Overview
- Late September security firm GoPlus published an analysis arguing THORChain’s GG20 threshold‑signature vaults and an active validator set let node operators jointly control outbound transfers rather than leaving keys solely with users.
- GoPlus traced flows from the recent Bitget breach through THORChain and flagged about 101.5 BTC (roughly $8.5 million) and 27.63 million XRP (roughly $43 million) as having been processed by the protocol.
- THORChain’s own documentation and history show node operators can issue 720‑block pauses and use Mimir votes to halt signing or reverse actions, and operators did coordinate such a halt after a May 15, 2026 exploit that drained about $10.7 million.
- THORChain and some security defenders say those emergency tools protect the protocol and do not equal selective blacklisting, while critics say the same tools demonstrate the protocol already has effective custody powers.
- If regulators accept GoPlus’s framing, cross‑chain swap services could face new compliance duties and exchanges may press protocols to block known attacker addresses, affecting how users and businesses rely on permissionless infrastructure.