THORChain Responds to Allegations of Assisting Stolen Funds Transfer: Decentralization Shouldn’t Be a Get-Out-of-Jail-Free Excuse
The core of this controversy isn’t really whether THORChain is decentralized, but whether “decentralization” can serve as an excuse for handling risk funds without responsibility.
THORChain’s design is indeed different from centralized exchanges: there is no single company controlling the protocol, cross-chain transactions are executed collectively by nodes, and the protocol itself can’t directly freeze or reverse user assets the way an exchange can. But the issue lies precisely here—when stolen funds enter a cross-chain protocol, “inability to control” from a technical standpoint and “whether it should be held accountable” from an industry perspective are entirely different questions.
Earlier, security organizations had already documented cases where stolen assets were used via THORChain to cross-chain exchange and alter the path of funds, suggesting that cross-chain DEXs can naturally become critical infrastructure for hackers to move funds.
Even more noteworthy is that in May this year, THORChain itself suffered an attack of roughly $10.7 million. The official disclosure said the attacker exploited a vulnerability in a GG20 threshold signature scheme to withdraw an asset from a vault. The protocol then paused part of—up to and including network-wide—operations through automatic solvency checks and manual governance mechanisms. This means THORChain has already demonstrated that “complete inability to intervene” is not accurate: even under specific security incidents, the protocol still has mechanisms to pause, upgrade, and govern.
So what the market should truly focus on this time isn’t simply slapping THORChain with a “laundering for hackers” label, but a more practical question: how decentralized protocols in the future can establish risk identification, node governance, and emergency response mechanisms for clearly stolen funds without undermining their anti-censorship attributes.
For RUNE, in the short term the market may first trade on “regulatory risk + reputational risk.” If the dispute continues to intensify, funds may further price in a risk premium tied to THORChain’s compliance and security costs. But if the team can present clear boundaries for fund identification and governance, the incident could instead be converted into an upgrade of its security mechanisms.
In one sentence: decentralization addresses “who controls the protocol,” but it doesn’t automatically resolve “what responsibility the protocol should bear.” That may be the issue for cross-chain DEXs going forward that they can’t avoid.