Layer 1 blockchain
THORChain ticker RUNE
Summary
THORChain (chain ID thorchain-1) is a Cosmos SDK chain with CometBFT consensus run by bonded THORNodes: 99 were active and 59 on standby in a read on 2026-09-29. Every active node gets the same voting power, and a block commits once more than two-thirds precommit it, about every six seconds. Nodes enter by bonding RUNE; at each churn the highest-bonded ready nodes join and departing, oldest or worst-performing nodes leave. The same nodes run Bifrost to watch connected chains and share threshold-signature vaults on them; a vault spends only when about two-thirds of its members sign, and an unauthorized spend is slashed from the members' bonds at 1.5 times its value. Continuous liquidity pools pair each asset with RUNE, so a swap between two chains runs through two pools and is paid out by a vault. 1112222324293031
Design
- System
- Layer 1 blockchainIndependent chain built on the Cosmos SDK with CometBFT consensus and its own bonded node set (THORNodes); it does not settle to another chain. The same nodes also hold coins of connected chains in threshold-signature vaults on those chains and pay swaps out natively, so part of the value THORChain accounts for lives outside its own ledger. Chain ID thorchain-1 since block 17,562,001, after earlier chain IDs thorchain and thorchain-mainnet-v1.
- Settlement family
- Cosmos SDK
- Scarce resource
- Stake (proof of stake)
- State model
- Accounts
- Finality
- Other
- Who makes blocks
- CometBFT rotates proposers in proportion to voting power. THORChain gives every active node the same power (100 in the reviewed code), so proposing rotates evenly across active nodes; bond size decides entry at churn and reward share up to a cap, not proposal weight. Churn normally runs every 43,200 blocks (roughly two and a half to three days), adds at most one net node and removes at most a third of the set. It was paused for more than 60 days after the May 2026 exploit and resumed with v3.20.
- Fork choice
- No open weight-based fork choice: each height is decided by precommits from more than two-thirds of active nodes. If more than a third are offline or disagree the chain stops; THORChain's August 2026 report says the network halted on 26 and 27 August after a node execution mismatch. THORNode's code, in the public v3.20.3 release tag and the develop branch, records double signing as 1,000 slash points (lost rewards) and leaves the bond untouched, while the node docs describe a bond slash. THORChain has twice exported its state and restarted under a new chain ID.
Qualifications
- Finality · Partial. Recorded as other. THORChain's own terms: CometBFT blocks commit with precommits from more than two-thirds of active THORNodes, each holding equal voting power. In THORNode's code (the public v3.20.3 release tag and the develop branch) double signing costs slash points (forgone rewards), not bond, so committed blocks are not backed by stake that equivocation would forfeit; bond is slashed for unauthorized vault spends instead.
- Slashing · Contested. The node docs say double signing costs 5% of the minimum bond, but THORNode's code, in the public v3.20.3 release tag and the develop branch, adds 1,000 slash points and does not touch the bond. Bond slashing in the code applies to unauthorized spends from a vault, at 1.5 times the value taken, shared across that vault's members by bond. Releases shipped as private binaries could not be inspected when they were deployed.
- External asset custody · Applies. Coins from connected chains are held in threshold-signature vaults on those chains, not on THORChain's own ledger. Vaults are split into shards of a set size (default 20 nodes in the developer docs; five vaults at the time of the May 2026 exploit), and each spends only with about two-thirds of its members. Solvency checks compare expected and actual vault balances and halt a chain when a supermajority of nodes reports a gap.
- Node governance mimir · Applies. Active nodes vote on-chain on Mimir parameters: economic keys need two-thirds of active nodes; operational keys such as halts take effect with three votes, can be overturned by four and re-set by five, per THORChain's first exploit report. Software upgrades are proposed on-chain and approved by node votes. The node overview page says an admin Mimir value applies when two-thirds is not reached, while the emergency-procedures page says admin Mimir has been removed. Other RUNE holders take part only through the nodes they bond to; TCY carries no vote.
- Bonding and bond providers · Applies. Holders bond RUNE to a node with a deposit carrying a BOND memo, and an operator can add bond providers who share its rewards after an operator fee. The bond sits in a module controlled by the state machine; only the address that first bonded can unbond or leave, and only while the node is on standby, not while it is active or ready.
- Cross chain settlement · Partial. A committed THORChain block is final, but a swap from another chain is processed only after the source chain reaches a confirmation count that grows with the deposit's value, and large outbounds are held back across blocks. The external chains' own finality therefore bounds how fast and how safely a swap settles.
- Private security releases · Applies. THORNode v3.15.0, v3.18.0, v3.19.0, v3.20.0 and v3.20.1 shipped as private binaries with security patches that operators were told not to build from source, and the v3.16.1 notes refer to a private build of v3.16.0. The v3.18.0 source was later published as a disclosed tag, and v3.20.2 reconciled the 3.20 changes into the public branch. Until disclosure, operators run code they cannot inspect.
- Tps · Unknown. No sourced, classified throughput figure for THORChain was found. The node docs give a block interval of about six seconds; that is not a capacity figure, and swap completion also depends on source-chain confirmations and outbound scheduling.
Tradeoffs
- Emphasizes
- Security and Decentralization Contested
- Gives up
- Cheap participation and fast settlement. An active node must bond more than the smallest active bond (about 356,000 RUNE in a 2026-09-29 read), run full nodes of every connected chain on a Kubernetes cluster, and the node docs estimate hosting at 2,000 to 3,500 US dollars a month. Swaps wait for source-chain confirmations that grow with value, large outbounds are spread across blocks, and chains or trading halt when solvency checks or a few node votes call for it.THORChain's docs name security and decentralization among its aims and target bonded RUNE worth about twice the pooled non-RUNE assets, so theft should cost more than it gains. Both emphases are disputed: in the reviewed code double signing costs slash points, not bond; in May 2026 one newly joined node broke a vault's key through signing-library flaws despite the bond; bond and hosting costs limit who can run a validator; and several 2026 releases shipped as private binaries that operators could not build from source until later disclosure.
- Full node at home
- Demanding 1213141617A THORChain full node runs the thornode daemon, optionally with Midgard, without the external chain clients. The docs say a current binary cannot replay history from genesis, so a node starts from recent state: network StateSync, which the docs say needs about 80 GB of memory, or a pruned or archive snapshot published by Liquify, which means trusting that snapshot. Storage and CPU needs are not published, and the documented node-launcher path runs on Kubernetes. Validators are a separate class: a Kubernetes cluster running every connected chain's full node plus the bond.
- Throughput claims
- No classified figure recorded
Scaling layers
No scaling layer recorded in this profile.
Capabilities
| Capability | How it is provided | Notes and sources |
|---|---|---|
| Account abstraction | Structured assessment pending | Not yet assessed for any chain. |
| Atomic swaps | Unknown | THORChain's own swap does not meet this row: coins go to a vault address, nodes observe the deposit, swap through RUNE-paired pools and pay out from a vault that about two-thirds of its members must sign. That is custody by a rotating signer set, not a hash-time lock, and the trade is against pools, not another party. RUJI Trade, an on-chain order book on the App Layer, was not assessed: the cited pages do not show where its resting orders sit or how a match settles, so absence is not stated. 1571933 |
| Authenticated data publication | Unknown | Not yet assessed under this row's current definition. |
| Light clients | Unknown | Building blocks only: CometBFT produces validator-signed commits a light client could check, and a node restoring by StateSync takes a trust height from default RPC servers. No THORChain light client for users was documented, the deploy guide says THORNodes are full nodes, not light clients, and the reviewed app wiring registers no IBC module. 141625 |
| Native staking or delegation | Structured assessment pending | Not yet assessed for any chain. |
| On-chain governance | Structured assessment pending | Not yet assessed for any chain. |
| Parallel execution | Structured assessment pending | Not yet assessed for any chain. |
| Payment or state channels | Unknown | No payment or state channel layer anchored to THORChain was found in the reviewed docs; absence was not verified. |
| Programmable spending | Native (protocol or core-team software) Earlier definition | CosmWasm contracts run on the base chain as the App Layer, introduced with THORNode 3.0. Deployment is permissioned: only approved code and deployers are whitelisted for mainnet, and nodes can pause one contract or the whole App Layer through Mimir. Contracts have no privileges beyond an ordinary THORChain address: they can send, swap or call other contracts but cannot touch vault logic. 725 |
| Protocol-verified messaging | Structured assessment pending | Not yet assessed for any chain. |
| Reversible transfers or recovery | Unknown | Not yet assessed under this row's current definition. Swaps that cannot meet the user's price limit are refunded by the protocol, which is automatic handling, not a sender-controlled cancel window. 5 |
| Rollups | Unknown | No rollup settling to THORChain was found in the reviewed sources; absence was not verified. The App Layer runs contracts on the base chain itself, not as a separate layer. 7 |
| Shielded transfers | Structured assessment pending | Not yet assessed for any chain. |
| Signed partial offers | Unknown | Not yet assessed under this row's current definition. |
Reading these values
- How this feature is provided
- Built into the protocol, core-team software or independent software says where a feature lives and who can change it. These are implementation layers, not quality: core-team software is not closer to the protocol than independent software.
- Structured assessment pending
- The shared review has not assessed this feature for any chain yet (Account abstraction, Native staking or delegation, On-chain governance, Parallel execution, Protocol-verified messaging and Shielded transfers). That does not mean it is absent, and a chain’s profile may already describe it.
- Unknown
- The review has not established this for this chain under the current definition; the note beside it says why. Unknown is not absent and not a low score. A feature reads “Not present” only when a source shows it is absent.
- Earlier definition
- Payment or state channels, Programmable spending and Rollups keep the earlier definition until the next fact-check. There, “Native” does not separate the protocol from core-team software, “Ecosystem software” does not say who publishes it, and “Partial” does not say which layer.
- Reading across rows
- The list of capabilities is incomplete. Do not read these rows as a chain leading or lagging overall.
Ecosystem & custody
| Product type | Status | Notes and sources |
|---|---|---|
| Automated market makers | Native to the protocolTHORChain continuous liquidity pools (RUNE-paired), Streaming swaps, RUJI Trade order book (App Layer), RUJI AMM strategies (App Layer) | The exchange is the chain's core function: each pool pairs an asset with RUNE, swaps pay a fee that grows with the swap's size relative to pool depth, and streaming swaps split large swaps across blocks. On the App Layer, Rujira runs a contract order book that can also draw on base-layer pools. Liquidity depth, audits and App Layer operators were not reviewed. 1533 |
| Issuer-native stablecoins | None found | Neither Circle's USDC list nor Tether's supported-protocol list includes THORChain. Stablecoins traded through THORChain stay on their home chains in THORChain's vaults, and users on THORChain hold pool, trade or secured-asset claims on them. 63435 |
| Algorithmic stablecoins | Unknown | TOR, the protocol's dollar unit, cannot be transferred or held and serves only pricing and the retired lending ledger, so it is not a stablecoin users hold. Stablecoins issued by App Layer projects were not reviewed. 8 |
| Bridges | Native to the protocolBifrost observation and threshold-signature vaults, Secured assets (usable by App Layer contracts) | THORChain does not mint wrapped copies on other chains: its nodes hold connected chains' coins in vaults and pay swaps out natively. A 2026-09-29 read listed vault addresses on 12 chains (Avalanche, Base, Bitcoin Cash, BNB Smart Chain, Bitcoin, Dogecoin, Ethereum, Cosmos Hub, Litecoin, Solana, TRON, XRP Ledger), with trading paused on Bitcoin and Solana at that moment. Secured assets, which THORChain's docs describe as wrapped forms of connected-chain coins managed in THORChain's own state, let deposited coins be used by App Layer contracts. Risk: Everything deposited depends on each vault's signer set. On 15 May 2026 a node that had joined two days earlier used flaws in the GG20 signing library to rebuild one vault's key and drained about 10 to 10.7 million US dollars by THORChain's own reports; the network halted about five weeks, patched the library, and ADR-028 charged the loss to protocol-owned positions, savers and the treasury, not regular liquidity providers. Coins sent to a retired vault address are lost, and a source-chain reorganisation deeper than the confirmation count can leave a vault short. 67181920272832 |
| Block explorers | Established in the ecosystemRUNEScan, THORChain Network Explorer (thorchain.net), xScanner, THORChain Tx Tracker | THORChain's docs list these community-run explorers and say the ecosystem has no official channels; their operators were not verified. Listing is not a quality or completeness check, and explorer data is indexed and can lag the chain. 9 |
| Hardware wallets | ThinLedger (through ASGARDEX or the THORNode command-line client) | See the custody rows: Ledger devices sign RUNE through ASGARDEX or THORChain's command-line client, while Ledger Wallet's published currency list has no THORChain entry; Trezor says it does not support THORChain. THORChain's ecosystem page also lists KeepKey among wallets; its RUNE support was not checked. 9373940 |
Hardware-wallet custody
| Device maker | Status | What users can and cannot do |
|---|---|---|
| Ledger | Through an intermediaryASGARDEX desktop wallet or the THORNode command-line clientSame as native: Unknown | Can: Add a Ledger account in ASGARDEX and use it for RUNE, per ASGARDEX's own feature table Can: Add a Ledger key to the THORNode command-line client with the --ledger flag and confirm transactions on the device, per THORChain's developer docs Cannot: Find THORChain in Ledger's published Ledger Wallet currency list (@ledgerhq/cryptoassets 13.56.0)Ledger's THORChain page (modified 2026-02-20) is a generic template that invites users to manage THORChain in Ledger Wallet, but Ledger's published currency list has no THORChain entry. A THORChain device app forked from the Cosmos app is kept in Ledger's GitHub organization; the reviewed ASGARDEX and command-line docs do not name the device app they use. THORChain's ecosystem page links a Ledger support article on RUNE that could not be read in this review. 92136373839 |
| Trezor | None foundSame as native: No | Cannot: Manage RUNE in Trezor Suite; Trezor's THORChain page says it does not currently support THORChainTrezor's page asks users who used THORChain with Trezor before to contact support. Third-party wallets that might sign RUNE with a Trezor device were not checked. 40 |
Public data
iKnow Blockchain has no public-data lookups for THORChain yet. This is a limit of the service, not a statement about the network.
| Lookup | Status | What it covers and its limits |
|---|---|---|
| Address or account | Not available yet | Public-data lookups for this chain are not built yet. |
| Tokens and assets | Not available yet | Public-data lookups for this chain are not built yet. |
| NFTs | Not available yet | Public-data lookups for this chain are not built yet. |
| Transactions | Not available yet | Public-data lookups for this chain are not built yet. |
Sourced developments
Developments: Reviewed Sep 29, 2026 Next review due Oct 9, 2026, 12:00 UTC.
Publication date · newest first
-
v3.20 resumed churn and switched on protocol-owned liquidity controls
THORNode v3.20 unblocked validator churn after more than 60 days, made the protocol-owned liquidity controls operational (nodes set 20% of system income to it), and shipped an experimental Stable Reserve for one-to-one stablecoin swaps, disabled by default. It also applied a residual ADR-028 remediation and added Zcash and Monero work that was not yet activated.
- Implementation:shipped in THORNode v3.20.0 (private binary), with patch releases through v3.20.3
- Release:v3.20.0 tagged 2026-08-19
- Activation:upgrade at block 27,580,000; churn and POL active; Stable Reserve disabled by default; Zcash and Monero not active in the 2026-09-29 read
Sources: THORChain blog — THORChain Protocol Upgrade v3.20 (external site) · THORChain (GitLab) — THORNode v3.20.0 release (external site) · THORChain blog — State of the Network - August 2026 (external site) · THORChain blog — How THORChain's New System Income Distribution Works (external site) · THORChain Midgard API, public endpoint run by Liquify — Midgard /v2/network via Liquify (read 2026-09-29) (external site) · THORNode API, public endpoint run by Liquify — THORNode /thorchain/inbound_addresses via Liquify (read 2026-09-29) (external site)
-
v3.19.0 carried the fixes to reopen the network after the exploit
THORNode v3.19.0 shipped the TSS patches behind the restart, walled off the compromised vault from new deposits and added a temporary key check before trading resumed. It also merged Monero chain support, which still needed testing and a node vote to activate, and an affiliate revenue share.
- Implementation:shipped in THORNode v3.19.0 (private binary)
- Release:v3.19.0 tagged 2026-06-05
- Activation:upgrade at block 26,518,000; trading resumed around 22 June 2026; Monero not yet activated
Sources: THORChain blog — THORChain Protocol Upgrade v3.19.0 (external site) · THORChain (GitLab) — THORNode v3.19.0 release (external site) · THORChain blog — State of the Network - June 2026 (external site) · THORNode API, public endpoint run by Liquify — THORNode /thorchain/inbound_addresses via Liquify (read 2026-09-29) (external site)
-
A vault was drained through a signing-library flaw, and the network halted
THORChain's first exploit report describes how, on 15 May 2026, a node that had churned in two days earlier rebuilt one vault's key through flaws in the GG20 signing library and drained about 10.7 million US dollars (the second report says about 10 million). Automatic solvency halts and node votes stopped trading, signing, chain observation and churn within hours; the other four vaults were unaffected.
- Implementation:halt applied; library patched in later releases
- Release:exploit reports published 20 May, 3 July and 6 August 2026
- Activation:trading resumed around 22 June 2026 per THORChain's June network report
Sources: THORChain blog — THORChain Exploit Report #1 (external site) · THORChain blog — THORChain Exploit Report #2 (external site) · THORChain blog (prepared by THORSec) — THORChain Exploit Report #3 (external site) · THORChain Dev Docs — ADR 028: Exploit Conciliation (external site) · THORChain blog — State of the Network - June 2026 (external site)
-
v3.17.0 burned most of the Reserve and set RUNE's maximum supply to 360 million
THORNode v3.17.0 implemented ADR-023, burning about 64.9 million RUNE from the protocol Reserve and setting the maximum supply to 360 million RUNE. The same release moved the developer fund to a 2-of-3 multisig and retired the bug bounty program.
- Proposal:ADR-023 accepted; the April 2026 blog post says it had passed
- Implementation:shipped in THORNode v3.17.0
- Release:v3.17.0 tagged 2026-04-21
- Activation:upgrade set for block 25,959,000, estimated 28 April 2026; THORChain's tokenomics page now gives the 360 million maximum supply
Sources: THORChain blog — Protocol Upgrade - v3.17.0 (external site) · THORChain (GitLab) — THORNode v3.17.0 release (external site) · THORChain Dev Docs — ADR 023: $RUNE Supply Restructure (external site) · THORChain blog — ADR023 - Changing RUNE FDV (external site) · THORChain blog — THORChain Exploit Report #2 (external site) · THORChain Docs — Tokenomics of RUNE and TCY (external site)
-
TRON connected to THORChain with TRX and USDT pools
THORChain announced that its TRON integration was complete, with native TRX and USDT on TRON available for swaps and liquidity against RUNE, and whitelisted TRC-20 tokens supported. TRON was still among the chains with active vault addresses in a 2026-09-29 read.
- Implementation:TRON chain client shipped
- Release:announced as complete
- Activation:TRON listed with an active vault address and trading not paused in the 2026-09-29 read
Sources: THORChain blog (Nine Realms) — TRON Integration Complete: Native TRX & USDT Swaps Live on THORChain (external site) · THORNode API, public endpoint run by Liquify — THORNode /thorchain/inbound_addresses via Liquify (read 2026-09-29) (external site)
Topics your AI can explain
Your AI can explain these topics for THORChain through the connection, with sources.
Known gaps
What this profile's review did not establish:
- The node docs say double signing costs 5% of the minimum bond, but THORNode's code in the public v3.20.3 release tag only adds slash points; earlier releases shipped as private binaries could not be inspected when deployed.
- THORChain's node docs disagree on admin Mimir: the overview page says its value applies when two-thirds of nodes do not agree, and the emergency-procedures page says it has been removed; the live state was not verified.
- Who operates each THORNode, and how many nodes a single party runs, is not public; node counts and bonds come from one Midgard read on 2026-09-29 and move with every churn.
- Storage, CPU and bandwidth needs for a THORChain full node are not published; only the StateSync memory figure is documented.
- The May 2026 exploit loss figure and the ADR-028 allocation come from THORChain's own reports and design record; the final amounts applied at upgrade height and whether the attacker's bond was slashed were not verified on chain.
- Trading on Bitcoin and Solana showed as paused in the 2026-09-29 read of inbound addresses; the reason and expected restart were not checked.
- Monero, Zcash and Dash support has been merged in node software, but none appeared among the chains with vault addresses on 2026-09-29; activation dates are not set.
- RUJI Trade, the App Layer order book, was not assessed under the atomic swap row, so that cell stays unknown.
- No light client for THORChain users was found, and absence was not exhaustively verified.
- Ledger's support article on RUNE, linked from THORChain's docs, did not render for this review; whether Ledger Wallet shows RUNE balances directly is unconfirmed.
- Third-party wallets that might sign RUNE with a Trezor device, and KeepKey, which THORChain's ecosystem page lists among wallets, were not checked.
- Rujira's documentation lists a BTC-backed stablecoin among its App Layer products; whether one is live, and how it is backed, was not verified.
- The developer docs give a default vault shard size of 20 nodes, while the constants file in code sets a default of 40 that Mimir can override; the live value was not read.
- The public Midgard host midgard.thorchain.network did not resolve from this review's network on 2026-09-29, in two separate checks.
- No sourced throughput figure was found for THORChain.
- Operators, audits and liquidity depth of App Layer products were not reviewed.
Sources
Oldest dated source check: Source checked Sep 29, 2026 Next check due Oct 29, 2026.
- Native Cross-chain Swaps (external site)
- Network Security and Governance (external site)
- Emergency Procedures (node voting, admin Mimir removal, network upgrades) (external site)
- Security (confirmation counting, outbound throttling, halts, solvency checker) (external site)
- Continuous Liquidity Pools (external site)
- Bifrost, TSS and Vaults (external site)
- CosmWasm (App Layer overview) (external site)
- TOR (external site)
- Ecosystem (external site)
- THORNode Overview (node voting on Mimir) (external site)
- Node Operations (churning, node statuses, bond providers) (external site)
- THORNode Stack (components, keys, hard-fork history) (external site)
- Risks, Costs and Rewards (external site)
- Deploying (external site)
- Joining (external site)
- Thornode - Docker (fullnode setup) (external site)
- Thornode Snapshot Recovery and Storage Management (external site)
- How Bifrost Works (finality and confirmation counting) (external site)
- Threshold Signature Scheme (TSS) (external site)
- ADR 028: Exploit Conciliation (external site)
- Offline Ledger Support (external site)
- x/thorchain/manager_slasher_current.go (v3.20.3 release tag; same logic on develop): double-sign and vault slashing (external site)
- x/thorchain/manager_validator_current.go (v3.20.3 release tag): validator updates with equal power (external site)
- constants/constants_v1.go (v3.20.3 release tag): default protocol constants (external site)
- app/app.go (v3.20.3 release tag): registered modules (external site)
- THORNode releases (external site)
- THORChain Exploit Report #1 (2026-05-20) (external site)
- THORChain Exploit Report #2 (2026-07-03) (external site)
- State of the Network - August 2026 (external site)
- Byzantine Consensus Algorithm (external site)
- Midgard /v2/network via Liquify (active and standby nodes, bond metrics; read 2026-09-29) (external site)
- THORNode /thorchain/inbound_addresses via Liquify (connected chains and halt flags; read 2026-09-29) (external site)
- RUJI Trade (external site)
- USDC contract addresses (external site)
- Supported Protocols and Integration Guidelines (external site)
- THORChain Wallet - Buy, manage & hold your RUNE (external site)
- @ledgerhq/cryptoassets 13.56.0 currency list (external site)
- LedgerHQ/app-thorchain: Ledger THORChain app (external site)
- ASGARDEX desktop README (feature table, Ledger accounts) (external site)
- THORChain wallet (external site)
Report an error
Found something wrong or out of date? Reporting is free, and every chain goes through the same process. Published corrections appear in the public log.
Funding disclosure
Funding disclosures appear here when an upkeep arrangement exists, in the form “Upkeep funded by [name]; verdicts unaffected.” The funder ledger has not been published yet. Neutrality & funding