💡 Community Spotlight
Throw this one some love, Chads, because we love to celebrate the consistent contributors to the THORChain ecosystem and today, it's the guy who's editing the videos from our livestreams.
@WithTheCoke has a cool journey to share. Let's dive in 👇
Yeah…
Anyway, TC still finding its footing in this brave new world with AI lurking and being weaponized both in attacks but, more frustratingly, in the constant submission of AI slop spam. I will work with core team and the ecosystem to get TC’s security posture up to par, but it will undoubtedly look different than the previous L1 landscape of bug bounties via platforms, they became literally unusable.
How to filter the noise is now an important problem to solve, and how to manage submissions in a trustless environment also. The role of security researchers will also evolve, but the threatening recourse breaking responsible disclosure is not the path.
On the other hand, apologies to the honest, hard working contributors and researchers who’ve had a negative experiences in the past, please reach out to me if there is something to address from the past honorably. For now, I am aware of https://t.co/kU1gZWIJ9z and @kayabaNerve , my DM’s are open good sers 🙂 I think I can largely speak for TC nodes and users that security is valued, even if it has been mishandled in the past.
@THORChain@QuaiNetwork Join THORChain Live now!
https://t.co/NGXef2GSR8
https://t.co/NBOywkN2QW
https://t.co/krsmrgIwsI
And request to speak:
https://t.co/3ifRMlOtEu
If you don’t want to speak, you can leave a comment in the live chat and the hosts will see it. (YouTube is the most reliable one)
Incident Update #4 is live and the ADR-028 proposal is on the table
Here’s everything you need to know about the @THORChain Recovery Plan 👇
→ POL absorbs the loss first. Synth holders take what's left
→ No new RUNE minted. No holder diluted. No RUNE sold to cover anything
→ Attacker slashed in full. Recovered RUNE paired with vault assets, surplus burned.
→ Innocent nodes protected
→ White hat bounty on the table. Return the funds, the plan rolls back proportionally.
→ Protocol neutrality holds. Attacker's swaps won't be censored once trading resumes
Node Operators vote now. Yes = green light to restart
No mint. No bailout. No censorship. Full transparency
Onwards⚡
@THORChain@CBarraford Join THORChain Live now!
https://t.co/Zyeq0S8oLJ
https://t.co/FPdT6y4x2G
https://t.co/hdPzW2iptX
And request to speak:
https://t.co/3ifRMlOtEu
If you don’t want to speak, you can leave a comment in the live chat and the hosts will see it. (YouTube is the most reliable one)
THORChain Exploit Report #1 is now live.
Full timeline of the May 15 incident, how the security layers responded, and what comes next via ADR-028.
https://t.co/8QXfeKxwva
TSS Exploit Update #3
→ Attack understood, technical details not yet public
→ Not a known GG20 exploit
→ v3.18.1 tomorrow. Node operators instructed to upgrade immediately
→ Decisions over lost funds set by ADR-028 community governance vote
TLDR; we're making progress 💚
THORChain incident update #3
The developers and THORSec teams have been hard at work throughout the weekend continuing the investigation to fully understand the events that took place, while also planning the road to recovery. It’s important to note that the investigation is still ongoing, and details may change in the coming days as we continue to gather information and adjust plans accordingly.
At this time, the team has a strong understanding of what occurred and how the attack was executed, although they are not yet in a position to publicly discuss the technical details. What they can say is that the attack vector does not appear to be related to any currently known GG20 exploits, and at this stage are still assessing whether other GG20 implementations could also be at risk. The team will continue investigating this possibility and will coordinate with other affected teams as appropriate.
We would like to thank the many cryptographers and security researchers who assisted throughout this process, including members of the team that originally developed GG20.
The team currently expects to release version 3.18.1 tomorrow for node operators to adopt. We ask that all node operators upgrade to this release as soon as possible.
There is also an open question regarding the best approach for handling the lost funds within the network. This will need to be discussed and ultimately decided by the community through governance. To facilitate this discussion, there’s a new channel in Discord called adr-028-tss-exploit-recovery .
Before the network can return to a healthy state, nodes will need broad consensus on this ADR, after which the selected approach will be implemented as part of the 3.19 update. THORChads are encouraged to share well-structured and thoughtful proposals for the community to support or challenge. In the coming days, a vote will occur highlighting the most widely supported approaches for node operators to vote on.
Regarding the future direction of the cryptographic systems used to secure the vaults, that discussion is still ongoing and requires additional research before any long-term decisions are made. For the immediate future, the team is currently leaning toward remaining on GG20 in order to restore network health and stability as quickly and safely as possible. Longer-term discussions around the future of THORChain’s cryptographic security model will continue once the network has stabilized.
We are proud of how both the developer team and community have handled this situation. Everything will get running again as soon as possible, but the process will not be rushed. THORChain has a strong roadmap ahead, and devs are excited to return their focus to continuing to push the envelope of what this project can achieve.
Onwards
Hey all, @THORChain & @RujiraNetwork weekly recap is up! The main topic was obviously the recent exploit, but we also had time for an app layer discussion and a podcast with @firoorg!
Thank you all for the support! @Dashpay@XBToshi@banteg and others!
https://t.co/xqIbqMV8D2
THORChain incident update #2
We have become aware of multiple fake accounts and false information circulating regarding “refunds”, “airdrops”, compensation claims, and other alleged initiatives.
To be absolutely clear:
- Initial findings indicate that no user funds were lost in the incident
- THORChain is currently conducting no refund, airdrop, or compensation program
- Any account claiming otherwise is impersonating THORChain or spreading misinformation.
Please rely only on official THORChain communication channels for updates.
THORChain contributors are still actively investigating the recent incident alongside THORSec and external security partners. More information will be shared as the investigation progresses.