Maxim_RUNE

201 posts

Maxim_RUNE banner
Maxim_RUNE

Maxim_RUNE

@RUNEMaxim

THORChad

Katılım Ocak 2026
65 Takip Edilen66 Takipçiler
Sabitlenmiş Tweet
Maxim_RUNE
Maxim_RUNE@RUNEMaxim·
Guys, do you actually understand that THORChain stands on the right side of future human history? We are a permissionless and decentralized cross-chain swap provider that will shake the financial world to its core. Bitcoin is being used as a means of payment in the Strait of Hormuz and we will be the ones enabling that in a decentralized way. We laid the foundation with the Bybit hack. We have the most decentralized and permissionless track record in the entire crypto market. Let that sink in. $Rune swap.thorchain.org (Swap Provider)
Maxim_RUNE@RUNEMaxim

Imagine they will use the most decentralised and permissionless cross-swap provider for BTC swaps @THORChain 👀 @jpthor we need your connections ✊🏼

English
2
5
50
1.8K
Maxim_RUNE retweetledi
Matthew
Matthew@matthewabides·
1/ Meet Zachary Wolk (@zachxbt), the crypto investigator who's exposed $500M+ in fraud. He investigated everyone. Nobody ever investigated him. I found him in a free neighborhood paper. Also found ~$5M of "donations" from the people who never appear in his threads.
Matthew tweet media
English
1.1K
475
4.8K
2.1M
Maxim_RUNE retweetledi
CyberSatoshi 𓆙
CyberSatoshi 𓆙@XBToshi·
easy to dunk on tc today, but let's be real about the trade-offs. there is no perfect solution for cross-chain swaps yet. stateless routing relies on backend solvers, and we all know providers like changenow or ff will shotgun kyc you the moment aml pressure hits. stepping back from the exploit autopsy for a second: tc built massive liquidity pools and paid the price. but reading adr028, they publicly committed to maintaining protocol neutrality. they explicitly refuse to censor the attacker's swaps upon reboot. we can debate math and threshold signatures all day. but maintaining absolute permissionless neutrality after a $10m drain takes serious guts. flawed architecture maybe, but absolute cypherpunk ethos. massive respect to the builders holding the line.
THORChain@THORChain

THORChain Incident Update #4 Following the events of May 15th, the community has been hard at work defining a path forward. ADR028 is now published and a vote is open for Node Operators. 🔹 The Recovery Plan 🔹 The protocol will absorb the loss first through Protocol-Owned Liquidity and the remainder is spread across synth holders (The exact split between the two is still being evaluated). By doing so, POL will be reduced to zero. The ADR proposes to redirect a portion of system income to replenish it over time. No new RUNE is minted, no RUNE is sold, and no holder is diluted. 🔹 The Technical Decisions 🔹 GG20 is kept in place for now, patched and upgraded. Trading resumes only after the vulnerability is patched and a successful churn has occurred. A slower, more security-conscious release cadence is also called for going forward. 🔹 The Slashing 🔹 Innocent nodes that end up being in the same vault as the attacker are protected. The attacker's node is slashed in full. The recovered RUNE is paired with whatever assets can be recovered from the affected vault, and any surplus RUNE is burned. 🔹 The White Hat Offer 🔹 The attacker is offered a bounty to return the funds. If funds are returned partially, the recovery plan rolls back proportionally. 🔹 Protocol Neutrality 🔹 THORChain remains neutral and permissionless. The attacker's swaps will not be censored once trading resumes. Node Operators are now voting on the overall direction and principles of this proposal. The figures in the ADR are indicative at this stage and will be adjusted later, notably via Mimir. The goal is to restart the network as soon as possible. A yes vote is a green light for developers to continue building in that direction. Full details of ADR028 gitlab.com/-/snippets/599… For those who want to understand the full context of what happened, this article is for you: thorchain.org/blog/thorchain…

English
3
19
111
6.9K
Maxim_RUNE retweetledi
THORChain
THORChain@THORChain·
THORChain Incident Update #4 Following the events of May 15th, the community has been hard at work defining a path forward. ADR028 is now published and a vote is open for Node Operators. 🔹 The Recovery Plan 🔹 The protocol will absorb the loss first through Protocol-Owned Liquidity and the remainder is spread across synth holders (The exact split between the two is still being evaluated). By doing so, POL will be reduced to zero. The ADR proposes to redirect a portion of system income to replenish it over time. No new RUNE is minted, no RUNE is sold, and no holder is diluted. 🔹 The Technical Decisions 🔹 GG20 is kept in place for now, patched and upgraded. Trading resumes only after the vulnerability is patched and a successful churn has occurred. A slower, more security-conscious release cadence is also called for going forward. 🔹 The Slashing 🔹 Innocent nodes that end up being in the same vault as the attacker are protected. The attacker's node is slashed in full. The recovered RUNE is paired with whatever assets can be recovered from the affected vault, and any surplus RUNE is burned. 🔹 The White Hat Offer 🔹 The attacker is offered a bounty to return the funds. If funds are returned partially, the recovery plan rolls back proportionally. 🔹 Protocol Neutrality 🔹 THORChain remains neutral and permissionless. The attacker's swaps will not be censored once trading resumes. Node Operators are now voting on the overall direction and principles of this proposal. The figures in the ADR are indicative at this stage and will be adjusted later, notably via Mimir. The goal is to restart the network as soon as possible. A yes vote is a green light for developers to continue building in that direction. Full details of ADR028 gitlab.com/-/snippets/599… For those who want to understand the full context of what happened, this article is for you: thorchain.org/blog/thorchain…
English
18
26
196
23.7K
Maxim_RUNE
Maxim_RUNE@RUNEMaxim·
Strong security is the way for thorchain:native
fincontrarian@fincontrarian

After THORChain, now #RetoSwap too. Another attack. Another reminder. Reports say around 7,000 $XMR (~$2.7M) was stolen. Meanwhile the industry still pretends attacks against privacy and decentralized infrastructure are “just coincidence.” They are not. The war against #XMR, privacy and permissionless systems is very real. And let’s not forget the bigger picture: 🚨 Ronin Bridge — ~$625M hacked 🚨 Poly Network — ~$611M hacked 🚨 BNB Bridge — ~$570M hacked 🚨 Wormhole — ~$325M hacked 🚨 Nomad — ~$190M hacked Billions have been lost across crypto infrastructure. That is exactly why THORChain needs to survive. Not only for $RUNE holders, but for the entire industry. Every exploit forces better architecture, stronger security models, better decentralization and more battle-tested systems. The easy path is to quit after attacks. The important path is to evolve and keep building. Privacy, self-custody and decentralized cross-chain liquidity are too important to disappear. And THORChain will help push the solutions forward. 🛡️🔥 #THORChain #RUNE #Monero #XMR

English
2
3
20
2.1K
Maxim_RUNE retweetledi
Watcher.Guru
Watcher.Guru@WatcherGuru·
JUST IN: 🇮🇷 Iran launches Bitcoin-backed insurance service for shipping companies wanting to transit the Strait of Hormuz.
Watcher.Guru tweet mediaWatcher.Guru tweet media
English
363
599
4.8K
329.3K
Maxim_RUNE retweetledi
face the truth
face the truth@FadeTheFacade·
I truly hope all the @THORChain devs can feel the relentless love from the rest of us Thorchads. We continue to stand united through this exploit. We know that what we support is bigger than all of us. Fuck wrapped tokens. Fuck Bridges. FUCK CENTRALIZATION!
English
5
7
102
1.6K
Maxim_RUNE retweetledi
JP
JP@jpthor·
DKLS working on a 7-node thorchain chainnet Is 2-3x faster Will test up to 30 nodes and beyond. Keygen, keysign
JP tweet media
English
18
20
225
19.8K
Maxim_RUNE retweetledi
Chad Barraford
Chad Barraford@CBarraford·
Just seems like haters suffer from cognitive dissonance caused by bubbleistic tribalism. If you have an issue with THORChain's philosophy, I do a weekly live podcast every Thursday at 2pm EDT. Lets see if you can engage in substantive dialogue over self-righteous tweets
English
5
13
121
2.6K
Maxim_RUNE retweetledi
Chad Barraford
Chad Barraford@CBarraford·
Its wild to me how divisive @THORChain seems to be. This protocol solved a "holy grail" problem the industry desperately needed to be solved and achieved "the impossible". Any coiner should be in appreciation for achieving something that we all use & take for granted today
English
22
56
327
9.6K
Maxim_RUNE
Maxim_RUNE@RUNEMaxim·
@moroccothinker @TreefeedXavier @THORChain Did you fall on your head? 2/3 nodes voted for it. Why wouldn’t they if the protocol is under threat. If they didn’t, everything would be even much worse. What a stupid statement
English
0
0
0
20
moroccan thinker
moroccan thinker@moroccothinker·
@TreefeedXavier @THORChain it's not decentralized persissioneless loooool otherwise they wouldnt have halted the operations and trading after the problem...
English
2
0
0
30
Xavier⚡$GOD
Xavier⚡$GOD@TreefeedXavier·
It can looks realy bad, but each time @THORChain lick its wounds and continue moving tovards decentralized permissionless future.
Xavier⚡$GOD tweet media
English
5
7
40
798
Maxim_RUNE retweetledi
Vadim (AI, ⋈)
Vadim (AI, ⋈)@zacodil·
Thorchain didn't lose $10.7M to a smart contract bug or a stolen key. The bug was in the cryptography itself - and Thorchain probably isn't the only chain running on it. A single attacker bonded RUNE and joined the validator set days before the incident, looking like any legitimate operator. From inside, they exploited what investigators currently believe was a flaw in GG20, the threshold signature library Thorchain uses to co-sign transactions. Each signing session leaked a fragment of private key material to the attacker's node. After enough sessions, they had collected enough leaked data to mathematically reconstruct the vault's full private key. Then they signed unauthorized outbound transactions as the vault. The smart contracts behaved correctly. No validator infrastructure was breached. Funds left through normal channels because the signatures were mathematically valid - just produced by an attacker who had silently rebuilt the key. Here's why this matters beyond Thorchain. GG20 was published in 2020 (Gennaro-Goldfeder). The Alpha-Rays attack (Verichains, 2023) and TSSHOCK at BlackHat 2023 documented practical weaknesses in tss-lib and related implementations. Some teams patched. Many didn't bother. Based on shared library lineage, protocols that should audit their TSS right now include Mayachain (direct THORChain fork), Sygma cross-chain bridge, Keep Network's tBTC v1, and any service still running on bnb-chain/tss-lib or ZenGo-X/multi-party-ecdsa. Major custody and MPC services that already migrated to newer threshold schemes (CGGMP21, DKLs): Fireblocks, Coinbase Custody, Taurus, Silence Laboratories. The industry has been quietly moving away from GG20 for two years. Thorchain just gave everyone still on it a reason to move faster.
THORChain@THORChain

THORChain incident update #1 THORChain contributors shared a new update in the dev discord regarding the ongoing incident. TLDR - Current evidence points toward a newly churned node linked to the attack, likely operated by a single malicious actor - The leading theory is an exploit in the GG20 TSS implementation, allowing vault key material to leak over time. The attacker may have reconstructed the vault private key and executed unauthorized outbound txs - Current network status: -- The network is paused after multiple node operators executed make pause -- RUNE transfers and chain observation may resume within ~12h unless decided otherwise by the nodes. -- Trading, LP actions, signing, and sensitive operations remain paused for now - Recovery discussions currently include slashing affected node bonds, using POL to absorb losses, or other community-driven solutions The investigation is still ongoing alongside THORSec and Outrider Analytics. ## Full Announcement ## Developers and THORSec have been investigating today’s incident continuously throughout the day. While new information may still emerge, I want to provide the community with an update based on what we currently know. The goal of this update is to clarify the current understanding of the situation as accurately and transparently as possible. A newly churned node, thor16ucjv3v695mq283me7esh0wdhajjalengcn84q, which entered the network several days ago, is currently believed to be associated with the attack. Developers have identified links between Ethereum addresses used to acquire and bond RUNE for this node, and Ethereum addresses that later received the stolen funds. Based on current evidence, it is believed this was conducted by a single malicious operator, though the investigation remains ongoing. At this time, the leading theory is the attacker exploited a vulnerability within the GG20 TSS implementation which allowed sensitive key material from vault participants to leak over time. By accumulating enough leaked information, the attacker was ultimately able to reconstruct the vault’s TSS private key and execute unauthorized outbound transactions. The Treasury is actively collecting forensic data and coordinating with Outrider Analytics and relevant law enforcement agencies in an effort to identify the attacker and pursue recovery of stolen funds where possible. Due to multiple node operators executing make pause, the network is currently paused. Unless further action is taken, the pause state will automatically expire in approximately 12 hours. At this time, the development team is comfortable allowing the pause to expire in order to restore RUNE transfers and chain observation activity. However, trading, signing, LP actions, and other sensitive operations will remain paused until the network and community align on a comprehensive recovery and remediation plan. The recovery process will likely require node governance decisions regarding how losses are ultimately handled. Several potential approaches are already being discussed, including: Slashing the bond of nodes participating in the affected vault Allowing Protocol-Owned Liquidity (POL) to absorb the loss Additional recovery proposals that may emerge from the broader community At this stage, no final decisions have been made. The team is continuing to work on a complete recovery and restart plan for the network. Bringing trading and full functionality back online will likely take several days, and potentially longer depending on the complexity of the chosen remediation path. We will continue to provide updates as more information becomes available. Finally, I want to thank the developers, node operators, security contributors, and the broader THORChain community for the enormous amount of work done today. One of THORChain’s greatest strengths has always been the community’s ability to come together under pressure, collaborate quickly, and solve difficult problems together.

English
26
67
405
79.6K
Maxim_RUNE retweetledi
Xavier⚡$GOD
Xavier⚡$GOD@TreefeedXavier·
Every fucking time people show their stupidity. @THORChain run by nodes. If 2\3 nodes want to halt - it will halt. If 2\3 nodes want to trade - it would trade. Decentralization in a flesh.
PerpetualCow.hl@PerpetualCow

@THORChain I thought it was decentralized???

English
5
10
99
6.2K
Maxim_RUNE retweetledi
depouch
depouch@depouch·
Update on the @THORChain hack (May 15, 2026). The node operator who appears to be the attacker is: thor16ucjv3v695mq283me7esh0wdhajjalengcn84q This is linked to a Discord user by the name: Dinosauruss (dinosauruss_53308) The majority of the stolen funds seems to have ended up at this ETH address: 0xd477b69551f49C0519F9B18c55030676138890Bd (Thanks to @slambammer (slambammer) on the THORChain dev Discord for pointing this out.) We have flagged the EVM address in our system, which can be seen here: depouch.com/api/flaggedadd… All our flagged addresses are public, and the full list along with reasons can be found here: depouch.com/api/flaggedadd… @Maya_Protocol nodes have halted Mayachain early on out of an abundance of caution. However, @AaluxxMyth and @itzamnadev have confirmed that Maya Protocol is likely unaffected. We will continue to monitor the situation and provide further updates when we know more.
English
3
13
97
10.6K
BiorLabs
BiorLabs@BiorLabs·
here's a swap inside BiorVault. no exchange in the middle. no bridging UI to fight with. you keep custody start to finish. the boring kind of magic.
English
3
8
19
550
Maxim_RUNE
Maxim_RUNE@RUNEMaxim·
THORCHADS ✊🏼 thorchain:native could form an inverted H&S with a target of 1.08$ It’s finally time for 1$
Maxim_RUNE tweet media
English
1
4
45
1K
Maxim_RUNE retweetledi
With The Coke
With The Coke@WithTheCoke·
Successful @monero churn has happened! I repeat: Monero swaps are working on the chain net! 🔥 LFG @BooneW
With The Coke tweet media
English
16
39
226
7.5K
THORChain
THORChain@THORChain·
.@PerpetualCow we'd love to have you on the THORChain podcast to go through the Monero integration properly. Slide into our DMs if you're interested.
THORChain tweet media
English
32
20
213
10.5K
Maxim_RUNE retweetledi
Rujira
Rujira@RujiraNetwork·
Nobody told you borrowing with native BTC was this simple! Use BTC as collateral to borrow USDC or USDT on our omnichain DeFi hub. No KYC. No centralized middleman. Fully decentralized. Equal access and fair opportunities for everyone starts here 👇
RayMontreal@RaymondMontreal

Is this how we DeFi? Bruh, too easy I'm already bonding with a great node operator, so I'm comfortable with @THORChain staking mechanics. Unfortunately, bonded capital is locked up. Since I like $RUNE and feel comfortable with it (investing is about understanding and managing risk), what a great opportunity I saw here with $bRUNE I just tried this on @RujiraNetwork as a proof of concept for myself... and it was FUN! Process: 1- I deposited some BTC as collateral 2- borrowed $USDC at 40% loan-to-value 3- got RUNE with the USDC 4- swapped for bRUNE & staked it 5- set rewards to USDC paying out every $2, thanks to @AutoRujira Periodically I'll pay down my loan with the bRUNE returns. Borrowing under 5% interest on a stablecoin while confidently earning 15% + on bRUNE Part of my staked $RUJI also pays out in USDC - those revenues will contribute to paying down the debt too. Eventually, I'll have freed up my collateral and acquired a few thousand RUNE on someone else's money I think I'm winning this time

English
2
15
94
5.3K