Skip to content

Network & Security

THORChain secures cross-chain assets through bonded node operators, threshold signatures, Mimir-controlled operations, solvency checks, and economic penalties.

Checking live network status

Fetching THORNode Mimir, inbound-address, version, and block evidence.

Loading live source...

Look here first

Ordinary swaps

Checking

Limited chains

Unavailable

Other operations

Unavailable

Data quality

Pending

Node operator actions

Current Mimir controls for bonding, unbonding, rebonding, and operator rotation. These action gates are separate from ordinary swaps and LP availability.

current-only
CheckingNode operation controls are not available

Waiting for current THORNode Mimir controls for bonding, unbonding, rebonding, and operator rotation.

This panel is about network-level action gates. It does not prove a specific node can leave safely; node state, churn timing, slash points, and operator tooling still matter.

Check A Route

On-demand THORNode quote probe. It uses Midgard available pools plus native RUNE as route choices, does not collect a wallet address, and is not a send instruction.

Loading live source...

Network status unavailable

Live THORNode status has not loaded.

Refund / failed swap triage

Refund diagnosis: insufficient evidence

Run a fresh quote probe and compare it with the actual quote flow, memo, inbound transaction, and any refund transaction before naming a cause.

Triage guide

Current quote result

Missing

No quote has been checked for this selected route and amount.

Live route blockers

Missing

Live THORNode status has not loaded.

Amount threshold

Missing

Need the quote minimum amount and the inbound chain dust threshold before blaming amount size.

Same quote-flow inputs

Missing

Need the inbound address or router, memo, and expiry from the same fresh quote flow. This wiki does not create wallet send instructions.

Transaction and refund proof

Missing

Need the inbound transaction hash, observed memo, source and destination chains, and any refund or outbound transaction before assigning a refund cause.

Result discipline: current quotes and halts can narrow the investigation, but a specific refund cause requires the actual transaction evidence.

Current Operation Snapshot

Additional context for node counts, operator constants, and grouped operation gates. Open when you need the secondary view.

Additional context

Grouped by the decision a reader is trying to make. Swap execution, LP actions, recovery rails, and App Layer controls are deliberately separated so one paused rail does not look like a global swap halt.

Node set

Midgard

Live Midgard counts for validator-set shape. These are not a node-health audit.

Active nodes

Validators currently in the active set.

Unavailable

Standby nodes

Candidates available for future churn.

Unavailable

Consensus threshold

Static threshold framing; verify live node state for incidents.

2/3+

Operator constants

Static + THORNode

Do not freeze these as static facts; constants and Mimir can change live.

Minimum bond

Check constants + Mimir

Slash rate

Check constants + Mimir

Churn interval

Check constants + Mimir

Swap execution

THORNode

The controls most likely to affect whether an ordinary swap can route or settle.

Trading

Checking

Signing

Checking

Chain observation

Checking

Manual synth swaps

Checking

Liquidity actions

THORNode

LP, deposit, loan, and asym controls are separate from ordinary swap execution.

LP actions

Checking

Pool deposits

Checking

Asym withdrawals

Checking

Loans

Checking

TCY and RUNEPool

THORNode

Recovery and RUNEPool rails can be paused independently from swaps.

TCY claims

Checking

TCY claim swaps

Checking

TCY staking

Checking

TCY distributions

Checking

TCY unstaking

Checking

TCY trading

Checking

RUNEPool

Enablement flag only; deposit, withdrawal, maturity, and wallet paths are separate checks.

Checking

RUNEPool deposits

Checking

RUNEPool withdrawals

Checking

App and asset rails

THORNode

Secured assets, trade accounts, bank sends, and WASM/app-layer controls need scoped live checks.

Secured assets

Checking

Trade accounts

Feature flag only; route, asset, and interface support need separate proof.

Checking

Trade deposits

Deposit enablement flag only; not wallet or route instructions.

Checking

WASM/app layer

Checking

Bank sends

Bank module send flag only; not transaction safety or app-layer support.

Checking

Midgard node-count source

Loading live source...

THORNode operation-state source

Loading live source...

Page Source Posture

CuratedChecked 2026-07-14·Review due 2026-08-14·
THORChain Docs
retrieval details
Source retrieved 2026-07-05Official documentation root used for curated protocol background; it still describes GG20 at review time, but current safety and migration state require dated incident and release sources.
+10 sources
THORNode node operations
retrieval details
Source retrieved 2026-07-14Official node lifecycle and churn reference for Whitelisted, Standby, Ready, Active, and Disabled status, churn-out criteria, and the Standby-only unbond boundary.
Leaving THORChain as a node operator
retrieval details
Source retrieved 2026-07-14Official LEAVE and UNBOND procedure reference; a node must be Standby and outside vault migration before unbonding, and the original operator address controls the action.
Managing THORNodes
retrieval details
Source retrieved 2026-07-05Official node operations guidance for slash troubleshooting, sync checks, and operational risk.
THORNode risks, costs and rewards
retrieval details
Source retrieved 2026-07-05Official node-operator source for slash points, bond rewards, operator fees, and node reward mechanics.
THORNode Bifrost transaction flow
retrieval details
Source retrieved 2026-07-14Pinned official THORNode source-tree snapshot for observer/signer roles, Active and Retiring vault observations, 67% consensus, finality, re-orgs, and outbound evidence.
THORNode vault behaviors
retrieval details
Source retrieved 2026-07-14Pinned official THORNode source-tree snapshot for physical-vault lifecycle, inbound-vault selection, migration, and the distinction between slash points and bond-principal slashing.
THORChain Network Halts
retrieval details
Source retrieved 2026-07-05Official halt-control reference; live Mimir and inbound-address reads still own current availability.
THORChain Exploit Report #2
retrieval details
Source retrieved 2026-07-04Official root-cause report for the May 2026 GG20/TSS vault exploit, patched v3.19.1 recovery, and still-planned migration away from GG20.
Protocol Upgrade v3.19.0
retrieval details
Source retrieved 2026-07-04Official v3.19.0 release summary for post-exploit restart controls, including TSS patches, compromised-vault exclusion, temporary KeyVerify, and pause safety.
THORChain Exploit Report #1
retrieval details
Source retrieved 2026-07-05Official initial May 2026 exploit timeline and then-pending ADR-028 recovery framing; use Report #2 and the accepted ADR for later root-cause and conciliation status.

Node lifecycle, churning, slashing, vault security, and live operational state.

Use This Page For

  • Current operational diagnostics, halt controls, node/security concepts, and source-warning posture.
  • Separating live THORNode/Midgard evidence from dated security reports and static protocol explanations.

Verify Elsewhere Before Claiming

  • That a paused operation, chain, signing path, LP action, TCY control, or app-layer feature is available right now.
  • That historical incident reports prove present-day safety, solvency, signing availability, or route quality.

Use these before turning current dashboard values into a broader claim.

current-only

Node Operator Guide

Use this as an orientation map before acting. Official operator docs explain setup and maintenance, while this page separates current controls, node lifecycle, bond risk, and rewards context so a guide search does not look like live action proof.

official docs

Setup and maintenance

Start from the official operator runbook for setup, sync, troubleshooting, and maintenance details. Treat local wiki text as a source map, not installation instructions.

Managing THORNodes
current controls

Bond, unbond, and rotate checks

Use live diagnostics for PauseBond, PauseUnbond, HaltRebond, HaltOperatorRotate, source warnings, and the boundary around whether a specific node can act now.

Check node-operation controls
context

Lifecycle and leaving

Whitelisted, Standby, Ready, Active, and Disabled are distinct states. Only a Standby node outside vault migration may unbond; current state still needs direct node evidence.

context

Rewards and slash exposure

Slash points reduce rewards; separately defined security events can slash bond principal. Documentation examples do not prove a node's current balance, parameters, or incident outcome.

THORNode risks, costs and rewards

Node Types

Whitelisted

Bonded, but required node keys have not yet been set; operator setup is incomplete.

Standby

Bonded but not active. Current requirements are evaluated during churn; only Standby nodes outside vault migration may unbond.

Ready

Passed current preflight requirements and is eligible for churn selection; a node cannot unbond while Ready.

Active

Participates in consensus, observation, and signing; it cannot unbond until churned to Standby and clear of vault migration.

Disabled

Completed the permanent-leave path while Standby and cannot rejoin with the same node account.

Security Architecture

Threshold Signatures

Distributed signing protects vault keys, but implementation details and migration status should stay tied to dated source material.

Solvency Checks

Nodes monitor vault balances and can trigger halts when observed balances diverge from expected protocol state.

Operational Mimir

Emergency parameters can halt trading, signing, churning, chain observation, LP actions, TCY claims, and more.

Bonded Operators

Operators bond RUNE as economic security. Minimum bond and slash constants can be overridden by Mimir.

Slash Points

Nodes can accrue slash points for missed observations or signing failures, affecting churn and rewards.

Churning

Validator rotation and vault rotation reduce long-lived key exposure; exact intervals are live constants or Mimir overrides.