We're excited to unveil Vaultstone Advisory – bridging traditional capital with the decentralized revolution.
Inspired by #Bitcoin, @vultisig and @THORChain, we're empowering institutions to swap, yield, store and thrive in DeFi.
Details incoming! #Vaultstone#THORChain#DeFi
Yikes! A court just froze $12.6M in USDC, and unrelated users in the same pool got locked out of their own funds.
The freeze hit a shared contract, so people who had nothing to do with the legal dispute lost access to their money just because of who they happened to share a pool with.
The bitter pill to swallow here:
A court in one jurisdiction can freeze onchain assets without ever targeting you personally.
You just have to be in the wrong pool at the wrong time.
Defenders will win when whitehats find and report vulnerabilities before attackers do. The industry is still adapting, but teams that adopt scalable security processes will be able to move at AI speed without sacrificing security. Hopefully, we're not too far away. (7/8)
The Clarity Act cleared the Senate banking committee 15-9. While everyone debates BTC's price, the legal rails are being laid. Infrastructure before speculation.
#Bitcoin#CryptoRegulation
$528M left BlackRock's Bitcoin ETF in one day. Not because BTC broke — because Treasury ops are draining $150B in liquidity. Price follows plumbing, not fundamentals.
#Bitcoin#BTC
Fear & Greed at 25. Strive just bought 1,109 more BTC — now holds 16,500. When retail panics, institutions accumulate. That divergence tells you everything.
#Bitcoin#BTC
shipping a testnet this fast while the whole timeline is dunking on you takes serious grit. $10m is a brutal tax for tech debt, but this is exactly how unbreakable infra is forged. I am not a $RUNE maxi, but sincerely rooting for TC to survive this as a builder.
This protocol was the first legit DEX that worked with real Bitcoin (and other isolated coins) and advanced what was even possible with AMMs. No matter what happens it has played an important role in crypto history and helped birth the DeFi movement.
The team and the community continues to push the envelop in the best interest of the industry as a whole, preserving liberty and expanding what is even possible (ie $XMR), while doing it on a shoe string budget.
Its wild to me how divisive @THORChain seems to be.
This protocol solved a "holy grail" problem the industry desperately needed to be solved and achieved "the impossible". Any coiner should be in appreciation for achieving something that we all use & take for granted today
Thank you for your comment. Yes it seems counterintuitive. However, to use the same logic as Chipotle's 2015 E. coli crisis or Toyota's 2009 recall: public company, public scrutiny, public fix .... both came out with stronger operations and higher valuations. The ones that bury problems are the ones that blow up. FTX had zero public incidents until it had one.
Exploited. Audited. Challenged. Open-sourced. Repeat.
That's not a failure loop — it's how protocols get forged.
THORChain wears its scars in public. That's the point.
#THORChain#DeFi#OpenSource
Domino's 2009: CEO went on camera and said the pizza was cardboard. Stock under $10. They rebuilt the recipe in public. Cleared $500.
THORChain just got exploited. Nodes paused the network within hours. Damage contained. Now they rebuild — in public.
Same playbook.
#THORChain
Thorchain didn't lose $10.7M to a smart contract bug or a stolen key. The bug was in the cryptography itself - and Thorchain probably isn't the only chain running on it.
A single attacker bonded RUNE and joined the validator set days before the incident, looking like any legitimate operator. From inside, they exploited what investigators currently believe was a flaw in GG20, the threshold signature library Thorchain uses to co-sign transactions. Each signing session leaked a fragment of private key material to the attacker's node. After enough sessions, they had collected enough leaked data to mathematically reconstruct the vault's full private key.
Then they signed unauthorized outbound transactions as the vault. The smart contracts behaved correctly. No validator infrastructure was breached. Funds left through normal channels because the signatures were mathematically valid - just produced by an attacker who had silently rebuilt the key.
Here's why this matters beyond Thorchain.
GG20 was published in 2020 (Gennaro-Goldfeder). The Alpha-Rays attack (Verichains, 2023) and TSSHOCK at BlackHat 2023 documented practical weaknesses in tss-lib and related implementations. Some teams patched. Many didn't bother.
Based on shared library lineage, protocols that should audit their TSS right now include Mayachain (direct THORChain fork), Sygma cross-chain bridge, Keep Network's tBTC v1, and any service still running on bnb-chain/tss-lib or ZenGo-X/multi-party-ecdsa.
Major custody and MPC services that already migrated to newer threshold schemes (CGGMP21, DKLs): Fireblocks, Coinbase Custody, Taurus, Silence Laboratories. The industry has been quietly moving away from GG20 for two years.
Thorchain just gave everyone still on it a reason to move faster.
THORChain was exploited for $10M across four chains yesterday.
Multi-vault architecture limited the blast — 80% unaffected. Node operators triggered global pause within hours. User funds untouched.
Resilient infrastructure doesn't mean unbreakable. It means contained.
#THOR...