Skip to content
⬡
THORChain Wiki

Governance & History

ADRs, Mimir context, milestones, incidents, and research. Vote percentages are shown only when source-backed.

Curated·Last verified 2026-07-13· 7 sources
CuratedChecked 2026-07-13·
THORChain Docs
retrieval details
Source retrieved 2026-07-05Official documentation root used for curated protocol background; it still describes GG20 at review time, but current safety and migration state require dated incident and release sources.
+6 sources
THORChain Network Halts
retrieval details
Source retrieved 2026-07-05Official halt-control reference; live Mimir and inbound-address reads still own current availability.
THORChain Exploit Report #2
retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Is Back: Security Update
retrieval details
Source retrieved 2026-07-13Official 2026-06-25 post-restart update confirming trading resumed while DKLS/FROST migration and TSS-library publication remained future work.
ADR-028 Exploit Conciliation (v3.19.0)
retrieval details
Source retrieved 2026-07-13Immutable v3.19.0 source marking ADR-028 Accepted and specifying the one-time Migrate15to16 conciliation waterfall; not proof that every affected user recovered every loss.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.

Use this page for

  • Source-backed ADR, Mimir, incident, milestone, and recovery-history context.
  • Dated incident and governance records with explicit current-review labels.

Verify elsewhere before claiming

  • Current node consensus, live Mimir values, active recovery status, or final governance outcome.
  • That a historical incident record proves present-day network safety or solvency.

Move from dated governance and incident records into current diagnostics, recovery review, or the historical recovery path before making present-tense claims.

claim path
Claim checks by type

Start with the claim type. Governance records are useful for dated decisions and history; live controls, incident root-cause wording, recovery status, and community interpretation need separate proof paths.

live state

Operational Mimir claim

Use For
Whether trading, signing, LP actions, churning, TCY controls, or chain operations are active now.
Verify
Use Network diagnostics and current THORNode/Mimir evidence before using present-tense availability wording.
Do Not Claim
Do not infer live availability from a proposal, incident archive, milestone, or missing halt mention.
Check live diagnostics
dated record

ADR or proposal status

Use For
What an ADR, proposal, milestone, or governance record said at the cited review point.
Verify
Use the record source, source-map guidance, and any linked live tracker before calling a design active.
Do Not Claim
Do not treat proposed, draft, needs-review, or historical records as final live protocol behavior.
Check official sources
security history

Incident root-cause claim

Use For
Exploit cause, affected vault/chain scope, patch wording, migration context, and dated security lessons.
Verify
Use incident reports plus the Network Security path before summarizing safety or cryptographic details.
Do Not Claim
Do not convert a dated exploit report, restart, or patch into proof of present-day safety.
Read security path
current review

Recovery or solvency claim

Use For
Post-exploit recovery state, THORFi/TCY recovery framing, and records tagged for current review.
Verify
Use the current recovery tracker, TCY recovery timeline, dated upgrade notes, and live diagnostics together.
Do Not Claim
Do not claim final recovery, par redemption, current solvency, or product availability from one record.
Review recovery tracker
context

Community sentiment claim

Use For
Debate topics, open questions, or how contributors described tradeoffs in community channels.
Verify
Use community sources only as context, then confirm protocol facts through official or live sources.
Do Not Claim
Do not present Discord chatter as canonical protocol proof or representative sentiment without sampling.
Check community boundary

Current Incident & Recovery Tracker

Conservative tracker for records explicitly tagged as current or needing current recovery review. Historical unresolved records remain in the incident archive below unless they are re-verified for current tracking.

Show summary and claim-check detail

Tracked records

3

Current or needs-review records promoted from the full governance and incident archive.

Evidence path

Record + live check

Use the full dated record first, then current Network diagnostics before present-tense claims.

Check Before Claiming

Savers or Lending are available now

Start with
Archived feature sources
Verify
Official archived docs and any current interface/source claiming reactivation.
Do not claim
Do not describe archived mechanics as current deposit or borrowing instructions.

Check Before Claiming

A claimant can claim or stake TCY right now

Start with
TCY timeline plus live network diagnostics
Verify
TCY guide, official claim interface, and TCY Mimir controls such as TCYCLAIMINGHALT or TCYSTAKINGHALT.
Do not claim
Do not infer availability from historical TCY launch copy alone.

Check Before Claiming

TCY restored the original debt value

Start with
TCY source caveats
Verify
Market and distribution evidence outside this tracker; official developer docs say full recovery is not guaranteed.
Do not claim
Do not state par recovery, redemption value, or investment outcome as fact.

Check Before Claiming

Post-exploit recovery is complete

Start with
Current recovery tracker records
Verify
Dated exploit reports, upgrade notes, ADR/proposal status, and live network diagnostics.
Do not claim
Do not convert a restart, patch, or proposal into proof of final recovery completion.

Incident record

GG20 Vault Exploit

Explicit current tracker

Exploit Report #2 describes a cryptographic GG20/TSS attack: a validator planted malformed Paillier key material and used repeated failed MTA rounds to leak key-share fragments before signing alone.

Approximately $10M-$10.7M drained from one vault; normal signing and fund movements resumed after v3.19.1 verification, while migration away from GG20 remains planned and current vault safety still needs live evidence.

Use This For
Dated official exploit, restart, patch, and migration context for the May 2026 GG20 vault incident.
Verify Next
  • - Network diagnostics for current halts, signing, route limits, and source warnings.
  • - Security deep dives for the dated GG20/TSS attack scope and migration wording.
  • - TCY controls only when the claim is about current claim, stake, distribution, unstake, or trade actions.
Boundary
Do not use the incident record, restart, or v3.19 notes as proof that recovery is complete, users are made whole, or present-day safety is guaranteed.
Official sourceChecked 2026-07-13·
THORChain Exploit Report #2
retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
+4 sources
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Is Back: Security Update
retrieval details
Source retrieved 2026-07-13Official 2026-06-25 post-restart update confirming trading resumed while DKLS/FROST migration and TSS-library publication remained future work.
ADR-028 Exploit Conciliation (v3.19.0)
retrieval details
Source retrieved 2026-07-13Immutable v3.19.0 source marking ADR-028 Accepted and specifying the one-time Migrate15to16 conciliation waterfall; not proof that every affected user recovered every loss.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.

Incident record

Memoless Transaction Halt Cycle

Explicit current tracker

Community reporting and live Mimir snapshots show a memoless halt, re-enable with a raised transaction cost (MEMOLESSTXNCOST=200000), a spam-driven re-halt, and HALTMEMOLESS=1 active after the v3.20.0 upgrade. The official release notes include memoless ERC-20 handler and refund work in the same window.

Memoless flows were repeatedly unavailable for roughly five days; ordinary memo-based swaps continued when global trading controls were clear. Current state remains a Mimir snapshot question.

Use This For
August 2026 memoless halt, cost vote, spam re-halt, and v3.20.0-era feature work.
Verify Next
  • - Current HALTMEMOLESS and MEMOLESSTXNCOST values in Network diagnostics before any present-tense memoless claim.
  • - The v3.20.0 release notes for dated handler, refund, and chain-client work.
  • - Route quotes for concrete swaps; a memoless halt does not prove ordinary swap routes are blocked.
Boundary
This record proves a scoped availability cycle, not a global outage or a permanent fee level. Cost parameters can be re-voted after the incident window.
CuratedChecked 2026-08-26·
THORNode v3.20.0 Release Notes (GitLab)
retrieval details
Source retrieved 2026-08-26Official v3.20.0 release notes plus blog recap: proposed block 27580000 on 25-Aug-2026, private binary, TSS/Bifrost hardening, memoless ERC20 work, XMR/ZEC chain clients, churn resumption prep, operational POL Mimirs, and the Stable Reserve experiment (ships disabled).
+1 source
Liquify THORNode Mimir endpoint
retrieval details
Source retrieved 2026-07-13Current-only Liquify operational controls; malformed or regionally stale values must not be treated as inactive.

Governance record

ADR-028 Recovery Path

Explicit recovery tracker

ADR-028 is Accepted in the v3.19.0 source and specifies a one-time conciliation migration for exploit-created accounting gaps; that allocation decision is not proof that every loss was restored.

Accepted; implemented in v3.19.0

Use This For
Accepted ADR-028 decision and one-time v3.19.0 conciliation migration for the May 2026 exploit-created accounting gap.
Verify Next
  • - The immutable v3.19.0 ADR before describing its reserve, Saver, treasury, or stuck-swap allocation waterfall.
  • - Current release and Network diagnostics before converting the historical migration into present protocol availability or safety.
  • - TCY controls and official interface evidence before saying a user can claim, stake, trade, or receive distributions now.
Boundary
ADR-028 acceptance proves the conciliation decision and migration design, not that every loss was restored, recovery is complete, current vaults are safe, or any user action is enabled.
Official sourceChecked 2026-07-13·
ADR-028 Exploit Conciliation (v3.19.0)
retrieval details
Source retrieved 2026-07-13Immutable v3.19.0 source marking ADR-028 Accepted and specifying the one-time Migrate15to16 conciliation waterfall; not proof that every affected user recovered every loss.
+3 sources
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Exploit Report #2
retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.

Governance Records

Dated governance and operational records. The status badge describes the record evidence posture; use live diagnostics before turning it into a current action claim.

thorfi-unwind

THORFi Unwind

Deprecation and unwind process for Savers and Lending liabilities.

Historical
Protocol UnwindCreated: 2025-01Record status: Historical
Official sourceChecked 2026-07-13·Review due 2026-11-17·
Source: Archived Savers and Lending docs
source retrieval details
Source retrieved 2026-07-05Official archived feature index marking Savers and Lending as deprecated, no longer available, and preserved only for historical reference.
+3 sources
THORFi Unwind Announcement
retrieval details
Source retrieved 2026-07-05Dated THORFi unwind postmortem with January-February 2025 liability, pause, and Proposal 6 milestones; its implementation-status section is historical, not current TCY availability proof.
RUNE and TCY tokenomics
retrieval details
Source retrieved 2026-07-05Official RUNE and TCY tokenomics overview, including TCY supply, revenue share, and no-governance-rights caveat; current amounts and distributions still require live evidence.
TCY Developer Guide
retrieval details
Source retrieved 2026-07-05Developer-facing TCY mechanics, claim, staking, and recovery caveats, including the explicit warning that full debt recovery is market dependent and not guaranteed.
adr-028-recovery

ADR-028 Recovery Path

ADR-028 is Accepted in the v3.19.0 source and specifies a one-time conciliation migration for exploit-created accounting gaps; that allocation decision is not proof that every loss was restored.

Accepted; implemented in v3.19.0
RecoveryCreated: 2026-05Record status: Implemented once; current recovery claims still need fresh evidence
Official sourceChecked 2026-07-13·Review due 2026-11-17·
Source: ADR-028 Exploit Conciliation (v3.19.0)
source retrieval details
Source retrieved 2026-07-13Immutable v3.19.0 source marking ADR-028 Accepted and specifying the one-time Migrate15to16 conciliation waterfall; not proof that every affected user recovered every loss.
+3 sources
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Exploit Report #2
retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.
mimir-operational-halts

Operational Mimir Halts

Operational Mimir parameters such as HALTTRADING and HALTSIGNING can pause network activity and should be read from THORNode.

Current-only control reference
Operational ParameterCreated: OngoingRecord status: Check current THORNode Mimir state
Official sourceChecked 2026-07-13·Review due 2026-11-17·
Source: THORChain Network Halts
source retrieval details
Source retrieved 2026-07-02Official halt-control reference; live Mimir and inbound-address reads still own current availability.
+1 source
THORNode inbound_addresses
retrieval details
Source retrieved 2026-07-04Current-only chain availability, router, halt, and inbound-address snapshot; not durable uptime proof.
adr-026-dynamic-l1-fees

ADR-026 Dynamic L1 Fees

Dynamic per-thorname and per-pair L1 minimum fee experiment. Official ADR text is proposed-design context while live THORNode snapshots may show enabled Mimirs and dynamic-fee records.

Proposed ADR / live Mimir evidence
ADR / Operational ExperimentCreated: 2026-04-15Record status: ADR discussion review target 2026-11-17
CuratedChecked 2026-07-08·Review due 2026-11-17·
Source: ADR-026 dynamic L1 fee model
source retrieval details
Source retrieved 2026-07-08Architecture decision text still labels the ADR proposed; live THORNode evidence is separate current-only state.
+3 sources
THORNode Mimir endpoint
retrieval details
Source retrieved 2026-07-08Current-only Mimir read showed L1DYNAMICFEEENABLED=1 with SS and Symbiosis whitelist entries; values can change after the checked block.
THORNode dynamic_l1_fees
retrieval details
Source retrieved 2026-07-08Current-only sealed dynamic L1 fee endpoint returned records during this refresh; record values can change by epoch.
THORNode dynamic_l1_fees_current
retrieval details
Source retrieved 2026-07-08Current-only in-progress epoch accumulator endpoint returned records during this refresh; not historical attribution proof.
adr-030-delegated-node-ops

ADR-030 Delegated Node Operator Permissions

Proposed ADR for a per-node delegate registry: the operator could grant MAINT, LEAVE, bond-provider-whitelist, and set-fee permissions to delegate addresses with optional block-offset expiry. Custody, UNBOND, OPERATOR_ROTATE, and delegation management would stay exclusive to the operator key. The official v3.20 recap says the framework ships in v3.20 code with activation expected in v3.21; no delegate registry is active on mainnet yet.

Proposed ADR
ADR / Node OperationsCreated: 2026-07-17Record status: Check develop ADR status and release notes before present-tense claims
Official sourceChecked 2026-08-26·Review due 2026-11-17·
Source: ADR-030 Delegated Node Operator Permissions (develop)
source retrieval details
Source retrieved 2026-08-26Official develop-branch ADR text marked Proposed: per-node delegate registry with MAINT/LEAVE/WHITELIST_BP/SET_FEE permission bits, optional block-offset expiry, non-delegable custody and OPERATOR_ROTATE.
adr-027-revshare

ADR-027 Affiliate Revenue Share (REVSHARE)

Proposed ADR for per-thorname protocol revenue share: operational REVSHARE-<thorname> Mimirs (capped at 5000 bps) would pay attributed swap liquidity fees from reserve system income through AffiliateCollector at end of block. Community reporting says SwapKit accounting is accumulating data ahead of QA; payout configuration and start dates remain unconfirmed.

Proposed ADR; SwapKit accounting reported in progress
ADR / EconomicsCreated: 2026-04-27Record status: Confirm final payout settings and activation from official releases before claims
CuratedChecked 2026-08-26·Review due 2026-10-26·
Source: ADR-027 Affiliate Revenue Share / REVSHARE (develop)
source retrieval details
Source retrieved 2026-08-26Official develop-branch ADR text marked Proposed: per-thorname REVSHARE-<name> operational Mimirs capped at 5000 bps, reserve-funded payouts through AffiliateCollector at end of block.
adr-031-rujira-alignment

ADR-031 THORChain x Rujira Alignment

Official blog post reports that after the initial ADR-020 collaboration period expired, nodes voted on the future of the Rujira cooperation and selected Option 1, confirming and reinforcing it with an updated revenue split. Treat vote mechanics and any payout configuration as source-dated claims until protocol releases confirm them.

Passed per official blog (2026-07-29)
ADR / Ecosystem GovernanceCreated: 2026-07-29Record status: Confirm implementation details from release notes before present-tense payout or App-Layer POL claims
Official sourceChecked 2026-08-26·Review due 2026-11-17·
Source: ADR031 - The Path Forward With Rujira (blog)
source retrieval details
Source retrieved 2026-08-26Official 2026-07-29 post: node vote selected Option 1, confirming the THORChain-Rujira cooperation with an updated revenue split after the initial ADR-020 collaboration period expired.

Milestones

2018

THORChain Founded

A pseudonymous core team founded THORChain in 2018.

HistoricalChecked 2026-07-13·
THORChain FAQ
retrieval details
Source retrieved 2026-07-13Official FAQ source for the 2018 founding year; it does not provide a more precise founding date.
2021-04-13

Multichain Chaosnet Launch

Multichain Chaosnet launches with native cross-chain swaps across five networks while safeguards remain in place on the path to mainnet.

HistoricalChecked 2026-07-13·
THORChain Multichain Chaosnet launch
retrieval details
Source retrieved 2026-07-13Contemporaneous THORChain launch announcement for Multichain Chaosnet on 2021-04-13; the article explicitly describes safeguards and a future path to mainnet.
2024-12-11

THORNode v3.0.0 Release

THORNode v3.0.0 upgrades to Cosmos SDK v0.50 and lays groundwork for future App Layer functionality.

HistoricalChecked 2026-07-13·
THORNode v3.0.0 tag
retrieval details
Source retrieved 2026-07-13Official THORNode release tag created on 2024-12-11 with the v3.0.0 change list.
+1 source
THORChain 2024 year-end report
retrieval details
Source retrieved 2026-07-13Official Q4 report describing the Cosmos SDK v0.50 upgrade as groundwork for future CosmWasm App Layer functionality.
2025-01-04

Savers and Lending Deprecated

Official archived pages say Savers and Lending were permanently deprecated on January 4, 2025, are no longer available, and remain documented only for historical reference.

Official sourceChecked 2026-07-14·
Archived Savers docs
retrieval details
Source retrieved 2026-07-14Official historical Savers mechanics and explicit permanent-deprecation date of 2025-01-04; not current deposit, yield, synth, or redemption instructions.
+1 source
Archived Lending docs
retrieval details
Source retrieved 2026-07-14Official historical Lending mechanics and explicit permanent-deprecation date of 2025-01-04; not current borrow, repay, collateral, or TOR instructions.
2026-05-15

GG20 Vault Exploit and Emergency Halt

Official reports say attackers drained roughly $10M from one vault after an upstream GG20/TSS cryptographic attack. v3.19.0 supplied emergency restart controls, v3.19.1 patched the incident class, and migration away from GG20 remained planned.

Official sourceChecked 2026-07-14·
THORChain Exploit Report #2
retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
+3 sources
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.
THORChain Is Back: Security Update
retrieval details
Source retrieved 2026-07-13Official 2026-06-25 post-restart update confirming trading resumed while DKLS/FROST migration and TSS-library publication remained future work.
2026-08-26

THORNode v3.20.0 Upgrade

The official v3.20.0 tag notes a proposed block of 27,580,000 on 25-Aug-2026, a private binary with security patches, the ADR-028 residual migration (Migrate17to18), TSS/Bifrost hardening, memoless ERC-20 work, and XMR/ZEC chain-client updates. The blog recap adds churn resumption prep, operational POL System Income and Asset Whitelist Mimirs, and an experimental Stable Reserve shipping disabled.

Official sourceChecked 2026-08-26·
THORNode v3.20.0 Release Notes (GitLab)
retrieval details
Source retrieved 2026-08-26Official v3.20.0 release notes plus blog recap: proposed block 27580000 on 25-Aug-2026, private binary, TSS/Bifrost hardening, memoless ERC20 work, XMR/ZEC chain clients, churn resumption prep, operational POL Mimirs, and the Stable Reserve experiment (ships disabled).

Security Incidents

Showing 6 of 6 incident records. Filter by posture before turning a dated incident into a current recovery or safety claim.

ETH Router Exploit #1

Resolved

ETH router/Bifrost exploit where an attack contract in front of the router caused fake ETH deposits to be read as real deposits. Approximately $8M impact; the post-mortem says no other chains or assets were affected.

Dated resolved incident record; still use current diagnostics for present-tense safety claims.

Deposit-event parsing needed stricter validationUnaudited ETH Bifrost code created unacceptable router riskSolvency checks and active monitoring became explicit recovery priorities
HistoricalChecked 2026-07-08·Review due 2026-11-17·
Source: ETH Router exploit post-mortem
source retrieval details
Source retrieved 2026-07-08Historical THORChain post-mortem for early ETH router incidents; not current router availability evidence.
Incident source

ETH Router Exploit #2

Resolved

Second ETH router exploit where a fake router and malicious deposit event path caused real ERC-20 refunds from the system. Approximately $8M across economically significant ERC-20 assets, followed by a broader recovery and audit plan.

Dated resolved incident record; still use current diagnostics for present-tense safety claims.

Return-to-trading needed explicit safety gates and halt controlsRouter changes required deeper adversarial validationOutbound throttling, node timeouts, and audit coverage became part of the response plan
HistoricalChecked 2026-07-08·Review due 2026-11-17·
Source: ETH Router exploit post-mortem
source retrieval details
Source retrieved 2026-07-08Historical THORChain post-mortem for early ETH router incidents; not current router availability evidence.
Incident source

THORFi Unwind

Historical open record

Savers and Lending were deprecated and moved to archived documentation after THORFi liability concerns. Deprecated Savers and Lending products; Proposal 6 and current TCY docs establish the recovery-token mechanics, but do not prove par recovery or that every claimant was made whole.

Kept in the archive as unresolved historical context; not promoted to current recovery status without re-review.

Experimental yield and lending features need explicit solvency and liability framing
Official sourceChecked 2026-07-13·Review due 2026-11-17·
Source: Archived Savers and Lending docs
source retrieval details
Source retrieved 2026-07-05Official archived feature index marking Savers and Lending as deprecated, no longer available, and preserved only for historical reference.
+3 sources
THORFi Unwind Announcement
retrieval details
Source retrieved 2026-07-05Dated THORFi unwind postmortem with January-February 2025 liability, pause, and Proposal 6 milestones; its implementation-status section is historical, not current TCY availability proof.
RUNE and TCY tokenomics
retrieval details
Source retrieved 2026-07-05Official RUNE and TCY tokenomics overview, including TCY supply, revenue share, and no-governance-rights caveat; current amounts and distributions still require live evidence.
TCY Developer Guide
retrieval details
Source retrieved 2026-07-05Developer-facing TCY mechanics, claim, staking, and recovery caveats, including the explicit warning that full debt recovery is market dependent and not guaranteed.
Incident source

Post-Bybit Laundering Flow

Historical open record

THORChain saw controversial post-exchange-hack flow; this was not a THORChain protocol exploit. High-volume illicit-flow and interface-policy debate rather than a protocol drain.

Kept in the archive as unresolved historical context; not promoted to current recovery status without re-review.

Separate protocol exploits from illicit usage of open infrastructureUse precise source-backed labels
Needs reviewChecked 2026-07-08·Review due 2026-11-17·
Source: TRM Labs Bybit laundering update
source retrieval details
Source retrieved 2026-07-08Third-party illicit-flow analysis; this is not a THORChain protocol exploit source.
Incident source

GG20 Vault Exploit

Current tracker

Exploit Report #2 describes a cryptographic GG20/TSS attack: a validator planted malformed Paillier key material and used repeated failed MTA rounds to leak key-share fragments before signing alone. Approximately $10M-$10.7M drained from one vault; normal signing and fund movements resumed after v3.19.1 verification, while migration away from GG20 remains planned and current vault safety still needs live evidence.

Promoted to the current recovery tracker above; pair this dated record with live diagnostics.

Monitor validator-level key-sign failures instead of relying only on solvency outflow detectionGG20/Paillier migration wording should stay tied to dated official reportsDo not describe EdDSA chains as exposed to this specific GG20 attack path
Official sourceChecked 2026-07-13·Review due 2026-11-17·
Source: THORChain Exploit Report #2
source retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
+4 sources
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Is Back: Security Update
retrieval details
Source retrieved 2026-07-13Official 2026-06-25 post-restart update confirming trading resumed while DKLS/FROST migration and TSS-library publication remained future work.
ADR-028 Exploit Conciliation (v3.19.0)
retrieval details
Source retrieved 2026-07-13Immutable v3.19.0 source marking ADR-028 Accepted and specifying the one-time Migrate15to16 conciliation waterfall; not proof that every affected user recovered every loss.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.
Incident source

Memoless Transaction Halt Cycle

Current tracker

Community reporting and live Mimir snapshots show a memoless halt, re-enable with a raised transaction cost (MEMOLESSTXNCOST=200000), a spam-driven re-halt, and HALTMEMOLESS=1 active after the v3.20.0 upgrade. The official release notes include memoless ERC-20 handler and refund work in the same window. Memoless flows were repeatedly unavailable for roughly five days; ordinary memo-based swaps continued when global trading controls were clear. Current state remains a Mimir snapshot question.

Promoted to the current recovery tracker above; pair this dated record with live diagnostics.

A cost vote alone did not stop the spam; the halt key stayed the effective control.Read HaltMemoless as scoped: it blocks memoless handling, not every swap route.Treat MEMOLESSTXNCOST as a parameter snapshot that can be re-voted after an incident.
CuratedChecked 2026-08-26·Review due 2026-09-25·
Source: THORNode v3.20.0 Release Notes (GitLab)
source retrieval details
Source retrieved 2026-08-26Official v3.20.0 release notes plus blog recap: proposed block 27580000 on 25-Aug-2026, private binary, TSS/Bifrost hardening, memoless ERC20 work, XMR/ZEC chain clients, churn resumption prep, operational POL Mimirs, and the Stable Reserve experiment (ships disabled).
+1 source
Liquify THORNode Mimir endpoint
retrieval details
Source retrieved 2026-07-13Current-only Liquify operational controls; malformed or regionally stale values must not be treated as inactive.
Incident source

Research

Dated analysis and roadmap context. Treat these as period framing until current protocol, route, or recovery sources agree.

2025-04-24 · Messari · Drexel Bakker

THORChain Q1 2025 Brief

Quarterly analysis covering affiliate volume, TVL, RUNE price performance, swap activity, and THORFi liabilities.

CuratedChecked 2026-07-08·
Messari THORChain Q1 2025 Brief
retrieval details
Source retrieved 2026-07-08Third-party quarterly research brief; use as historical analysis, not live protocol state.
Research source

2025-07-09 · Nine Realms · Nine Realms

THORChain Q2 2025 Ecosystem Report & Q3 Roadmap

Ecosystem report with Q3 roadmap priorities and development updates.

CuratedChecked 2026-07-08·
Nine Realms Q2 2025 Ecosystem Report
retrieval details
Source retrieved 2026-07-08Ecosystem report and roadmap context from Nine Realms; roadmap items are not current delivery proof.
Research source

2024-10-07 · Nine Realms · Nine Realms

THORChain Q3 2024 Ecosystem Report

Quarterly ecosystem report covering protocol performance, development milestones, and community initiatives.

CuratedChecked 2026-07-08·
Nine Realms Q3 2024 Ecosystem Report
retrieval details
Source retrieved 2026-07-08Historical ecosystem report from Nine Realms; use for period context, not current protocol state.
Research source