GoPlus Security is making a pointed argument: if your protocol can block transactions but chooses not to, calling yourself “decentralized like Bitcoin” is a stretch.
The blockchain security firm publicly challenged THORChain’s decentralization narrative on September 26, pointing out that the cross-chain swap protocol’s threshold signature scheme (TSS) vaults give active validators shared control over outbound transfers. That’s a meaningful structural difference from Bitcoin or Ethereum, where users hold their own private keys and no validator committee can collectively freeze or halt fund movements.
The Bitget hack fallout
The critique didn’t arrive in a vacuum. It landed one day after the Bitget exchange hack, which resulted in losses of roughly $387.5 million. Stolen assets quickly found their way through THORChain’s infrastructure, and GoPlus identified what it called “highly likely DPRK-linked” activity in the flow.
The numbers GoPlus flagged are specific: approximately 101.5 BTC, valued at about $8.5 million, and around 27.63 million XRP worth approximately $43 million were processed through THORChain during the incident.
The decentralization debate
THORChain operates as a cross-chain liquidity protocol, using its native token RUNE and a validator set of around 100 nodes to manage multi-chain TSS vaults. The architecture lets users swap assets across different blockchains without centralized intermediaries. Proponents have long compared it to base-layer protocols like Bitcoin and Ethereum, arguing it represents genuinely decentralized infrastructure.
GoPlus’s argument cuts at the foundation of that comparison. In Bitcoin and Ethereum, no group of validators can collectively decide to halt a specific user’s outbound transfer. THORChain’s TSS model, by contrast, requires active validator participation in signing transactions. That means validators can, in theory, refuse to sign.
The protocol’s governance system reinforces this point. THORChain uses a mechanism called Mimir that allows parameter changes and emergency halts. According to GoPlus, these halts require a threshold of 3 or more validators to enact and 4 or more to reverse. Past attempts to block DPRK-linked flows through this mechanism have actually been enacted, only to be reversed afterward.
GoPlus isn’t the only voice raising this concern. OKX founder Star Xu has also questioned THORChain’s decentralization credentials, highlighting the risks inherent in collective control of TSS vaults versus the individual key custody that defines truly permissionless networks.
A billion-dollar pattern
The Bitget hack is not THORChain’s first brush with North Korean-linked laundering. Since at least 2023, the protocol has processed what multiple trackers estimate at over $1 billion in funds attributed to DPRK operations. The typical pattern involves converting stolen ETH into BTC, using THORChain’s cross-chain capabilities as the bridge.
THORChain’s defenders argue that blocking specific transactions would compromise the protocol’s neutrality and set a precedent that transforms validators into compliance officers. GoPlus is essentially saying: you can’t have it both ways. You can’t claim to be as permissionless as Bitcoin while operating a system where a committee of 100 nodes jointly custodies assets and actively signs every outbound transfer.
The distinction matters because regulatory frameworks increasingly differentiate between protocols based on their actual architecture, not their marketing. A system where validators can collectively halt transactions looks a lot more like a financial intermediary than a base-layer blockchain, regardless of what the documentation says.
Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

3 hours ago
24









English (US) ·