Slashing and Economic Security
Slashing is the primary economic defense mechanism that aligns node operator incentives with the security of the network.
The safest wiki wording separates reward slash points from bond-at-risk events, and separates design meaning from current constants or operator state.
What is Slashing?
THORChain uses two related penalty ideas that should not be collapsed together:
- Slash points reduce earned rewards for reliability failures such as missed observations, missed block signing, double block signing, or TSS ceremony failures.
- Bond-principal slashing burns bonded RUNE for separately defined security-critical behavior such as an unauthorized vault outflow.
Bonded RUNE is the "skin in the game" that makes attacks economically irrational, but not every operator fault directly confiscates bond.
The distinction matters for incident diagnosis. When a report says a node was slashed, it could mean reward-point accumulation, a bond-principal penalty, or both. The exact ledger affected depends on the event family and the node lifecycle state at the time of the offense.
The distinction matters for incident diagnosis. When a report says a node was slashed, it could mean reward-point accumulation, a bond-principal penalty, or both. The exact ledger affected depends on the event family and the node lifecycle state at the time of the offense.
Types of Slashing Events
- Observation and signing slash points: Late or missing observations, missed block signing, and TSS keygen/keysign blame can reduce rewards and may affect churn selection or jailing. Example: a node that is offline during a churn keygen accumulates slash points for missing the ceremony, which can push its total above the bad-validator threshold and trigger churn-out.
- Double block signing: Double block signing adds slash points under the current source-tree vault documentation; it does not by itself prove a bond-principal slash. The operator risk page also documents a separate double-sign capital penalty, so classify the exact event and current implementation before stating which balance was affected. Example: a node that signs two different blocks at the same height accumulates slash points and may face capital penalties depending on the current implementation.
- Bond-principal slashing: An observed outbound that does not match an approved THORChain instruction can slash signing nodes' bonded RUNE and trigger additional chain-safety handling. Example: nodes that sign an outbound transaction not matching an approved vault instruction can lose bonded RUNE proportionally, not just earned rewards.
Common Misreadings
-
"Every slash point means bond was confiscated." Slash points accumulate for reliability failures and reduce earned rewards. Only bond-principal slashing — a separately defined security-critical event like an unauthorized vault outflow — actually confiscates bonded RUNE. A node can accumulate many slash points without losing bond.
-
"Slashing is proportional to the offense." Some offenses carry fixed penalties rather than proportional ones. Double block signing, for example, may have a fixed slash amount regardless of the offense size. Check current Mimir constants for the actual penalty structure.
-
"Slashed nodes are immediately removed." Slash points accumulate and interact with the bad-validator threshold at churn time. A node can carry slash points through multiple churn intervals before being churned out, depending on the current threshold and other eligibility factors.
-
Slashing is only for malicious behavior.Most slash points come from reliability failures -- being offline, missing observations, or failing to participate in signing ceremonies. Malicious behavior like unauthorized vault outflows triggers a different penalty class (bond-principal slashing) with different thresholds and consequences. -
Slashing is only for malicious behavior.Most slash points come from reliability failures -- being offline, missing observations, or failing to participate in signing ceremonies. Malicious behavior like unauthorized vault outflows triggers a different penalty class (bond-principal slashing) with different thresholds and consequences.
Slash Rate
Slash constants, jail periods, churn thresholds, and minimum bond values can be overridden by live Mimir parameters. The wiki should describe the economic purpose and event class, then point to THORNode constants, Mimir, node state, and transaction evidence for current values rather than freezing a rate in prose.
The economic logic is straightforward: the penalty for misbehavior must exceed the profit from the attack. If a node can steal more than it loses from slashing, the security model breaks. This is why bond ranges, minimum bond, and slash multipliers are protocol-critical parameters that should be checked against current Mimir constants rather than hardcoded in prose.
The economic logic is straightforward: the penalty for misbehavior must exceed the profit from the attack. If a node can steal more than it loses from slashing, the security model breaks. This is why bond ranges, minimum bond, and slash multipliers are protocol-critical parameters that should be checked against current Mimir constants rather than hardcoded in prose.
Churn and Unbonding
Nodes whose slash points cross the current bad-validator threshold can be marked for churn-out. Unbonding and leaving are state-dependent: only Standby nodes outside vault migration may unbond, while Ready and Active nodes cannot. See the Churning deep dive for the full node lifecycle, churn mechanics, and vault migration details.
Why This Matters
Without strong slashing, a rational actor could attempt to steal funds or disrupt the network if the expected value of the attack exceeded the bond at risk. Bond ranges, minimum bond, and slash multipliers are live/current-only parameters and should be checked before being quoted.
Current source-tree documentation also separates vault-lifecycle security, observation consensus, and capital penalties. That separation matters when an incident report uses the broad word "slashed" without identifying the affected ledger or event family.
Current State
In late 2024, community discussion and incident reports raised concerns that slashing enforcement was not working as intended — the phrase "slashing seems completely broken" appeared in public governance discussions. Subsequent protocol releases and Mimir parameter updates addressed some of these concerns, but the exact enforcement status remains a live, protocol-state-dependent question. Current slash behavior should be verified against current Mimir constants, node state, and recent incident evidence rather than assumed from static documentation.
For current enforcement status, check node-level slash-point totals in THORNode state, compare against the live MinSlashPointsForBadValidator threshold, and review recent incident reports for bond-principal events. The wiki cannot establish current network safety from static documentation alone.
For current enforcement status, check node-level slash-point totals in THORNode state, compare against the live MinSlashPointsForBadValidator threshold, and review recent incident reports for bond-principal events. The wiki cannot establish current network safety from static documentation alone.
Operator Evidence Ladder
For a current operator or incident claim, use current node status, bond, slash-point, jail, and vault-membership data; current Mimir/constants for thresholds; exact event evidence for observations, signing, keygen, or outbound actions; and dated reports only for historical wording. "Has slash points" is not the same claim as "bond was confiscated."
A slashing statement should identify the reward-versus-bond ledger, exact event family, affected lifecycle state, and whether it describes a dated incident or the current release. Without those checks, this page cannot establish current totals, balances, parameters, unbonding availability, network safety, or incident recovery.