and have not been confirmed in THORChain financial disclosures.

Earlier THORChain vote to block flows was reversed

The Bybit episode produced an internal dispute among THORChain contributors and validators. In February 2025, three validators voted to halt Ethereum trading as stolen Bybit funds moved through the protocol. Developer Oleg Petrov later said the action was reversed within minutes.

Core contributor Pluto subsequently said he would stop contributing to THORChain. Validator TCB said at the time that he could leave as well unless the network developed a way to stop North Korean-linked flows.

THORChain founder John-Paul Thorbjornsen supported continued trading and opposed allowing a non-authority third party to dynamically update protocol-level deny lists.

Thorbjornsen said he would support nodes using static deny lists based on official OFAC or FBI information if individual operators were comfortable doing so.

GoPlus now argues that official government attribution provides a stronger basis for intervention than dynamic lists maintained by private security companies.

The FBI’s 2025 Bybit notice explicitly asked private-sector virtual asset services to block transactions involving or derived from the listed TraderTraitor addresses.

Bitget flows renew the decentralization dispute

GoPlus brought the earlier arguments back into focus after the September Bitget breach. The firm claims approximately 101.5 BTC worth around $8.5 million has already exited through THORChain from Bitget-linked flows. It said another 27.63 million XRP, valued near $43 million, was moving through swaps toward Bitcoin.

Those numbers come from GoPlus’s tracing and should be treated as the security company’s analysis rather than figures confirmed by Bitget or THORChain.

Bitget has raised its confirmed estimate of assets transferred to attacker-controlled addresses to approximately $387.5 million. The exchange has begun offering recovery bounties and plans to restore withdrawals in stages from Sept. 28. Crypto.news reported the updated loss and bounty program on Sept. 26.

GoPlus said THORChain could use its existing emergency framework for funds tied to addresses officially identified by agencies such as the FBI or OFAC.

THORChain’s documented emergency procedures define a critical event as one in which funds in pools or vaults face an attack or another threat to protocol security. The documentation tells node operators to initiate pauses and vote on targeted emergency actions under those conditions.

Whether the same framework should be applied to externally stolen assets moving through THORChain is the point of dispute raised by GoPlus. THORChain’s published procedures describe technical security emergencies but do not state that every third-party theft automatically requires a protocol halt.

Read more:

Jason Calacanis calls meme coins a ‘giant scam’

crypto.news

Leave a comment

Market data by CoinGecko