Web3 security company GoPlus has challenged THORChain’s claims of decentralization after examining the decentralized exchange’s role in processing cryptocurrency linked to North Korean hackers, reopening a long-running debate over censorship resistance and responsibility in permissionless financial protocols. In research published September 27, GoPlus examined how funds attributed to North Korea’s Lazarus Group moved through THORChain following major cryptocurrency thefts.
The security company argues that although THORChain describes itself as decentralized and permissionless, important parts of the ecosystem — including interfaces and infrastructure used to access the protocol — can still exercise meaningful control. That distinction, GoPlus said, complicates claims that nothing can be done when sanctioned or stolen funds pass through THORChain. The analysis does not allege that THORChain itself participated in the underlying hacks. Instead, it focuses on how a decentralized protocol should respond when blockchain analytics identify assets associated with sanctioned entities.
Bybit Hack Put THORChain Under Scrutiny
The issue became particularly prominent following the $1.5 billion Bybit hack in February 2025, which the FBI formally attributed to North Korean state-sponsored actors known as TraderTraitor. Blockchain researchers found that substantial portions of the stolen assets subsequently passed through THORChain as attackers attempted to exchange ETH and other assets into Bitcoin and additional cryptocurrencies. THORChain recorded extraordinary activity during the laundering process. In the days following the Bybit theft, the protocol processed billions of dollars in swaps, generating millions of dollars in fees for liquidity providers and network participants.
The episode triggered an internal dispute among THORChain contributors over whether addresses associated with the hackers should be blocked. One validator temporarily stopped participating amid disagreement over the handling of the transactions, while developer Pluto announced his departure from the project. THORChain ultimately continued processing transactions. Supporters of that decision argued that the protocol was designed to operate without selectively discriminating between users or transactions. GoPlus now argues that the situation is more complicated than a simple choice between decentralization and censorship.
Protocol and Interface Decentralization Are Different
The central issue in GoPlus‘s analysis is the distinction between the underlying blockchain protocol and the infrastructure surrounding it. THORChain allows native assets on different blockchains to be exchanged without using wrapped tokens or a centralized custodian. Validators collectively operate the network, while liquidity providers supply assets used for swaps. The protocol itself is intended to be permissionless. However, users frequently access decentralized protocols through websites, APIs, routing services and other interfaces. Those components can have different governance structures and potentially implement compliance controls even when the underlying blockchain remains censorship-resistant.
GoPlus argues that this creates multiple layers of decentralization rather than a binary distinction between centralized and decentralized systems. The debate carries increasing regulatory significance because North Korean hacking groups remain among the most sophisticated actors targeting cryptocurrency infrastructure. The FBI attributed the Bybit theft to North Korea in February 2025, while U.S. authorities have repeatedly sanctioned cryptocurrency addresses and services linked to DPRK money laundering.
More recently, security researchers attributed the April 2026 KelpDAO bridge attack, which resulted in the loss of 116,500 rsETH worth approximately $292 million, to North Korea-linked TraderTraitor actors. For decentralized exchanges, the challenge is structural. Implementing address screening at the protocol level could reduce the ability of sanctioned actors to use a network but would introduce mechanisms capable of discriminating between transactions. Maintaining complete permissionlessness preserves censorship resistance but can also leave the infrastructure available to sophisticated money-laundering operations. GoPlus’s criticism therefore extends beyond THORChain. As regulators and blockchain-security companies become increasingly capable of tracing illicit funds in real time, decentralized protocols face pressure to explain where — if anywhere — intervention should occur. THORChain’s experience demonstrates the unresolved trade-off: a protocol can be technically capable of processing transactions without permission while still relying on people, interfaces and infrastructure whose degree of control is considerably more complicated.