Search the site
Press ESC to close
LIVE
Loading...
Updating...

GoPlus Challenges THORChain Decentralization Over Stolen Fund Transfers

Fact-checked
2 min read
395 words
Share

Security firm GoPlus Security has publicly challenged the decentralization claims of THORChain (RUNE) following the movement of illicit assets linked to the Bitget exchange hack. The security provider argues that the protocol’s architecture allows for the potential interception of funds associated with North Korean cybercriminals, contrary to THORChain's assertions regarding permissionless operations. The dispute highlights a growing tension between the technical constraints of decentralized finance (DeFi) and the pressure to comply with international security standards.

Mechanism of Fund Outflows and Security Concerns

According to GoPlus Security, THORChain operates differently than base-layer networks like Bitcoin (BTC) or Ethereum (ETH). The firm points out that fund outflows on THORChain require active signing by validators through Threshold Signature Schemes (TSS). This technical distinction suggests that validators could theoretically prevent specific transactions from being processed. GoPlus identified significant illicit activity involving the following assets:

  • Approximately 101.5 BTC (valued at roughly $6.5 million) stolen from Bitget has been transferred via the protocol.
  • An additional 27.63 million XRP (estimated at $16 million) is currently being exchanged for Bitcoin through THORChain’s liquidity pools.

TSS technology is a cryptographic primitive for key generation and signing that requires a distributed set of nodes to cooperate to authorize a transaction, which GoPlus suggests creates a point of control.

THORChain Response and the Decentralization Debate

In response to the growing scrutiny regarding the handling of hacker-linked assets, THORChain maintainers have reiterated their stance on the nature of the protocol. The project emphasizes that it functions as a decentralized, permissionless network, which, by design, cannot selectively block transactions or addresses without compromising its core principles.

Decentralized permissionless protocols cannot prevent this.

GoPlus Security has countered this by calling for the active interception of North Korean-associated addresses, suggesting that the validator set has the technical capacity to intervene. This situation echoes previous industry debates regarding Tornado Cash and other privacy-enhancing or cross-chain protocols that have been utilized by malicious actors to obfuscate the origin of funds.

The conflict underscores a critical juncture for the cross-chain liquidity sector. As regulators and security firms increase pressure on DeFi protocols to implement filtering mechanisms, the definition of true decentralization remains a contested topic. The outcome of this debate could significantly impact how liquidity providers and node operators manage their responsibilities in the face of sophisticated cybercrime and international sanctions.

Frequently Asked Questions

Quick answers to the most common questions about this topic.