Everything about #THORChain and app layer! Content at @thorchain

Joined October 2024
354 Photos and videos
Pinned Tweet
Many thanks, this means a lot to me!🫡
💡 Community Spotlight Throw this one some love, Chads, because we love to celebrate the consistent contributors to the THORChain ecosystem and today, it's the guy who's editing the videos from our livestreams. @WithTheCoke has a cool journey to share. Let's dive in 👇
2
6
22
2,106
Hey, @THORChain & @RujiraNetwork weekly recap is up! We are almost ready to go back online, with some Rujira updates, & we also had amazing podcast episodes with @TheDesertLynx @BooneW, & on Saturday with @HydratedGoose & @DrFuture8000 from @zephyr_org youtu.be/Q4HPu0dLzdo?si=eAVK…
1
7
38
2,651
With The Coke retweeted
Yeah… Anyway, TC still finding its footing in this brave new world with AI lurking and being weaponized both in attacks but, more frustratingly, in the constant submission of AI slop spam. I will work with core team and the ecosystem to get TC’s security posture up to par, but it will undoubtedly look different than the previous L1 landscape of bug bounties via platforms, they became literally unusable. How to filter the noise is now an important problem to solve, and how to manage submissions in a trustless environment also. The role of security researchers will also evolve, but the threatening recourse breaking responsible disclosure is not the path. On the other hand, apologies to the honest, hard working contributors and researchers who’ve had a negative experiences in the past, please reach out to me if there is something to address from the past honorably. For now, I am aware of x.com/qed_audit/status/20616… and @kayabaNerve , my DM’s are open good sers 🙂 I think I can largely speak for TC nodes and users that security is valued, even if it has been mishandled in the past.

Jun 2
This turned out to be worse than I thought. 1. The company behind v12 was a security vendor for Thorchain, did a security audit in January 2025 for one of their components, and hosted a bug bounty for a thorchain application up until recently! 2. Thorchain paused their bug bounty after being unable to handle the volume of submissions (h/t @QED_Audit for the screenshot). An unfortunate trend for anyone with a bounty in 2026 (curl and many others have publicly spoken about this). 3. Getting denied on a bounty sucks. Every security researcher in the last 20 years will tell you a story of an unfair bounty. You find another target and move on. The pie is bigger than you think. It's not okay to extort, i.e., threaten to release more bugs in public, if they don't pay. It's even more egregious when its a former customer!
11
22
106
20,389
With The Coke retweeted
Incident Update #4 is live and the ADR-028 proposal is on the table Here’s everything you need to know about the @THORChain Recovery Plan 👇 → POL absorbs the loss first. Synth holders take what's left → No new RUNE minted. No holder diluted. No RUNE sold to cover anything → Attacker slashed in full. Recovered RUNE paired with vault assets, surplus burned. → Innocent nodes protected → White hat bounty on the table. Return the funds, the plan rolls back proportionally. → Protocol neutrality holds. Attacker's swaps won't be censored once trading resumes Node Operators vote now. Yes = green light to restart No mint. No bailout. No censorship. Full transparency Onwards⚡
THORChain Incident Update #4 Following the events of May 15th, the community has been hard at work defining a path forward. ADR028 is now published and a vote is open for Node Operators. 🔹 The Recovery Plan 🔹 The protocol will absorb the loss first through Protocol-Owned Liquidity and the remainder is spread across synth holders (The exact split between the two is still being evaluated). By doing so, POL will be reduced to zero. The ADR proposes to redirect a portion of system income to replenish it over time. No new RUNE is minted, no RUNE is sold, and no holder is diluted. 🔹 The Technical Decisions 🔹 GG20 is kept in place for now, patched and upgraded. Trading resumes only after the vulnerability is patched and a successful churn has occurred. A slower, more security-conscious release cadence is also called for going forward. 🔹 The Slashing 🔹 Innocent nodes that end up being in the same vault as the attacker are protected. The attacker's node is slashed in full. The recovered RUNE is paired with whatever assets can be recovered from the affected vault, and any surplus RUNE is burned. 🔹 The White Hat Offer 🔹 The attacker is offered a bounty to return the funds. If funds are returned partially, the recovery plan rolls back proportionally. 🔹 Protocol Neutrality 🔹 THORChain remains neutral and permissionless. The attacker's swaps will not be censored once trading resumes. Node Operators are now voting on the overall direction and principles of this proposal. The figures in the ADR are indicative at this stage and will be adjusted later, notably via Mimir. The goal is to restart the network as soon as possible. A yes vote is a green light for developers to continue building in that direction. Full details of ADR028 gitlab.com/-/snippets/599292… For those who want to understand the full context of what happened, this article is for you: thorchain.org/blog/thorchain…
5
15
71
10,798
With The Coke retweeted
THORChain Exploit Report #1 is now live. Full timeline of the May 15 incident, how the security layers responded, and what comes next via ADR-028. thorchain.org/blog/thorchain…
14
46
212
28,649
With The Coke retweeted
TSS Exploit Update #3 → Attack understood, technical details not yet public → Not a known GG20 exploit → v3.18.1 tomorrow. Node operators instructed to upgrade immediately → Decisions over lost funds set by ADR-028 community governance vote TLDR; we're making progress 💚
THORChain incident update #3 The developers and THORSec teams have been hard at work throughout the weekend continuing the investigation to fully understand the events that took place, while also planning the road to recovery. It’s important to note that the investigation is still ongoing, and details may change in the coming days as we continue to gather information and adjust plans accordingly. At this time, the team has a strong understanding of what occurred and how the attack was executed, although they are not yet in a position to publicly discuss the technical details. What they can say is that the attack vector does not appear to be related to any currently known GG20 exploits, and at this stage are still assessing whether other GG20 implementations could also be at risk. The team will continue investigating this possibility and will coordinate with other affected teams as appropriate. We would like to thank the many cryptographers and security researchers who assisted throughout this process, including members of the team that originally developed GG20. The team currently expects to release version 3.18.1 tomorrow for node operators to adopt. We ask that all node operators upgrade to this release as soon as possible. There is also an open question regarding the best approach for handling the lost funds within the network. This will need to be discussed and ultimately decided by the community through governance. To facilitate this discussion, there’s a new channel in Discord called ⁠adr-028-tss-exploit-recovery . Before the network can return to a healthy state, nodes will need broad consensus on this ADR, after which the selected approach will be implemented as part of the 3.19 update. THORChads are encouraged to share well-structured and thoughtful proposals for the community to support or challenge. In the coming days, a vote will occur highlighting the most widely supported approaches for node operators to vote on. Regarding the future direction of the cryptographic systems used to secure the vaults, that discussion is still ongoing and requires additional research before any long-term decisions are made. For the immediate future, the team is currently leaning toward remaining on GG20 in order to restore network health and stability as quickly and safely as possible. Longer-term discussions around the future of THORChain’s cryptographic security model will continue once the network has stabilized. We are proud of how both the developer team and community have handled this situation. Everything will get running again as soon as possible, but the process will not be rushed. THORChain has a strong roadmap ahead, and devs are excited to return their focus to continuing to push the envelope of what this project can achieve. Onwards
7
37
1,594
With The Coke retweeted
THORChain incident update #3 The developers and THORSec teams have been hard at work throughout the weekend continuing the investigation to fully understand the events that took place, while also planning the road to recovery. It’s important to note that the investigation is still ongoing, and details may change in the coming days as we continue to gather information and adjust plans accordingly. At this time, the team has a strong understanding of what occurred and how the attack was executed, although they are not yet in a position to publicly discuss the technical details. What they can say is that the attack vector does not appear to be related to any currently known GG20 exploits, and at this stage are still assessing whether other GG20 implementations could also be at risk. The team will continue investigating this possibility and will coordinate with other affected teams as appropriate. We would like to thank the many cryptographers and security researchers who assisted throughout this process, including members of the team that originally developed GG20. The team currently expects to release version 3.18.1 tomorrow for node operators to adopt. We ask that all node operators upgrade to this release as soon as possible. There is also an open question regarding the best approach for handling the lost funds within the network. This will need to be discussed and ultimately decided by the community through governance. To facilitate this discussion, there’s a new channel in Discord called ⁠adr-028-tss-exploit-recovery . Before the network can return to a healthy state, nodes will need broad consensus on this ADR, after which the selected approach will be implemented as part of the 3.19 update. THORChads are encouraged to share well-structured and thoughtful proposals for the community to support or challenge. In the coming days, a vote will occur highlighting the most widely supported approaches for node operators to vote on. Regarding the future direction of the cryptographic systems used to secure the vaults, that discussion is still ongoing and requires additional research before any long-term decisions are made. For the immediate future, the team is currently leaning toward remaining on GG20 in order to restore network health and stability as quickly and safely as possible. Longer-term discussions around the future of THORChain’s cryptographic security model will continue once the network has stabilized. We are proud of how both the developer team and community have handled this situation. Everything will get running again as soon as possible, but the process will not be rushed. THORChain has a strong roadmap ahead, and devs are excited to return their focus to continuing to push the envelope of what this project can achieve. Onwards
27
67
329
40,366
Hey all, @THORChain & @RujiraNetwork weekly recap is up! The main topic was obviously the recent exploit, but we also had time for an app layer discussion and a podcast with @firoorg! Thank you all for the support! @Dashpay @XBToshi @banteg and others! youtu.be/f0iFwsRSv1I?si=TK5D…

3
12
56
5,094
With The Coke retweeted
THORChain incident update #2 We have become aware of multiple fake accounts and false information circulating regarding “refunds”, “airdrops”, compensation claims, and other alleged initiatives. To be absolutely clear: - Initial findings indicate that no user funds were lost in the incident - THORChain is currently conducting no refund, airdrop, or compensation program - Any account claiming otherwise is impersonating THORChain or spreading misinformation. Please rely only on official THORChain communication channels for updates. THORChain contributors are still actively investigating the recent incident alongside THORSec and external security partners. More information will be shared as the investigation progresses.
27
50
298
34,041
With The Coke retweeted
There's a good reason THORChain's being smeared online after the recent exploit: symbolism. The protocol has become the symbol of permissionless finance. When it dared to try to resist censorship, it painted a massive target on its back. Now, people who champion permissioned protocols are piling on, because permissionlessness is a threat to them. And yes, even architects of other permissionless protocols are joining in out of pure envy. THORChain is technology filled with innovation and genius, flaws and mistakes. But, like it or not, in this moment it represents much more than just itself. Stand with the THORChads, not because you like them, but because right now, they're at the front lines of the war for freedom. Asgard calls for aid.
31
66
289
8,592
With The Coke retweeted
THORChain incident update #1 THORChain contributors shared a new update in the dev discord regarding the ongoing incident. TLDR - Current evidence points toward a newly churned node linked to the attack, likely operated by a single malicious actor - The leading theory is an exploit in the GG20 TSS implementation, allowing vault key material to leak over time. The attacker may have reconstructed the vault private key and executed unauthorized outbound txs - Current network status: -- The network is paused after multiple node operators executed make pause -- RUNE transfers and chain observation may resume within ~12h unless decided otherwise by the nodes. -- Trading, LP actions, signing, and sensitive operations remain paused for now - Recovery discussions currently include slashing affected node bonds, using POL to absorb losses, or other community-driven solutions The investigation is still ongoing alongside THORSec and Outrider Analytics. ## Full Announcement ## Developers and THORSec have been investigating today’s incident continuously throughout the day. While new information may still emerge, I want to provide the community with an update based on what we currently know. The goal of this update is to clarify the current understanding of the situation as accurately and transparently as possible. A newly churned node, thor16ucjv3v695mq283me7esh0wdhajjalengcn84q, which entered the network several days ago, is currently believed to be associated with the attack. Developers have identified links between Ethereum addresses used to acquire and bond RUNE for this node, and Ethereum addresses that later received the stolen funds. Based on current evidence, it is believed this was conducted by a single malicious operator, though the investigation remains ongoing. At this time, the leading theory is the attacker exploited a vulnerability within the GG20 TSS implementation which allowed sensitive key material from vault participants to leak over time. By accumulating enough leaked information, the attacker was ultimately able to reconstruct the vault’s TSS private key and execute unauthorized outbound transactions. The Treasury is actively collecting forensic data and coordinating with Outrider Analytics and relevant law enforcement agencies in an effort to identify the attacker and pursue recovery of stolen funds where possible. Due to multiple node operators executing make pause, the network is currently paused. Unless further action is taken, the pause state will automatically expire in approximately 12 hours. At this time, the development team is comfortable allowing the pause to expire in order to restore RUNE transfers and chain observation activity. However, trading, signing, LP actions, and other sensitive operations will remain paused until the network and community align on a comprehensive recovery and remediation plan. The recovery process will likely require node governance decisions regarding how losses are ultimately handled. Several potential approaches are already being discussed, including: Slashing the bond of nodes participating in the affected vault Allowing Protocol-Owned Liquidity (POL) to absorb the loss Additional recovery proposals that may emerge from the broader community At this stage, no final decisions have been made. The team is continuing to work on a complete recovery and restart plan for the network. Bringing trading and full functionality back online will likely take several days, and potentially longer depending on the complexity of the chosen remediation path. We will continue to provide updates as more information becomes available. Finally, I want to thank the developers, node operators, security contributors, and the broader THORChain community for the enormous amount of work done today. One of THORChain’s greatest strengths has always been the community’s ability to come together under pressure, collaborate quickly, and solve difficult problems together.
45
54
326
111,568
With The Coke retweeted
We will be doing a Livestream with @CBarraford around 3:15p - 3:30p ET to go over the recent exploit. To ask questions please watch the stream on YouTube and type in your questions there. Comments on the Twitter livestream do not show up on our end. youtube.com/@THORChainCommun…
13
17
107
12,146
With The Coke retweeted
Important Announcement Trading on THORChain is currently halted after a vault was compromised. Initial indications are user funds are safe and only protocol owned funds are affected. The network automatically detected abnormal behavior and halted signing activity, which alerted the broader community and prevented further outbound transactions. The investigation is still ongoing to determine the root cause. Contributors are actively working on the issue and we will report updates as we progress toward a solution. What we currently know: * One of the six Asgard vaults appears to have been compromised. * Current estimates place the loss at approximately $10.7m USD * The network automatically detected the abnormal behavior and halted signing activity, preventing further outbound activity. * Nodes securing the vault were subject to their bonded RUNE being slashed as a result of the unauthorized outbound transactions. * Churn activity has been paused while the investigation and remediation efforts are ongoing. * Onboarding additional chains and operations requiring churns will be delayed until the network is stabilized. * Initial indications show no individual user swaps were affected. We are asking all node operators to immediately review their infrastructure, hosts, key management systems, and operational security for any signs of compromise or abnormal behavior, and to report anything suspicious in Discord. Node operators participating in the affected vault are requested to securely provide Bifrost logs to the dev team for analysis using 'make relay' .
113
119
512
219,329
Join THORChain Live now! youtube.com/live/kXM-GGeqLbk x.com/i/broadcasts/1DGleEPzZ… linkedin.com/video/live/urn:… And request to speak: riverside.com/studio/thorcha… If you don’t want to speak, you can leave a comment in the live chat and the hosts will see it. (YouTube is the most reliable one)
⚡ THORChain Podcast | Monero Live Demo - tomorrow, May 14th. @jpthor joins @KentonC137 on the THORChain Podcast at 1 PM UTC / 9 AM EDT. JP will demo $XMR on the THORChain chainnet. A proof of concept walking through the entire process in real time with real funds: chain deploy, keygen, churning, liquidity, swaps, refunds, gas accounting, consolidation, migrations and more. Monero isn't live on THORChain yet. Bring your questions and jump on stage: riverside.com/studio/thorcha… Also streaming on YouTube: youtube.com/@THORChainCommun…
3
6
419
This will be huge🔥
⚡ THORChain Podcast | Monero Live Demo - tomorrow, May 14th. @jpthor joins @KentonC137 on the THORChain Podcast at 1 PM UTC / 9 AM EDT. JP will demo $XMR on the THORChain chainnet. A proof of concept walking through the entire process in real time with real funds: chain deploy, keygen, churning, liquidity, swaps, refunds, gas accounting, consolidation, migrations and more. Monero isn't live on THORChain yet. Bring your questions and jump on stage: riverside.com/studio/thorcha… Also streaming on YouTube: youtube.com/@THORChainCommun…
1
5
30
647
Successful @monero churn has happened! I repeat: Monero swaps are working on the chain net! 🔥 LFG @BooneW
16
39
227
7,607