GoPlus argues that THORChain’s architecture—which relies on threshold-signature vaults and an active validator set—differs significantly from base-layer networks like Bitcoin or Ethereum. According to the firm, THORChain’s documented emergency procedures, including Mimir votes and chain-specific signing halts, demonstrate that node operators possess the technical capability to intervene against specific fund flows.
This dispute resurfaced after GoPlus claimed that approximately 101.5 BTC linked to the September Bitget breach had already exited via the protocol, with nearly 27.63 million XRP currently moving toward Bitcoin. While Bitget has not confirmed North Korean involvement in the attack, the incident has renewed pressure on THORChain to address how it handles assets tied to high-profile thefts.
THORChain has previously utilized these emergency mechanisms during its own security incidents. Following a May 2025 exploit that drained $10.7 million, node operators coordinated a network-wide halt within two hours by stacking pause commands and utilizing Mimir votes. The protocol maintains that these controls are designed to distribute security among independent operators rather than centralize power. However, critics contend that if the network can pause to protect its own liquidity, it should similarly act against funds flagged by agencies like the FBI. The debate remains unresolved, with THORChain leadership previously resisting the implementation of dynamic deny lists that would allow third-party intervention in automated swaps.

Comments (0)
No comments yet. Be the first!