Skip to content
⬡
THORChain Wiki
Deep DiveCurated

Slashing and Economic Security

Bonded RUNE, slash exposure, and why current constants should be source checked.

About this article's sourcing
CuratedChecked 2026-07-14·
THORNode risks, costs and rewards
retrieval details
Source retrieved 2026-07-05Official node-operator source for slash points, bond rewards, operator fees, and node reward mechanics.
+3 sources
Managing THORNodes
retrieval details
Source retrieved 2026-07-05Official node operations guidance for slash troubleshooting, sync checks, and operational risk.
THORNode vault behaviors
retrieval details
Source retrieved 2026-07-14Pinned official THORNode source-tree snapshot for physical-vault lifecycle, inbound-vault selection, migration, and the distinction between slash points and bond-principal slashing.
THORChain constants and Mimirs
retrieval details
Source retrieved 2026-07-05Official constants and Mimir reference; live Mimir reads still own current override state.

Use this article for: An economic-security guide for bond risk, punishment mechanics, and the evidence needed before calling current validator behavior safe or unsafe.

Verify elsewhere before claiming: Current validator evidence, bond state, slash event records, protocol version, source freshness, and whether a safety claim is economic design or observed behavior.

Slashing and Economic Security

Slashing is the primary economic defense mechanism that aligns node operator incentives with the security of the network.

The safest wiki wording separates reward slash points from bond-at-risk events, and separates design meaning from current constants or operator state.

What is Slashing?

THORChain uses two related penalty ideas that should not be collapsed together:

  • Slash points reduce earned rewards for reliability failures such as missed observations, missed block signing, double block signing, or TSS ceremony failures.
  • Bond-principal slashing burns bonded RUNE for separately defined security-critical behavior such as an unauthorized vault outflow.

Bonded RUNE is the "skin in the game" that makes attacks economically irrational, but not every operator fault directly confiscates bond.

The distinction matters for incident diagnosis. When a report says a node was slashed, it could mean reward-point accumulation, a bond-principal penalty, or both. The exact ledger affected depends on the event family and the node lifecycle state at the time of the offense.

The distinction matters for incident diagnosis. When a report says a node was slashed, it could mean reward-point accumulation, a bond-principal penalty, or both. The exact ledger affected depends on the event family and the node lifecycle state at the time of the offense.

Types of Slashing Events

  • Observation and signing slash points: Late or missing observations, missed block signing, and TSS keygen/keysign blame can reduce rewards and may affect churn selection or jailing. Example: a node that is offline during a churn keygen accumulates slash points for missing the ceremony, which can push its total above the bad-validator threshold and trigger churn-out.
  • Double block signing: Double block signing adds slash points under the current source-tree vault documentation; it does not by itself prove a bond-principal slash. The operator risk page also documents a separate double-sign capital penalty, so classify the exact event and current implementation before stating which balance was affected. Example: a node that signs two different blocks at the same height accumulates slash points and may face capital penalties depending on the current implementation.
  • Bond-principal slashing: An observed outbound that does not match an approved THORChain instruction can slash signing nodes' bonded RUNE and trigger additional chain-safety handling. Example: nodes that sign an outbound transaction not matching an approved vault instruction can lose bonded RUNE proportionally, not just earned rewards.

Common Misreadings

  • "Every slash point means bond was confiscated." Slash points accumulate for reliability failures and reduce earned rewards. Only bond-principal slashing — a separately defined security-critical event like an unauthorized vault outflow — actually confiscates bonded RUNE. A node can accumulate many slash points without losing bond.

  • "Slashing is proportional to the offense." Some offenses carry fixed penalties rather than proportional ones. Double block signing, for example, may have a fixed slash amount regardless of the offense size. Check current Mimir constants for the actual penalty structure.

  • "Slashed nodes are immediately removed." Slash points accumulate and interact with the bad-validator threshold at churn time. A node can carry slash points through multiple churn intervals before being churned out, depending on the current threshold and other eligibility factors.

  • Slashing is only for malicious behavior. Most slash points come from reliability failures -- being offline, missing observations, or failing to participate in signing ceremonies. Malicious behavior like unauthorized vault outflows triggers a different penalty class (bond-principal slashing) with different thresholds and consequences.

  • Slashing is only for malicious behavior. Most slash points come from reliability failures -- being offline, missing observations, or failing to participate in signing ceremonies. Malicious behavior like unauthorized vault outflows triggers a different penalty class (bond-principal slashing) with different thresholds and consequences.

Slash Rate

Slash constants, jail periods, churn thresholds, and minimum bond values can be overridden by live Mimir parameters. The wiki should describe the economic purpose and event class, then point to THORNode constants, Mimir, node state, and transaction evidence for current values rather than freezing a rate in prose.

The economic logic is straightforward: the penalty for misbehavior must exceed the profit from the attack. If a node can steal more than it loses from slashing, the security model breaks. This is why bond ranges, minimum bond, and slash multipliers are protocol-critical parameters that should be checked against current Mimir constants rather than hardcoded in prose.

The economic logic is straightforward: the penalty for misbehavior must exceed the profit from the attack. If a node can steal more than it loses from slashing, the security model breaks. This is why bond ranges, minimum bond, and slash multipliers are protocol-critical parameters that should be checked against current Mimir constants rather than hardcoded in prose.

Churn and Unbonding

Nodes whose slash points cross the current bad-validator threshold can be marked for churn-out. Unbonding and leaving are state-dependent: only Standby nodes outside vault migration may unbond, while Ready and Active nodes cannot. See the Churning deep dive for the full node lifecycle, churn mechanics, and vault migration details.

Why This Matters

Without strong slashing, a rational actor could attempt to steal funds or disrupt the network if the expected value of the attack exceeded the bond at risk. Bond ranges, minimum bond, and slash multipliers are live/current-only parameters and should be checked before being quoted.

Current source-tree documentation also separates vault-lifecycle security, observation consensus, and capital penalties. That separation matters when an incident report uses the broad word "slashed" without identifying the affected ledger or event family.

Current State

In late 2024, community discussion and incident reports raised concerns that slashing enforcement was not working as intended — the phrase "slashing seems completely broken" appeared in public governance discussions. Subsequent protocol releases and Mimir parameter updates addressed some of these concerns, but the exact enforcement status remains a live, protocol-state-dependent question. Current slash behavior should be verified against current Mimir constants, node state, and recent incident evidence rather than assumed from static documentation.

For current enforcement status, check node-level slash-point totals in THORNode state, compare against the live MinSlashPointsForBadValidator threshold, and review recent incident reports for bond-principal events. The wiki cannot establish current network safety from static documentation alone.

For current enforcement status, check node-level slash-point totals in THORNode state, compare against the live MinSlashPointsForBadValidator threshold, and review recent incident reports for bond-principal events. The wiki cannot establish current network safety from static documentation alone.

Operator Evidence Ladder

For a current operator or incident claim, use current node status, bond, slash-point, jail, and vault-membership data; current Mimir/constants for thresholds; exact event evidence for observations, signing, keygen, or outbound actions; and dated reports only for historical wording. "Has slash points" is not the same claim as "bond was confiscated."

A slashing statement should identify the reward-versus-bond ledger, exact event family, affected lifecycle state, and whether it describes a dated incident or the current release. Without those checks, this page cannot establish current totals, balances, parameters, unbonding availability, network safety, or incident recovery.

Glossarysecurityslashing
Reader paths for this article

Use these paths to connect this explainer with the current-state checks needed before making live protocol claims.

View all paths
Swap Economics

Readers comparing settlement, slip, liquidity, rewards, and fee signals.

Step 7 of 7

Verify Before Claiming

  • Current liquidity depth, APY, and earnings coverage from live Midgard snapshots.
  • Current RUNEPool enablement, provider PnL, POL-enabled pool scope, or deposit/withdraw availability.
  • Whether a fee claim is ordinary fee mechanics or the ADR-026 dynamic-fee experiment.

Continue This Path

This is the final article in this path; use the follow-up checks before making live or current-state claims.

Swap Economics step 7/7
Previous in pathThe Incentive Pendulum
Path completeMove to the follow-up checks above.
Network Security

Readers tracing vault safety, observation, node rotation, slash exposure, and current pause controls.

Step 5 of 5

Verify Before Claiming

  • Current signing, observation, trading, or chain-specific Mimir state.
  • Whether a dated exploit or upgrade source applies to the current release.

Continue This Path

This is the final article in this path; use the follow-up checks before making live or current-state claims.

Network Security step 5/5
Previous in pathChurning and Node Lifecycle
Path completeMove to the follow-up checks above.
Historical Recovery

Readers separating deprecated THORFi context, TCY framing, exploit history, and current recovery state.

Step 4 of 5

Verify Before Claiming

  • Current TCY operations, balances, distributions, or recovery progress.
  • That archived memo or product documentation represents an enabled action rather than preserved historical syntax.
  • Current solvency, restart, or safety state beyond dated incident and upgrade reports.

Continue This Path

Continue with Churning and Node Lifecycle before treating this path as complete.

Historical Recovery step 4/5

Browse All Deep Dives

Article library order, separate from reader-path order.