THORChain FAQs: Shutdown and KYC?
Here's my own opinion on the risks
THORChain is the most important product in the entire industry because it's essentially a blockchain that acts as an exchange, minus the fiat. In its end state, THORChain will do everything a CEX does, but in a completely open source and transparent way.
There's a reason that THORChain has a culture of anon nodes and many of the OG core team and devs have chosen to remain pseudonymous.
The nodes control all of the funds on the network. Own a majority (>2/3) of the nodes, steal all of the LPs funds, or shut it down.
There's also a reason THORChain was architected the way that it is. You need massive amounts of $RUNE to become a validator who holds one of the 100 keys to the Asgard Vaults. Without anything at stake, you must be able to identify and trust those that hold the keys, else they just walk off with the funds.
Even in an MPC environment, if all the actors who hold the keys are known, they can be identified by other key holders, or people on the outside. Those individuals can collude to steal funds (share the profits), or can be subject to external pressures (threats, etc)
Let me start off by saying THORChain has one of the most diverse sets of node operators in the space. There is no entity that is even close to controlling a majority share of the network, and there's no one that can effectively block changes to the network.
All of the nodes are in a Mexican Standoff against one another. In order to make changes, all of them must agree and adopt new code that makes those changes.
There's also only one way for nodes to directly communicate with all of the other nodes. It's a feature called "Make Relay"
"Make Relay" is a feature built into every single THORNode that allows nodes to sign and broadcast anonymous messages signed with their pubkey to the THORChain developer discord. All messages are 100% public and viewable by anybody, and verifiable that they are sent by that node.
Any node can send messages to communicate there, but anyone can also read it. So it's not an effective form of communication to coordinate and steal funds. It is a very useful form of communication to keep operators anonymous while still allowing fully transparent levels of coordination and communication.
Take a look at all of the nodes on THORMon - my favorite node dashboard:
https://t.co/XrOobnO72W
One of the things you'll notice is the large variety in physical locations as well as different operator addresses. Of course, there's no guarantee that every operator address means a different operator, but it gives us some type of clue as to how many individual operators there are.
Another thing you will notice is all of the ISP providers of those node operators. You might look at that and go, "Well if you wanted to pwn THORChain, you could just get the server providers to shut down their nodes".
But there's a few things wrong with that.
First, there's been a huge uptick over the past 1.5 yrs of bare metal nodes. Bare metal nodes are servers run on custom equipment. Most of the time, these nodes funnel their traffic through a proxy operated on a major provider like AWS, GCS, or DigitalOcean, so they'll still appear in this list like they're running on a cloud service.
But for this example let's just assume that every single node is running on a cloud server. Then Uncle Sam calls Jeff Bezos and shuts down every last thornode server. What happens?
Well a few things happen. First, THORChain would stop producing blocks completely. No more swaps would be able to be processed because the nodes would obviously not be able to communicate with each other and sign out transactions. Does this mean the end of the network?
Hell nah.
The vaults still exist and are safe. No one can sign out funds because the nodes can't coordinate to send funds from the vaults. But how do the nodes rebuild and start to coordinate again?
Nodes have a feature built in that backs up their TSS keyshares on-chain after every churn. Those keyshares are triple encrypted by 3 different encryption methods and published directly on chain. All that's needed to rebuild a THORNode is to know the mnemonic of that node.
Just the 24 word private key is needed to rebuild the node on a new machine and get the network up and running again.
So after every node goes down, every node operator will take notice and re-build on a new machine. How do you know this will happen? Because every node has 800k+ $RUNE (millions of dollars) at stake, that can't be recovered unless the network is operational.
Once operators re-build their machines, they can use the "Make Relay" functionality to coordinate publicly (and anonymously). Once 2/3 are back online, the network will resume as normal. They'll be scanning the past block to see what swaps have been made since they went down, and continue processing swaps like nothing ever happened - right from the block they left off on.
With the whole keyshare backup system, I believe the system is pretty anti-fragile. Any kind of downtime would only be temporary and the network would be able to easily re-build and recover in a week or less.
Now... what about KYC? Can someone force the chain to start implementing KYC or other screening methods?
Not unless every single THORNode agrees to this change. Remember, 100% of validators must adopt a new version for changes to take effect. So unless every single anon validator chooses to adopt something it can't happen.
I don't believe that censorship at the base layer of THORChain is possible, because it will never be possible to convince anonymous operators to adopt the change.
Frontend is totally different and are a much easier target. Frontends can do whatever they want, or whatever they are forced to by their legal jurisdiction. They are completely free to filter traffic, KYC, do anything they want. Obviously, there is no way to enforce the same type of principles on the frontends, which inevitably must be hosted on some server in some jurisdiction somewhere.
It's important to continue to make this distinction because FUDders will continue to push the narrative of censorship on THORChain, which is simply not true. If THORChain ever implemented transaction censorship at the base layer, I'm sure that a fork would be created and liquidity would migrate there. It's a core principle for the network.
And no, censorship at the frontend does not mean the backend is nerfed. Go learn how to construct your own transactions if you care so much. It's not that hard. Frontends provide a very valuable service in making sure you don't mess up and lose your own funds. They don't owe you anything, and they also have to fight for their own right to exist
I hope you enjoyed this thread which is part of my series of FAQs on THORChain ⚡️😁 If you learned something, remember to follow, like, and share the post 💙
I gave GPT-4 a budget of $100 and told it to make as much money as possible.
I'm acting as its human liaison, buying anything it says to.
Do you think it'll be able to make smart investments and build an online business?
Follow along ���
💡 Innovator Spotlight Giveaway 💡
We're giving away $250 in $OSMO with @orbital_command to celebrate IBC innovators.
To enter:
✅ Follow @flipsidecrypto and @orbital_command
✅ Like and RT this thread
✅ Keep reading 🧵
[1/5]