Skip to content
Deep DiveCurated

Slashing and Economic Security

Bonded RUNE, slash exposure, and why current constants should be source checked.

CuratedChecked 2026-07-14·Review due 2026-08-14·
THORNode risks, costs and rewards
retrieval details
Source retrieved 2026-07-05Official node-operator source for slash points, bond rewards, operator fees, and node reward mechanics.
+3 sources
Managing THORNodes
retrieval details
Source retrieved 2026-07-05Official node operations guidance for slash troubleshooting, sync checks, and operational risk.
THORNode vault behaviors
retrieval details
Source retrieved 2026-07-14Pinned official THORNode source-tree snapshot for physical-vault lifecycle, inbound-vault selection, migration, and the distinction between slash points and bond-principal slashing.
THORChain constants and Mimirs
retrieval details
Source retrieved 2026-07-05Official constants and Mimir reference; live Mimir reads still own current override state.

Use This Article For: An economic-security guide for bond risk, punishment mechanics, and the evidence needed before calling current validator behavior safe or unsafe.

Verify Elsewhere Before Claiming: Current validator evidence, bond state, slash event records, protocol version, source freshness, and whether a safety claim is economic design or observed behavior.

Verify Now

Use these current-state checks before turning this explainer into a live protocol, wallet, or availability claim.

Slashing and Economic Security

Slashing is the primary economic defense mechanism that aligns node operator incentives with the security of the network.

The safest wiki wording separates reward slash points from bond-at-risk events, and separates design meaning from current constants or operator state.

What is Slashing?

THORChain uses two related penalty ideas that should not be collapsed together:

  • Slash points reduce earned rewards for reliability failures such as missed observations, missed block signing, double block signing, or TSS ceremony failures.
  • Bond-principal slashing burns bonded RUNE for separately defined security-critical behavior such as an unauthorized vault outflow.

Bonded RUNE is the "skin in the game" that makes attacks economically irrational, but not every operator fault directly confiscates bond.

Types of Slashing Events

  • Observation and signing slash points: Late or missing observations, missed block signing, and TSS keygen/keysign blame can reduce rewards and may affect churn selection or jailing.
  • Double block signing: Double block signing adds slash points under the current source-tree vault documentation; it does not by itself prove a bond-principal slash. The operator risk page also documents a separate double-sign capital penalty, so classify the exact event and current implementation before stating which balance was affected.
  • Bond-principal slashing: An observed outbound that does not match an approved THORChain instruction can slash signing nodes' bonded RUNE and trigger additional chain-safety handling.

Slash Rate

Slash constants, jail periods, churn thresholds, and minimum bond values can be overridden by live Mimir parameters. The wiki should describe the economic purpose and event class, then point to THORNode constants, Mimir, node state, and transaction evidence for current values rather than freezing a rate in prose.

Churn and Unbonding

Nodes whose slash points cross the current bad-validator threshold can be marked for churn-out. Unbonding and leaving are state-dependent: only Standby nodes outside vault migration may unbond, while Ready and Active nodes cannot.

Why This Matters

Without strong slashing, a rational actor could attempt to steal funds or disrupt the network if the expected value of the attack exceeded the bond at risk. Bond ranges, minimum bond, and slash multipliers are live/current-only parameters and should be checked before being quoted.

Current source-tree documentation also separates vault-lifecycle security, observation consensus, and capital penalties. That separation matters when an incident report uses the broad word “slashed” without identifying the affected ledger or event family.

Operator Evidence Ladder

For a current operator or incident claim, use the strongest evidence available:

  1. Current node status, bond, slash-point, jail, and vault-membership data from THORNode or operator tooling.
  2. Current Mimir and constants when the claim depends on thresholds or enabled/paused behavior.
  3. Exact observation, signing, keygen, or outbound evidence for a specific event.
  4. Dated incident reports or upgrade notes for historical root-cause and patch wording.
  5. Static docs for design meaning only.

Do not treat "has slash points" as the same claim as "bond was confiscated". Do not treat a historical slash rule as a current parameter without checking current protocol state.

What To Verify Before Claiming

Before making a slashing claim, verify:

  • whether it is reward slashing, slash points, bond slashing, or a broader incident-recovery mechanism,
  • whether the affected node was active, standby, leaving, or already churned out,
  • the current constants/Mimir values if quoting rates or thresholds,
  • the exact event family: observation, signing, keygen, equivocation, theft, or operational downtime,
  • whether a report is describing a specific dated incident rather than the current release.

Non-Claims

This page does not prove:

  • Current slash-point totals, bond balances, or active node risk.
  • That a particular operator fault burned bond rather than reduced rewards.
  • Current slash multipliers, jail periods, minimum bond, churn eligibility, or unbonding availability.
  • That every incident is automatically made whole by slashing.
  • That slashing alone proves present-day network safety.
Glossarysecurityslashing

Reader Paths For This Article

Use these paths to connect this explainer with the current-state checks needed before making live protocol claims.

View all paths
Swap Economics

Readers comparing settlement, slip, liquidity, rewards, and fee signals.

Step 7 of 7CuratedWiki reviewed 2026-07-14Review due 2026-08-14

Verify Before Claiming

  • Current liquidity depth, APY, and earnings coverage from live Midgard snapshots.
  • Current RUNEPool enablement, provider PnL, POL-enabled pool scope, or deposit/withdraw availability.
  • Whether a fee claim is ordinary fee mechanics or the ADR-026 dynamic-fee experiment.

Continue This Path

This is the final article in this path; use the follow-up checks before making live or current-state claims.

Swap Economics step 7/7
Previous in pathThe Incentive Pendulum
Path completeMove to the follow-up checks above.
Network Security

Readers tracing vault safety, observation, node rotation, slash exposure, and current pause controls.

Step 5 of 5CuratedWiki reviewed 2026-07-14Review due 2026-08-14

Verify Before Claiming

  • Current signing, observation, trading, or chain-specific Mimir state.
  • Whether a dated exploit or upgrade source applies to the current release.

Continue This Path

This is the final article in this path; use the follow-up checks before making live or current-state claims.

Network Security step 5/5
Previous in pathChurning and Node Lifecycle
Path completeMove to the follow-up checks above.
Historical Recovery

Readers separating deprecated THORFi context, TCY framing, exploit history, and current recovery state.

Step 4 of 5HistoricalWiki reviewed 2026-07-14Review due 2026-08-14

Verify Before Claiming

  • Current TCY operations, balances, distributions, or recovery progress.
  • That archived memo or product documentation represents an enabled action rather than preserved historical syntax.
  • Current solvency, restart, or safety state beyond dated incident and upgrade reports.

Continue This Path

Continue with Churning and Node Lifecycle before treating this path as complete.

Historical Recovery step 4/5

Browse All Deep Dives

Article library order, separate from reader-path order.