THORChain
Native cross-chain exchange, contested recoveries and the economics of shared vaults.
THORChain trades native assets through RUNE-based liquidity and shared signing vaults. Its appeal is exchange without a conventional account. Integration exploits, failed lending products and contested recoveries make its custody model and the distinction between protocol and interface essential to understanding the project.
Questa lettura è attualmente disponibile in inglese. L’interfaccia usa la lingua selezionata.
Leggi l’originale inglese →Verifica della lettura vocale del browser…
What native swaps actually mean
THORChain is its own blockchain and a trading protocol connecting assets that live on other networks. RUNE is its native asset, used for settlement liquidity and validator bonding. That identity is different from a wallet or exchange interface displaying THORChain routes. A person can encounter the protocol through another product without becoming a RUNE investor, while a RUNE holder need not operate any of its infrastructure.
In a native Bitcoin-to-Ethereum swap, the user sends BTC on Bitcoin and receives ETH on Ethereum. RUNE connects the pools internally; the user does not have to acquire it first. This avoids leaving the user with a wrapped Bitcoin token as the destination product. It does not eliminate the period in which the input has entered a protocol vault and the outbound payment is still being processed.
Vaults are controlled through threshold signing among participating nodes. Bifröst observes external chains and brings their transactions into THORChain's consensus process. Vault membership changes as nodes rotate, so an old deposit address must never be treated as permanently valid. The architecture distributes custody across a network, rather than removing custody from the process. External-chain observation, consensus and signing must all work correctly for a swap to settle.
Who earns fees, and who carries exposure
A liquidity position is exposure to the assets in its pool, including RUNE. Depositing one asset does not preserve a claim to that same quantity regardless of subsequent prices. The provider documentation explicitly describes changing balances and impermanent loss, with fees that may fail to offset those changes. The attraction is earning from trading activity; the economic cost is accepting a different outcome from simply keeping the original coins.
A displayed swap cost can combine source-chain gas, a liquidity fee, a destination-chain outbound charge and an interface's affiliate fee. Those payments compensate different parties. Streaming a trade across smaller pieces can reduce price impact, but adds execution time and remains dependent on available liquidity. Comparing routes therefore requires both the amount expected at the destination and the conditions under which the transaction can be delayed or refunded.
Node operators must supply bonded RUNE and maintain the systems required to observe and sign for multiple chains. Their return is business revenue with operating expenses, downtime penalties and slashing exposure. Losing control of an operator key can also jeopardize access to a bond. The documentation's illustrative hosting and reward figures are not a current quotation; the durable point is that security participation combines capital risk with continuing technical work.
An ambitious exchange learns through failures
The June 2021 ETH parsing incident showed how a mistake at the boundary between chains could become a loss inside the liquidity system. The project's account described incorrect transaction interpretation, a network halt and a patch, with a treasury-backed restoration plan. This was an integration failure rather than proof that Bitcoin or Ethereum consensus had failed. Cross-chain products inherit their own additional attack surface around otherwise functioning source networks.
The July 2021 postmortem covered two ETH router exploits and a premature return to trading. Its significance extends beyond the individual coding errors: deciding when to restart was itself part of the incident. A repaired component did not automatically make the whole operational process safe. That history helps explain why later discussions repeatedly emphasize staged integrations, security review and the possibility of halting trading while uncertainty remains.
Aquila's December 2021 mainnet RFC explicitly asked for stronger coordination between developers, node operators and the community. It proposed stability milestones, testing and healthier node bonds before a mainnet designation. The document's January target was a plan, not a launch certificate. Its comment thread also records an early tension that persisted: whether attracting more liquidity actually strengthened the network when that liquidity generated little trading revenue.
Code, votes and emergency judgment
THORChain governance is deliberately more constrained than an unrestricted token-holder parliament. Its documentation distinguishes software changes, node-controlled Mimir parameters and market-driven pool selection. Changing a parameter and changing the executable code are different decisions. This structure gives operators practical authority while developers still determine which implementations are available to adopt. Describing the system as minimally governed should not hide the human decisions behind upgrades, risk limits or emergency interventions.
An administrator paused the products on January 9, and nodes reversed the pause that day. The retrospective says administrative Mimir keys were subsequently removed in version 3.2.0. Later node voting paused the products again. The sequence demonstrates contested intervention powers, not the disappearance of operational discretion.
RUNE's monetary policy should also be read through dated decisions. The accepted ADR-023 record describes a reserve reduction and a maximum-supply reduction from 500 million to 360 million RUNE. An accepted architecture record is evidence of an approved design, not a substitute for checking its deployed accounting. The investor inference that a smaller supply guarantees a higher price goes beyond the document: demand, liquidity and liabilities remain separate variables.
The lending dream and its unwinding
The original THORFi lending design sought loans without interest charges, liquidation events or expiry dates. It used derived accounting and RUNE conversions rather than simply keeping every borrower's original collateral untouched in a separate vault. Its supporters expected the arrangement to attract outside capital and expand liquidity. The claimed benefits depended on economic relationships between RUNE and collateral assets, even when the interface made borrowing appear unusually simple.
The March 2025 unwind account connected collateral shortfalls and savings leverage to RUNE's weak performance. It also blamed damaging sentiment, an interpretation rather than independent evidence about prices. Lending and Savers were paused, leaving claims subject to restructuring. Historical product descriptions therefore should not be reused as instructions to open new positions.
TCY launched in May 2025 as the restructuring asset for eligible affected claims. Claiming and staking TCY provides exposure to a designated share of system income, paid in RUNE. It does not deliver the original collateral back at a guaranteed dollar value. A market in a recovery token lets a claimant choose whether to sell or remain exposed, but the existence of that choice is different from having been made whole.
Recovery was an argument about fairness
Aaluxx Myth's P6 implementation draft put rapid implementation and lower code complexity ahead of an elaborate rescue architecture. It proposed phased changes, a TCY claim mechanism and continuing attention to node incentives. Parts of the draft were aspirations about future capital efficiency, not already deployed features. Reading the proposal as a historical document preserves the distinction between the recovery supporters wanted and the narrower mechanics that ultimately went live.
Ursa's competing proposal emphasized the option to wait for an in-kind recovery rather than force every claimant to accept an immediate haircut. It combined priority exits with bailout modules and keeping protocol liquidity in pools. The underlying moral argument was patience and equal treatment of comparable claims. Its open-ended timetable also exposed a difficult tradeoff: preserving an eventual claim can leave a person waiting without a reliable completion date.
Slambammer proposed restricting exits from affected liquidity positions until network recovery improved. In the same thread, Mr. Smith objected that penalizing these providers could deepen distrust, especially when they had not initiated the run. That exchange is unusually useful evidence of community disagreement. Both sides wanted a functioning protocol, yet disagreed about whose freedom to exit should be constrained and whether retention incentives could restore confidence.
The 2026 vault exploit and the limits of repair
On May 15, 2026, an attacker extracted roughly $10.7 million from one of five vaults, according to the initial incident report. A recently admitted malicious validator exploited signing-related weaknesses. Detection and subsequent halts limited further exposure, but occurred after funds had moved. The event is a direct warning against interpreting distributed signing as an absolute guarantee that no single adversary can ever reconstruct or misuse a vault key.
The second report traced the incident to weaknesses in an older threshold-signature implementation and acknowledged that relevant upstream improvements had not been incorporated earlier. That is a maintenance and assurance lesson as much as a cryptographic one. The report describes patched software, network verification and changes to the security process. Those measures are evidence of remediation work; they do not retroactively validate the earlier library or establish that future implementations cannot fail.
Soda Labs and THORSec's further analysis separated consensus assumptions from the threshold needed to authorize a vault signature. Those are related but different security mechanisms. The report also examined how the signing weaknesses interacted, rather than reducing the incident to a generic stolen-password explanation. Proposed transitions to newer signing approaches must remain labeled as work to verify until deployed releases demonstrate them. A published analysis is not itself an activation event.
What changed again during 2026
The September 23 income announcement allocated 59% of system income to nodes, 20% to protocol-owned liquidity, 10% to TCY, 5% to development, 5% to marketing and 1% to burning RUNE. These shares describe the announced configuration, not permanent constitutional rights. They show the practical competition between security spending, deeper markets, recovery claims and token scarcity. Trading growth alone does not reveal how much value reaches any particular holder.
Version 3.20 added controls for protocol-owned liquidity and included an experimental Stable Reserve mechanism disabled by default. Its release notes also distinguished restored operations from integrations still being prepared. This matters when reading ambitious chain-support announcements: code preparation, a successful upgrade and an active trading route are separate milestones. A prospective user needs the live status of the particular chain and asset pair, not a count copied from a roadmap.
The August network report recorded renewed churn after an extended pause, alongside another execution mismatch that temporarily interrupted operation near the end of the month. It described protocol-owned liquidity as live and discussed continuing integrations. The evidence supports a network undergoing recovery and change, not uninterrupted service. Monthly volume or revenue should therefore be read alongside halt duration, functioning routes and the security work required to sustain those numbers.
The freedom narrative and the interfaces around it
The app-layer introduces another distinction: secured assets are THORChain-accounted claims on underlying native assets held by the protocol. They enable applications to use those balances, including the Rujira environment. Such a balance is not the same object as a coin sitting directly in a user's external-chain wallet. The native-swap story and the application-composability story can both be valid, provided their custody, contract and redemption assumptions are explained separately.
September's Houdini Swap debate concerned an optional service exposed through an interface, including routes involving centralized counterparties. Chad Barraford distinguished that service from the base protocol, while participants also questioned branding and revenue incentives. A familiar THORChain logo therefore cannot establish that every available route has identical trust assumptions. The relevant question is which route actually executes the transaction and what that route's operators can delay, freeze or disclose.
The official vision invokes financial freedom and an exchange infrastructure that can rival large centralized venues. That ambition helps explain why supporters persist through difficult recoveries: they want native assets to move without opening a conventional exchange account. It remains a vision. Evidence of progress consists of reliable settlement, useful liquidity and credible security practices; cultural loyalty, revenue projections and comparisons with major exchanges cannot demonstrate those outcomes on their own.
Come siamo arrivati qui.
- 2021-06-29
ETH parsing exploit disclosed
THORChain published an account of an integration error, the resulting loss and its halt-and-patch response.
- 2021-07-30
Router incident postmortem published
A combined report examined two exploits and the decision to resume trading prematurely.
- 2021-12-08
Mainnet RFC opens community discussion
Aquila published proposed stability and coordination milestones; the timetable remained a target.
- 2022-09-17
THORFi lending design proposed
The design described interest-free, non-liquidating loans supported through derived accounting and RUNE conversions.
- 2025-01-24
Nodes pause THORFi
Node voting halted Lending and Savers as exposure to collateral liabilities and liquidity losses intensified.
- 2025-05-05
TCY claims launch
Eligible affected users gained a recovery-token route linked to a share of network income.
- 2026-05-15
One vault loses funds in signing exploit
The incident later reported by THORChain affected one of five vaults and approximately $10.7 million.
- 2026-08-24
Version 3.20 announced
The upgrade introduced operational changes for protocol-owned liquidity and a disabled experimental reserve mechanism.
- 2026-09-23
Income allocation revised
The announced split increased protocol-owned liquidity funding and reduced the burn share to 1%.
Convinzioni, ambizioni e domande aperte.
Sono narrazioni attribuite, non approvazioni. Apri ogni dossier per vedere i documenti a sostegno e i limiti di ciò che dimostrano.
Convinzione documentataLiquidity should help pay for its security
Apri il dossier delle prove
Community member space-machine argued that donation-driven liquidity could strengthen node bonding rather than be rejected.
Da dove viene la storia
December 8, 2021 reply to Aquila's mainnet RFC.
Cosa sostengono i documenti
- The proposal would redirect part of donated value toward node incentives, addressing pools with depth but little swap volume.
Cosa non dimostra
- The author's revenue estimates and suggested mechanism were an argument for a design, not verified future earnings or a record of its adoption.
Cosa osservare
- Compare actual fees and secured value with the capital and operating costs required from nodes.
Interpretazione controversaA claimant should be allowed to wait
Apri il dossier delle prove
Ursa's recovery proposal treated the option of eventual in-kind redemption as preferable to compulsory immediate loss recognition.
Da dove viene la storia
Nine Realms contributor Ursa's January 31, 2025 proposal.
Cosa sostengono i documenti
- The design combined optional priority haircuts with slowly distributed bailout support and preserved pool liquidity.
Cosa non dimostra
- An unbounded timetable cannot promise when recovery will occur. This was a competing proposal, not a description of the later TCY claim entitlement.
Cosa osservare
- Distinguish rights actually implemented from rights a recovery proposal hoped to preserve.
Interpretazione controversaKeeping liquidity versus respecting the right to leave
Apri il dossier delle prove
Slambammer believed exit restrictions could give incumbent providers a larger stake in recovery; Mr. Smith argued that the restrictions would damage trust.
Da dove viene la storia
January 30 and 31, 2025 GitLab proposal and responses.
Cosa sostengono i documenti
- The thread directly records support for conditional exits and an objection that these providers should not bear another penalty.
Cosa non dimostra
- The exchange does not establish either view as community consensus or prove the proposed formula would restore solvency.
Cosa osservare
- Track which stakeholders fund a rescue and which retain a practical exit.
Interpretazione controversaA freedom-oriented protocol can have disputed interfaces
Apri il dossier delle prove
The Houdini discussion exposed disagreement over whether optional privacy-oriented routing and related revenue fit THORChain's public identity.
Da dove viene la storia
September 24, 2026 community podcast recap by Ray / Raynalytics.
Cosa sostengono i documenti
- Participants distinguished protocol mechanics, frontend services and commercial integrations rather than treating them as one system.
Cosa non dimostra
- A service's inclusion is not proof that every route is decentralized, private or protected from counterparty intervention.
Cosa osservare
- Look for route disclosure, commercial terms and the stated boundaries between the protocol and interface operator.
La biblioteca delle fonti.
I documenti primari spiegano meccanismi e decisioni. I registri comunitari mostrano le convinzioni dei partecipanti. Le date indicano quando i link sono stati verificati; le pagine esterne possono cambiare.
- What is THORChain and RUNE? ↗THORChain · primary · Verificato 2026-09-30
- Native cross-chain swaps ↗THORChain · primary · Verificato 2026-09-30
- THORChain vision ↗THORChain · primary · Verificato 2026-09-30
- Liquidity providers and their risks ↗THORChain · primary · Verificato 2026-09-30
- Fees technical deep dive ↗THORChain · primary · Verificato 2026-09-30
- Node risks, costs and rewards ↗THORChain · primary · Verificato 2026-09-30
- ETH parsing error and exploit ↗THORChain · primary · Pubblicato il 2021-06-29 · Verificato 2026-09-30
- ETH router exploits and premature return to trading ↗THORChain · primary · Pubblicato il 2021-07-30 · Verificato 2026-09-30
- Aquila: Path to Mainnet, with community replies ↗THORChain GitLab participants · community · Pubblicato il 2021-12-08 · Verificato 2026-09-30
- Governance technical deep dive ↗THORChain · primary · Verificato 2026-09-30
- THORFi unwind and decision timeline ↗THORChain · primary · Pubblicato il 2025-03-18 · Verificato 2026-09-30
- ADR-023: RUNE supply restructure, accepted record ↗THORChain · primary · Verificato 2026-09-30
- Lending design using derived assets ↗THORChain GitLab · primary · Pubblicato il 2022-09-17 · Verificato 2026-09-30
- TCY launch ↗Nine Realms / THORChain · primary · Pubblicato il 2025-05-05 · Verificato 2026-09-30
- Aaluxx Myth: P6 implementation plan V2 ↗Aaluxx Myth · community · Verificato 2026-09-30
- Ursa: priority haircuts and bailout modules ↗Ursa / Nine Realms · community · Pubblicato il 2025-01-31 · Verificato 2026-09-30
- Slambammer: proposed synth LP exit mechanism ↗Slambammer and GitLab respondents · community · Pubblicato il 2025-01-30 · Verificato 2026-09-30
- THORChain exploit report 1 ↗THORChain · primary · Pubblicato il 2026-05-20 · Verificato 2026-09-30
- THORChain exploit report 2 ↗THORChain · primary · Pubblicato il 2026-07-03 · Verificato 2026-09-30
- THORChain exploit report 3 ↗Soda Labs and THORSec / THORChain · primary · Pubblicato il 2026-08-06 · Verificato 2026-09-30
- How the new system income distribution works ↗THORChain · primary · Pubblicato il 2026-09-23 · Verificato 2026-09-30
- Protocol upgrade v3.20 ↗THORChain · primary · Pubblicato il 2026-08-24 · Verificato 2026-09-30
- State of the network: August 2026 ↗THORChain · primary · Pubblicato il 2026-09-04 · Verificato 2026-09-30
- Secured assets ↗THORChain · primary · Verificato 2026-09-30
- Inside the Houdini Swap debate ↗Ray / Raynalytics and community podcast participants · community · Pubblicato il 2026-09-24 · Verificato 2026-09-30
- Bifröst, TSS and vaults ↗THORChain · primary · Verificato 2026-09-30