Governance & History
ADRs, Mimir context, milestones, incidents, and research. Vote percentages are shown only when source-backed.
Page Source Posture
retrieval details
+6 sources
retrieval details
retrieval details
retrieval details
retrieval details
retrieval details
retrieval details
ADRs, operational Mimir, incidents, milestones, and sourced research.
Use This Page For
- Source-backed ADR, Mimir, incident, milestone, and recovery-history context.
- Dated incident and governance records with explicit current-review labels.
Verify Elsewhere Before Claiming
- Current node consensus, live Mimir values, active recovery status, or final governance outcome.
- That a historical incident record proves present-day network safety or solvency.
Continue From Here
Move from dated governance and incident records into current diagnostics, recovery review, or the historical recovery path before making present-tense claims.
Governance Claim Checks
Start with the claim type. Governance records are useful for dated decisions and history; live controls, incident root-cause wording, recovery status, and community interpretation need separate proof paths.
Operational Mimir claim
- Use For
- Whether trading, signing, LP actions, churning, TCY controls, or chain operations are active now.
- Verify
- Use Network diagnostics and current THORNode/Mimir evidence before using present-tense availability wording.
- Do Not Claim
- Do not infer live availability from a proposal, incident archive, milestone, or missing halt mention.
ADR or proposal status
- Use For
- What an ADR, proposal, milestone, or governance record said at the cited review point.
- Verify
- Use the record source, source-map guidance, and any linked live tracker before calling a design active.
- Do Not Claim
- Do not treat proposed, draft, needs-review, or historical records as final live protocol behavior.
Incident root-cause claim
- Use For
- Exploit cause, affected vault/chain scope, patch wording, migration context, and dated security lessons.
- Verify
- Use incident reports plus the Network Security path before summarizing safety or cryptographic details.
- Do Not Claim
- Do not convert a dated exploit report, restart, or patch into proof of present-day safety.
Recovery or solvency claim
- Use For
- Post-exploit recovery state, THORFi/TCY recovery framing, and records tagged for current review.
- Verify
- Use the current recovery tracker, TCY recovery timeline, dated upgrade notes, and live diagnostics together.
- Do Not Claim
- Do not claim final recovery, par redemption, current solvency, or product availability from one record.
Community sentiment claim
- Use For
- Debate topics, open questions, or how contributors described tradeoffs in community channels.
- Verify
- Use community sources only as context, then confirm protocol facts through official or live sources.
- Do Not Claim
- Do not present Discord chatter as canonical protocol proof or representative sentiment without sampling.
Current Incident & Recovery Tracker
Conservative tracker for records explicitly tagged as current or needing current recovery review. Historical unresolved records remain in the incident archive below unless they are re-verified for current tracking.
Tracked records
2
Current or needs-review records promoted from the full governance and incident archive.
Evidence path
Record + live check
Use the full dated record first, then current Network diagnostics before present-tense claims.
Non-claim
Not final recovery proof
Tracker inclusion does not prove solvency, restitution, product availability, or completion.
Recovery State Matrix
Separate the historical debt unwind, post-exploit recovery review, and live user-action checks before using recovery language.
THORFi debt unwind
- State
- Deprecated products, TCY framing, and historical-open liabilities belong in dated THORFi and TCY records.
- Evidence
- Use archived Savers/Lending docs, Proposal 6/TCY sources, and the TCY recovery timeline.
- Boundary
- No made-whole proof, current Savers/Lending availability, or deposit/borrow instruction.
GG20 exploit recovery
- State
- The v3.19.x restart and accepted ADR-028 conciliation are separate from the earlier THORFi debt unwind and from the still-planned migration away from GG20.
- Evidence
- Use exploit reports, v3.19 upgrade notes, the immutable accepted ADR-028 source, and full incident records.
- Boundary
- No final recovery-complete or present-day safety proof.
Current user actions
- State
- TCY claim, stake, distribution, unstake, claim-swap, and trading state are live-control questions.
- Evidence
- Use Network diagnostics, TCY controls, official interface evidence, and source warnings.
- Boundary
- No user eligibility, redemption value, or transaction-success proof.
Check Before Claiming
Savers or Lending are available now
- Start with
- Archived feature sources
- Verify
- Official archived docs and any current interface/source claiming reactivation.
- Do not claim
- Do not describe archived mechanics as current deposit or borrowing instructions.
Check Before Claiming
A claimant can claim or stake TCY right now
- Start with
- TCY timeline plus live network diagnostics
- Verify
- TCY guide, official claim interface, and TCY Mimir controls such as TCYCLAIMINGHALT or TCYSTAKINGHALT.
- Do not claim
- Do not infer availability from historical TCY launch copy alone.
Check Before Claiming
TCY restored the original debt value
- Start with
- TCY source caveats
- Verify
- Market and distribution evidence outside this tracker; official developer docs say full recovery is not guaranteed.
- Do not claim
- Do not state par recovery, redemption value, or investment outcome as fact.
Check Before Claiming
Post-exploit recovery is complete
- Start with
- Current recovery tracker records
- Verify
- Dated exploit reports, upgrade notes, ADR/proposal status, and live network diagnostics.
- Do not claim
- Do not convert a restart, patch, or proposal into proof of final recovery completion.
Safe current wording
The GG20 exploit record remains a current security tracker, while ADR-028 is now source-backed as Accepted and implemented through the one-time v3.19.0 conciliation migration. Use this section to decide what to verify next; neither record proves every loss was restored, final recovery, current vault safety, or user-action availability.
Incident record
GG20 Vault Exploit
Exploit Report #2 describes a cryptographic GG20/TSS attack: a validator planted malformed Paillier key material and used repeated failed MTA rounds to leak key-share fragments before signing alone.
Approximately $10M-$10.7M drained from one vault; normal signing and fund movements resumed after v3.19.1 verification, while migration away from GG20 remains planned and current vault safety still needs live evidence.
- Use This For
- Dated official exploit, restart, patch, and migration context for the May 2026 GG20 vault incident.
- Verify Next
- - Network diagnostics for current halts, signing, route limits, and source warnings.
- - Security deep dives for the dated GG20/TSS attack scope and migration wording.
- - TCY controls only when the claim is about current claim, stake, distribution, unstake, or trade actions.
- Do Not Use This For
- Do not use the incident record, restart, or v3.19 notes as proof that recovery is complete, users are made whole, or present-day safety is guaranteed.
retrieval details
+4 sources
retrieval details
retrieval details
retrieval details
retrieval details
Governance record
ADR-028 Recovery Path
ADR-028 is Accepted in the v3.19.0 source and specifies a one-time conciliation migration for exploit-created accounting gaps; that allocation decision is not proof that every loss was restored.
Accepted; implemented in v3.19.0
- Use This For
- Accepted ADR-028 decision and one-time v3.19.0 conciliation migration for the May 2026 exploit-created accounting gap.
- Verify Next
- - The immutable v3.19.0 ADR before describing its reserve, Saver, treasury, or stuck-swap allocation waterfall.
- - Current release and Network diagnostics before converting the historical migration into present protocol availability or safety.
- - TCY controls and official interface evidence before saying a user can claim, stake, trade, or receive distributions now.
- Do Not Use This For
- ADR-028 acceptance proves the conciliation decision and migration design, not that every loss was restored, recovery is complete, current vaults are safe, or any user action is enabled.
retrieval details
+3 sources
retrieval details
retrieval details
retrieval details
Dated Archive Map
Use the lane map before diving into the archive. Counts are navigation aids, not health scores, and every lane still needs the claim-specific checks above.
Current recovery lane
Start here for records explicitly promoted from the archive into current recovery review.
- Archive mix
- promoted records
- First check
- Pair each record with live diagnostics before present-tense claims.
Governance records lane
Use for ADRs, operational parameters, recovery-path records, and historical unwind context.
- Archive mix
- 2 operational/current-only
- First check
- Read the record status before treating an ADR, Mimir item, or proposal as live behavior.
Incident archive lane
Use for exploit root-cause, illicit-flow, and recovery-history records without flattening them into today.
- Archive mix
- 2 current/review, 2 historical-open
- First check
- Use the posture badge first: resolved, current tracker, needs review, or historical open.
Research and milestones lane
Use for timeline context and third-party or ecosystem analysis before checking current evidence.
- Archive mix
- 5 milestones, 3 reports
- First check
- Good for period framing; not enough for current protocol, route, or recovery claims.
Governance Records
Dated governance and operational records. The status badge describes the record evidence posture; use live diagnostics before turning it into a current action claim.
THORFi Unwind
Deprecation and unwind process for Savers and Lending liabilities.
source retrieval details
+3 sources
retrieval details
retrieval details
retrieval details
ADR-028 Recovery Path
ADR-028 is Accepted in the v3.19.0 source and specifies a one-time conciliation migration for exploit-created accounting gaps; that allocation decision is not proof that every loss was restored.
source retrieval details
+3 sources
retrieval details
retrieval details
retrieval details
Operational Mimir Halts
Operational Mimir parameters such as HALTTRADING and HALTSIGNING can pause network activity and should be read from THORNode.
source retrieval details
+1 source
retrieval details
ADR-026 Dynamic L1 Fees
Dynamic per-thorname and per-pair L1 minimum fee experiment. Official ADR text is proposed-design context while live THORNode snapshots may show enabled Mimirs and dynamic-fee records.
source retrieval details
+3 sources
retrieval details
retrieval details
retrieval details
Milestones
THORChain Founded
A pseudonymous core team founded THORChain in 2018.
retrieval details
Multichain Chaosnet Launch
Multichain Chaosnet launches with native cross-chain swaps across five networks while safeguards remain in place on the path to mainnet.
retrieval details
THORNode v3.0.0 Release
THORNode v3.0.0 upgrades to Cosmos SDK v0.50 and lays groundwork for future App Layer functionality.
retrieval details
+1 source
retrieval details
Savers and Lending Deprecated
Official archived pages say Savers and Lending were permanently deprecated on January 4, 2025, are no longer available, and remain documented only for historical reference.
retrieval details
+1 source
retrieval details
GG20 Vault Exploit and Emergency Halt
Official reports say attackers drained roughly $10M from one vault after an upstream GG20/TSS cryptographic attack. v3.19.0 supplied emergency restart controls, v3.19.1 patched the incident class, and migration away from GG20 remained planned.
retrieval details
+3 sources
retrieval details
retrieval details
retrieval details
Security Incidents
Showing 5 of 5 incident records. Filter by posture before turning a dated incident into a current recovery or safety claim.
ETH Router Exploit #1
ResolvedETH router/Bifrost exploit where an attack contract in front of the router caused fake ETH deposits to be read as real deposits. Approximately $8M impact; the post-mortem says no other chains or assets were affected.
Dated resolved incident record; still use current diagnostics for present-tense safety claims.
source retrieval details
ETH Router Exploit #2
ResolvedSecond ETH router exploit where a fake router and malicious deposit event path caused real ERC-20 refunds from the system. Approximately $8M across economically significant ERC-20 assets, followed by a broader recovery and audit plan.
Dated resolved incident record; still use current diagnostics for present-tense safety claims.
source retrieval details
THORFi Unwind
Historical open recordSavers and Lending were deprecated and moved to archived documentation after THORFi liability concerns. Deprecated Savers and Lending products; Proposal 6 and current TCY docs establish the recovery-token mechanics, but do not prove par recovery or that every claimant was made whole.
Kept in the archive as unresolved historical context; not promoted to current recovery status without re-review.
source retrieval details
+3 sources
retrieval details
retrieval details
retrieval details
Post-Bybit Laundering Flow
Historical open recordTHORChain saw controversial post-exchange-hack flow; this was not a THORChain protocol exploit. High-volume illicit-flow and interface-policy debate rather than a protocol drain.
Kept in the archive as unresolved historical context; not promoted to current recovery status without re-review.
source retrieval details
GG20 Vault Exploit
Current trackerExploit Report #2 describes a cryptographic GG20/TSS attack: a validator planted malformed Paillier key material and used repeated failed MTA rounds to leak key-share fragments before signing alone. Approximately $10M-$10.7M drained from one vault; normal signing and fund movements resumed after v3.19.1 verification, while migration away from GG20 remains planned and current vault safety still needs live evidence.
Promoted to the current recovery tracker above; pair this dated record with live diagnostics.
source retrieval details
+4 sources
retrieval details
retrieval details
retrieval details
retrieval details
Research
Dated analysis and roadmap context. Treat these as period framing until current protocol, route, or recovery sources agree.
2025-04-24 · Messari · Drexel Bakker
THORChain Q1 2025 Brief
Quarterly analysis covering affiliate volume, TVL, RUNE price performance, swap activity, and THORFi liabilities.
retrieval details
2025-07-09 · Nine Realms · Nine Realms
THORChain Q2 2025 Ecosystem Report & Q3 Roadmap
Ecosystem report with Q3 roadmap priorities and development updates.
retrieval details
2024-10-07 · Nine Realms · Nine Realms
THORChain Q3 2024 Ecosystem Report
Quarterly ecosystem report covering protocol performance, development milestones, and community initiatives.