GoPlus Security is calling out THORChain for trying to wear Bitcoin’s censorship-resistant cape while still keeping a giant pause button under the desk.
- GoPlus says THORChain can stop flows when it wants.
- The dispute is tied to the Bybit hack and a separate Bitget breach.
- THORChain’s own emergency controls proved they exist during a May exploit.
- The real issue is whether “decentralized” still means permissionless.
On Sept. 27, GoPlus Security said THORChain should not compare its cross-chain architecture directly with decentralized layer-1 networks like Bitcoin or Ethereum when arguing that stolen funds cannot be blocked. The security firm pointed to THORChain’s threshold-signature vaults, active validator set, and emergency governance controls as evidence that operators do have meaningful levers.
That criticism lands because the protocol is not just hypothetical infrastructure. It sits in the middle of two major laundering waves: the February 2025 Bybit hack, which the FBI blamed on North Korea, and the September Bitget breach, where GoPlus says attacker-linked funds have also been moving through THORChain.
Let’s be blunt: a protocol with emergency pause tools is not the same animal as Bitcoin. That does not make it fake decentralized. It does make the “nobody can stop this” marketing a lot harder to defend.
THORChain is a cross-chain liquidity protocol designed to move assets between blockchains without relying on the usual wrapped-asset setup. That makes it useful. It also makes it a magnet for exploiters, laundering crews, and every opportunist who wants to turn stolen coins into something harder to trace.
And that is where the tension starts. THORChain’s published emergency procedures allow validators to trigger a make pause command when funds face a critical threat. One pause lasts 720 blocks, or roughly one hour, and additional nodes can extend the halt. Node operators can also use Mimir, THORChain’s on-chain parameter system, to vote on trading halts, chain-specific stops, and signing controls.
In plain English: THORChain is not just passive code. It has governance levers. Useful in an emergency, yes. But not exactly the same thing as a base layer that cannot be switched off by a coordinated operator set.
THORChain’s own May incident makes that obvious. On May 15, a malicious validator exploited weaknesses in its GG20 Threshold Signature Scheme and reconstructed the private key for one Asgard vault. Roughly $10.7 million was drained before the network fully stopped.
According to THORChain’s exploit report, automatic solvency monitoring first detected irregular vault balances and halted signing and trading on several chains. Roughly 18-20 validators stacked pause commands during the response, and a complete controlled halt was reached within about two hours after the alarm was raised. The network stayed offline for roughly five weeks before trading resumed on June 23, after patched signing code, vault checks, and governance-approved recovery procedures were put in place.
So yes, THORChain can freeze itself. It has done it. That is a feature when a vault is under attack. It is also a problem when the protocol wants to be spoken of in the same breath as Bitcoin, where there is no governance layer with a pause switch waiting for consensus.
The Bybit case sharpened the argument. In February 2025, the FBI said the exchange hack, which it attributed to North Korea and linked to the TraderTraitor campaign, involved about $1.5 billion in stolen virtual assets. The bureau urged exchanges, bridges, RPC operators, DeFi services, and blockchain companies to block transactions involving addresses connected to the stolen funds. RPC operators are the infrastructure providers that wallets and apps use to talk to blockchains and submit transactions.
Bybit CEO Ben Zhou said around 72% of roughly $900 million in converted assets had passed through THORChain. That figure refers to the portion of funds that had already been swapped into other assets, not the full $1.5 billion stolen from Bybit. Crypto.news also reported in March 2025 that attackers converted most of the stolen 499, 000 ETH within ten days, with THORChain handling a large share of the swaps.
Early in that laundering run, THORChain recorded $2.91 billion in trading volume and roughly $3 million in fee revenue over five days, according to on-chain data cited by crypto.news. Those numbers turned a neutral plumbing protocol into a very loud political fight.
Some people saw neutral infrastructure being used neutrally. Others saw a protocol becoming a preferred laundering rail and hiding behind “we’re just code” rhetoric. Both reactions are understandable. One is a little cleaner than the other.
By February, three validators had voted to halt Ethereum trading as the stolen Bybit funds moved through the protocol. Developer Oleg Petrov later said the action was reversed within minutes. Core contributor Pluto said he would stop contributing to THORChain. Validator TCB said he could leave unless the network developed a way to stop North Korean-linked flows.
That is not the sound of a network in harmony. It is the sound of a protocol arguing with itself about what “neutral” should mean when dirty money is moving through the pipes.
THORChain founder John-Paul Thorbjornsen defended continued trading and opposed letting a non-authority third party dynamically update protocol-level deny lists. He said he would support static deny lists based on official OFAC or FBI information if individual operators were comfortable doing so.
That distinction matters. There is a big difference between a static list built from official attribution and an ad hoc censor button controlled by whatever crowd is loudest this week. One is policy. The other is panic with a keyboard.
GoPlus is effectively arguing that if THORChain already has emergency powers, it should use them more aggressively against clearly identified illicit flows. The firm said THORChain could use its existing emergency framework for funds tied to addresses officially identified by agencies such as the FBI or OFAC. It also said THORChain should stop comparing itself directly to layer-1 networks when explaining why stolen funds cannot be blocked.
That comparison is where the whole debate gets real. Bitcoin has no validator set that can coordinate a temporary network pause. That is one reason it remains the strongest example of censorship resistance at the base layer. THORChain is more flexible, more operationally complex, and more exposed to governance pressure. Those are tradeoffs, not bugs, but they are still tradeoffs.
Ethereum sits somewhere else on the spectrum, with its own validator coordination and social-layer realities. But THORChain’s emergency tools still make it a poor stand-in for “fully uncensorable” infrastructure. It is decentralized enough to avoid a single point of custody. It is not decentralized enough to pretend it has no choke points at all.
GoPlus also says roughly 101.5 BTC linked to the Bitget incident had already exited through THORChain, worth around $8.5 million, and that another 27.63 million XRP, valued near $43 million, was being routed toward Bitcoin. The firm’s own calculations put THORChain’s volume at about $5.9 billion and fees at $5.5 million. Those are GoPlus estimates, not THORChain disclosures.
Bitget has not publicly confirmed that North Korean actors carried out its September attack. The exchange said investigators saw preliminary IP and VPN similarities associated with previous North Korean-linked activity, but attribution remained unconfirmed. That distinction should not be waved away. Crypto is full of lazy attribution, and “it looks like North Korea” is not the same thing as proof.
Still, Bitget has raised its confirmed estimate of assets transferred to attacker-controlled addresses to about $387.5 million. The exchange has also begun offering recovery bounties and plans to restore withdrawals in stages from Sept. 28.
So the pressure on THORChain is not just ideological. It is operational. If a protocol can be used to route stolen assets at scale, security firms and exchanges are going to ask why the emergency controls exist if they are not being used. If those controls are used too aggressively, the protocol starts drifting away from the permissionless ethos that made people care about it in the first place.
That is the ugly little tradeoff crypto keeps running into: freedom until a thief shows up, then everyone suddenly discovers they like guardrails. THORChain sits right in the middle of that fight.
Key questions readers are asking
-
Is THORChain as censorship-resistant as Bitcoin?
No. THORChain has validator coordination, emergency pause tools, and on-chain governance mechanisms that can stop or restrict activity. Bitcoin does not have a comparable operational pause layer. -
Does THORChain have the power to freeze activity in emergencies?
Yes. Its documented procedures include a pause command lasting 720 blocks, with extensions possible, plus Mimir-based voting for trading halts, chain-specific stops, and signing controls. -
Does emergency control make THORChain centralized?
Not in the usual corporate sense. It is still a decentralized protocol, but one with enough governance and validator coordination to intervene when the network decides it must. -
Why is GoPlus Security pushing back now?
Because GoPlus says THORChain’s design gives operators enough control to slow or block stolen-fund flows, especially when there is official attribution from agencies like the FBI or sanctions bodies like OFAC. -
What happened in the May THORChain exploit?
A malicious validator exploited weaknesses in the GG20 Threshold Signature Scheme, reconstructed a private key for one Asgard vault, and drained about $10.7 million before the network was fully halted. -
Is North Korean involvement confirmed in the Bitget case?
No. Bitget said there were preliminary IP and VPN similarities to previous North Korean-linked activity, but attribution remains unconfirmed. -
Why do stolen funds keep ending up in cross-chain protocols?
Because swaps and bridges can make stolen assets harder to trace and intervene against. That is useful for legitimate users, and very useful for criminals trying to wash the trail.
The bigger lesson is simple: decentralization is not a slogan, it is a set of tradeoffs. THORChain is not a centrally controlled honeypot, but it is also not Bitcoin. Its own emergency tools prove that difference.
That nuance is uncomfortable for maximalists, compliance hawks, and everyone in between. Too bad. Reality does not care about branding.
Further reading
A few extra sources worth having on hand for the THORChain, laundering, and attribution rabbit hole.
- THORChain decentralization challenged over DPRK flows
- Bybit security incident timeline
- Crypto journalists
- Crypto platform Bitget suspects North Korea in $352 million hack
- THORChain flagged as key laundering route for major crypto hacks
- Lazarus Group profits $2.51M from WBTC sale, launders $1.39B from Bybit hack
- North Korea overtakes El Salvador in Bitcoin holdings after Bybit hack