BLK 385.62M·XRD $0.0011·Σ TVL √ 10.1K
LAUNCHGOVERN
Wiki homeEssays
  1. Home
  2. /
  3. Wiki
  4. /
  5. DAOs
  6. /
  7. Organizations
  8. /
  9. DEXs & trading
  10. /
  11. THORChain (RUNE)

PreviousSynthetix (SNX)NextUniswap DAO
Categories:WikiDAOsOrganizationsDEXs & trading
MANIFESTO · CAPER / OWN THE GAME
The launchpad that raises and deploys capital. Guaranteed entry / exit liquidity. Governance that can't be captured.

THORChain is a decentralized cross-chain liquidity protocol that lets users swap native assets — real BTC for real ETH, ETH for native SOL — without wrapping, bridging, or trusting a custodian. It is not an app on someone else's chain: THORChain runs its own Cosmos-SDK Layer-1 whose validators (THORNodes) watch external chains, hold assets in threshold-signed vaults, and settle every trade through pools paired against its native token, RUNE. That architecture makes it a structurally distinct entry in the DEX directory alongside the on-chain AMMs (Curve, Uniswap) and aggregators (Jupiter): its governance and its treasury risk both live at the node-operator layer, not in a token vote.

Native cross-chain swaps

Every asset THORChain supports sits in a Continuous Liquidity Pool paired against RUNE — a BTC–RUNE pool, an ETH–RUNE pool, and so on. A BTC→ETH swap is really two hops through RUNE (BTC→RUNE→ETH), which is why RUNE is described as the network's settlement asset: it is present in every pool and every trade, giving the token constant, activity-driven demand rather than a purely speculative one.

Custody is handled by a Threshold Signature Scheme (TSS). No THORNode ever holds a complete vault key; each holds a fragment, and only a supermajority (≈⅔) of nodes combining fragments can sign an outbound transaction. Vaults are regularly churned — active nodes rotate in and out on a cycle — so no fixed group can capture the network or its funds. This is the same reason THORChain has no admin multisig that can move user assets: there is no full key to hold.

Governance: Mimir, not a token vote

THORChain's governance is unusual and worth stating plainly: RUNE is not a governance token, and TCY explicitly confers no voting rights. Protocol decisions are made by active THORNode operators through Mimir, a system for voting network parameters directly.

  • Operational parameters — quick, low-stakes settings — activate on a small number of node votes (typically 3+), and can be flipped: 4 nodes overturn, 5 re-activate, and so on.
  • Economic parameters — anything touching the money — require supermajority consensus (~⅔ of validators), the same threshold that guards the vaults.

To become a validator at all, an operator must bond RUNE as collateral — currently over 300,000 RUNE per node. Misbehaviour is slashed against that bond, so the right to vote is bought with capital genuinely at risk. Larger architectural changes go through Architecture Decision Records (ADRs) debated by node operators and contributors. The result is a governance body that is fast and Sybil-resistant, but also small, technical, and closed to ordinary token holders — a deliberate trade-off very different from the balance-weighted vote-escrow models used elsewhere in the directory.

RUNE tokenomics & the Incentive Pendulum

RUNE has no vesting schedules or locked allocations — the full supply is released, and a portion of fees is burned, so circulating supply trends down over time (~425M total, ~350M circulating, ~75M reserve). Rewards to nodes and liquidity providers come from real fee revenue (on the order of $50,000–$100,000/day), not new emissions.

Security is anchored by a target ratio: total bonded RUNE ≈ 2× the value of all non-RUNE assets in the pools. If liquidity outgrows security the network becomes attackable; if bonded RUNE dwarfs liquidity it is capital-inefficient. The Incentive Pendulum continuously re-weights rewards between nodes and LPs to steer the system back toward that 2:1 target — an automatic economic governor sitting under the human Mimir votes.

The ThorFi debt crisis and TCY

THORChain is also one of DeFi's most instructive case studies in governance under stress. Its lending and savers products (“ThorFi”) accrued liabilities the protocol could not cover — roughly $200M+ of RUNE-denominated debt. In early 2025 node operators paused the network and voted on a restructuring rather than papering over the hole by inflating RUNE.

The resolution was a debt-to-equity conversion: a new token, TCY (THORChain Yield), was issued at 1 TCY per $1 of debt (fixed supply 210M), turning creditors into revenue-share holders instead of writing them to zero. TCY holders receive 10% of all network revenue paid in RUNE, with a RUNE/TCY pool for liquidity. Crucially, TCY was designed as a pure income instrument — it does not grant governance rights. Creditors got a claim on cash flow; the votes stayed with the bonded nodes.

2026 exploit and the governance response

On 15 May 2026 a newly-churned node operator exploited a vulnerability in the GG20 signature scheme and drained roughly $10.7M from one of five vaults. The response is a clean illustration of how a node-operated protocol governs an emergency: automatic solvency checks halted signing and trading within minutes without human intervention, then operators coordinated over Discord — stacking manual pauses and casting formal Mimir votes — to bring the whole network to a controlled halt within about two hours. The other four vaults were untouched, and the network absorbed the loss from protocol-owned reserves rather than minting fresh RUNE. Recovery of the lost funds was routed to community governance via ADR-028. Trading resumed after a multi-week pause once patched.

How Caper approaches this

THORChain draws a hard line most DAOs blur: the people who provide the capital (RUNE bonders) hold the votes, while the people owed money (TCY holders) get a cash-flow claim and no say at all. It is clean, but it means an ordinary holder's only real lever if they disagree with the operators is to sell into the open market.

Caper keeps holdings and voice on the same instrument, and adds a second lever THORChain's TCY holders never had — a canonical exit right. A caper's token holders both vote and, if they reject where the treasury is heading, can redeem their share of the reserve. Voting power is the canonical weight w = (t·v)/(V·T) — a holder's tokens times their own votes over total votes and circulating supply — so influence tracks both stake and participation, verified against the contract's compute_vote_weight. The point isn't that THORChain's model is wrong for a cross-chain settlement layer; it's that when a treasury restructures, giving holders a governed exit rather than only a revenue token changes who bears the downside.

References

  • THORChain Docs — Network Security and Governance (Mimir, bonding, TSS, churn, Incentive Pendulum)
  • THORChain Docs — Tokenomics of RUNE and TCY
  • THORChain Blog — Exploit Report #1 (15 May 2026)
  • THORChain — official site
Status🟢 Active
Founded2018
Websitethorchain.org
ProjectTHORChain
TokenRUNE (settlement, bond & incentive asset); TCY (revenue-share, non-governance)
CategoryCross-chain native-asset DEX / node-operated protocol
ChainsOwn Cosmos-SDK L1 settling native BTC, ETH, BNB, SOL, DOGE, and more — no wrapped or bridged assets
GovernanceNode-operator-only via the Mimir parameter-voting system (no token-holder vote); ADRs for larger changes
RUNE supply~425M total (net-deflationary via fee burn); ~350M circulating, ~75M reserve
Founded2018 (multichain mainnet 2021)
Websitethorchain.org