CoinYQ Dossier

The bridge that tried to become a vault society

THORChain did not make Bitcoin pretend to be an Ethereum token. It built a society of bonded machines to watch Bitcoin, price it against RUNE and release another native coin. That design replaced one custodian with a chain, a rotating signing room and a large economic wager—and its history is the record of where each layer held or broke.

The coin in the middle is invisible to the trader

A BTC-to-ETH order begins on Bitcoin, not inside an EVM wrapper. The inbound reaches an Asgard vault; Bifrost observers translate it into a common witness; the state machine executes BTC:RUNE and RUNE:ETH; an outbound vault signs native ETH. The trader sees one route, while RUNE gives every ordinary pool a common balance sheet.

That common asset makes RUNE useful without making it a receipt for everything the network holds. A pool unit accounts for liquidity; a node bond backs an operator; RUNE in a wallet is simply the native asset. The reviewed documents do not turn that wallet balance into ownership of Bitcoin in Asgard, a guaranteed exchange rate or a slice of network revenue.

A rotating room held keys no one was supposed to possess

Each node runs chain clients and Bifrost, votes on observations and joins threshold ceremonies. A vault key is divided across a supermajority, while sharding limits how much value one signing group handles. Churn retires old vaults and creates new ones as the active set changes. Bonds and slashing add an economic cost to bad behavior.

The architecture still has human-operable brakes. Node Mimir can stop trading without stopping observation, stop signing while outbounds queue, pause liquidity, or stop a chain client entirely. Solvency reports can set halts automatically. Those distinctions matter to a user: a displayed quote can be stale, a deposit can wait, and an outbound can remain queued even though the THORChain ledger continues producing blocks.

2021 broke the observer; 2026 broke the signing assumption

In July 2021, two Ethereum router exploits manipulated what Bifrost believed had arrived. The official post-mortem said the interface trusted event behavior it had not fully bounded; Ethereum and economically significant ERC-20 assets were taken, trading returned too early once, and the treasury promised to cover LP losses. The failure lived between an external smart contract and the observer.

On 2026-05-15, the attack moved deeper. A new node bonded about 635,000 RUNE, entered one of five vault groups and deliberately failed GG20 rounds 864 times over roughly two and a half days. Tiny key-share leaks accumulated until the attacker could reproduce the private key and issue signatures indistinguishable from authorized ones. About $10.7 million left one vault. Automatic solvency halts reacted after the mismatch; four vaults and EdDSA-secured Solana were not exposed.

Recovery also changed what outsiders could verify. v3.19.0 announced extra security patches in a private binary. The network could resume with unpublished defenses, but independent reviewers could not reproduce the complete deployed TSS implementation from the public THORNode tree. Decentralized validation of blocks and public reproducibility of every security component became two different claims.

Debt forced the protocol to name who actually gets paid

The base swap engine once carried THORFi Lending and Savers above it. At block 19,562,016 on 2025-01-24, nodes paused those programs and dollarized outstanding claims after the liabilities became unserviceable. The unwind did not make RUNE holders creditors. It minted 210 million TCY for affected claims and assigned staked TCY 10% of system income paid in RUNE.

That episode clarifies the token boundary better than a utility list. RUNE secures and settles the chain; TCY contains the explicit revenue mechanism arising from the default; LP and saver accounting carries separate withdrawal risk. A RUNE holder can benefit or suffer economically from protocol activity, but price exposure is not the same as an enforceable payment right.

The cap fell, while governance stayed with machines at work

RUNE began with 500 million at genesis, but burns and failed migrations made the headline increasingly misleading. ADR-023 removed about 64.9 million from the Reserve, left 9.3 million for operations and exploit coverage, and set `MaxRuneSupply` to 360,000,000. Published vesting is complete, block emissions are now minimal, and system-income burns can keep reducing the total.

The cap can still move through consensus software. Ordinary holders do not vote by token balance; active nodes change Mimir values and adopt releases, with about two-thirds support for most economic settings. v3.20 introduced experimental Stable Reserve code for eligible stable-to-stable fills outside RUNE pools, but it shipped disabled by default, with activation conditional on completed testing; this does not establish a currently available route. RUNE remains central, while the node set can redraw the paths around it.

How the project changed

  1. 2018
    Research begins

    The Mainnet retrospective dates THORChain's inception to 2018, before a live multichain network existed.

  2. 2021-04
    Multichain Chaosnet opens

    MCCN introduces native RUNE and live cross-chain liquidity with real funds.

  3. 2021-07-30
    Ethereum router failures are documented

    The post-mortem describes two exploits that fooled Bifrost and a premature return-to-trading incident; treasury reimbursement is promised.

  4. 2022-06-22
    Mainnet is declared

    THORChain marks the transition from Chaosnet and urges migration to native THOR.RUNE.

  5. 2023-07-18
    Legacy RUNE kill switch completes

    The BEP2 and ERC-20 upgrade path reaches zero, leaving THOR.RUNE as the network asset.

  6. 2025-01-24
    THORFi claims are frozen

    At block 19,562,016, Lending and Savers are paused and claims are dollarized for restructuring.

  7. 2025-05-05
    TCY launches

    The unwind assigns 210 million TCY and a 10% system-income mechanism to stakers of the separate recovery token.

  8. 2026-05-15
    One GG20 vault is captured

    A malicious newly churned node reconstructs a key and drains approximately $10.7 million from one of five vaults.

  9. 2026-08-24
    v3.20 changes the routing map

    After v3.19 recovery, v3.20 introduced operational POL controls and experimental Stable Reserve code. The eligible stablecoin route outside ordinary RUNE pools shipped disabled by default, with activation conditional on completed testing.

Evidence and primary sources

Last evidence review: 2026-09-05

What is THORChain?

THORChain is a Cosmos-SDK state machine and distributed vault network for exchanging assets that remain native to their own chains. A BTC-to-ETH user sends BTC to an Asgard address, the node set observes the deposit, the pools price two internal legs through RUNE, and a threshold-signed vault broadcasts native ETH. The canonical token is the chain's bank asset `THOR.RUNE`, not an ERC-20 contract. Official notation warns that legacy `BNB.RUNE` and `ETH.RUNE` are no longer in use.

RUNE has several jobs that should not be collapsed into an investment promise. It is the base side of ordinary pools, the bond posted by nodes, the fee asset on THORChain and an input to incentive accounting. Holding it outside a node or pool does not confer a validator vote, vault key, redemption price, title to pooled coins or a documented claim on protocol income.

What problem does THORChain solve?

Cross-chain trading usually introduces a custodian, wrapped representation or bridge contract. THORChain instead asks independent nodes to watch external chains and collectively operate addresses on them. That removes a company from the settlement path, but it does not remove custody risk: between inbound and outbound, assets sit in network vaults whose safety depends on chain observation, consensus software and threshold cryptography.

The hard question is therefore not whether one administrator can sign. It is whether enough distributed components can fail together. Bifrost needs 67% observation agreement; Asgard outbounds need a signing supermajority; bonds make theft expensive; churn changes the signing group; solvency checks compare accounting with L1 balances; Mimir can stop selected activity. The 2026 exploit proved that a signature can look valid even when the key was reconstructed through repeated protocol failures.

How does THORChain work?

In the normal route, every listed external asset has a pool against RUNE. An asset-to-RUNE trade uses one pool; an asset-to-asset trade uses two pools and never requires the user to possess the intermediate RUNE. Pool ratios set the price. A larger order relative to depth pays more slip-based liquidity fee, while the outbound chain charges a dynamic network cost. Streaming swaps can divide execution over time. The v3.20 Stable Reserve is a narrow exception: eligible stablecoin pairs may be filled 1:1 from protocol-owned inventory, with ordinary pools as fallback, and the feature launched disabled.

Each THORNode runs Bifrost clients, validates the THORChain ledger and helps create and use threshold keys. Vaults are sharded and replaced during churn. RUNE bonds choose and discipline the active set; Node Mimir, rather than wallet balance, changes many parameters. The same system exposes `HALT<CHAIN>TRADING`, `HALTSIGNING<CHAIN>`, `HALT<CHAIN>CHAIN`, liquidity pauses and network-wide controls. Automatic insolvency reports can halt trading, but an interface must also detect stale consensus and current inbound-address flags.

Supply has changed by explicit state migrations, not by a timeless marketing number. ADR-023 burned about 64.9 million RUNE from the Reserve, retained 9.3 million, and reset the maximum to 360,000,000. Documentation says genesis created the supply and vesting is finished. System-income burns continue, and any future need to exceed the remaining reserve would require another architecture decision and node vote. This is a protocol rule controlled through software consensus, not a private-law redemption covenant.

Key facts

  • Canonical asset: native `THOR.RUNE`; legacy BNB.RUNE and ETH.RUNE are no longer recognized for THORChain use.
  • Normal cross-chain trades settle through external-asset:RUNE pools; a non-RUNE pair uses two internal legs.
  • Bifrost requires 67% agreement on external-chain observations, and Asgard outbounds require a threshold-signing supermajority.
  • RUNE bonds secure node participation; merely holding RUNE does not give a Node Mimir vote.
  • Mimir and solvency logic can pause trading, signing, liquidity operations, observation or the wider network.
  • Maximum supply is 360,000,000 after an approximately 64.9 million Reserve burn left 9.3 million RUNE in the Reserve.
  • All original RUNE was created at genesis and published vesting is complete; ongoing system-income burns can reduce supply.
  • The 2021 ETH router exploits abused event interpretation; the treasury said it would reimburse affected LPs.
  • The 2025 THORFi unwind created 210 million TCY and directs 10% of system income to staked TCY, not to ordinary RUNE holders.
  • The 2026 GG20 attack drained approximately $10.7 million from one of five vaults; v3.19 recovery included undisclosed private security patches.

Official links

Categories

Related coins

Frequently asked questions

Is RUNE an ERC-20 token?

The current canonical asset is native `THOR.RUNE` on THORChain. Official asset notation says legacy Ethereum and BNB representations are no longer used and have no value within THORChain.

Do I need RUNE to swap BTC for ETH?

No. The state machine performs BTC-to-RUNE and RUNE-to-ETH internally and sends native ETH to the destination. The intermediate asset still matters economically because both pools hold RUNE.

Can every RUNE holder vote?

No. Active node operators cast Node Mimir votes. The technical FAQ says most economic parameters need about 67% support, while selected operational parameters can use smaller vote thresholds.

Who can stop the network?

Node votes and automatic rules can set granular Mimir halts for trading, signing, LP actions or chain observation, plus network-wide controls. A halt can delay refunds and outbounds; it is a safety switch, not a guarantee of recovery.

Is 360 million an immutable supply cap?

It is the current software cap after ADR-023 and the accepted state migration. The ADR itself says a future shortfall beyond the Reserve would need another ADR and node vote, so the limit is consensus-governed rather than an unchangeable contract promise.

Does RUNE give a claim on vault assets or protocol revenue?

The reviewed materials establish technical uses, not equity, fixed-price redemption, title to vault coins or a contractual revenue share. TCY, a separate token created for the THORFi unwind, has the explicit 10% system-income mechanism.

External trackers

Choose a tracking site for THORChain: