Monero & Zcash Trading Will Start Soon

Can or Should THORChain Censor Transactions?

Raynalytics logo
Ray

2026-10-01 — 9 min read

    Podcast
Protocol Update Podcast with Chad Barraford, Kenton and Denny

THORSday Community Podcast #239 ft. CBarraford, KentonC137 & patriotsounds | October 1, 2026 | Watch the full episode on YouTube

Raynalytics

TL;DR

  • THORChain's answer to calls for transaction censorship is technical as well as philosophical: node operators can protect the network by pausing a chain or the whole protocol when solvency is in doubt, but they cannot selectively pull out an individual swap.
  • Chad Barraford said there is no founder-controlled switch. Software releases, feature flags and network changes require node-operator adoption, with two-thirds consensus needed for major protocol decisions.
  • A recent Litecoin pause illustrated the intended safety path: a node saw suspicious outbounds, trading paused briefly, operators assessed the condition, then another node resumed activity. The control was network-wide and driven by a solvency question, not by the identity behind a transaction.
  • The hosts argued that deciding which transactions are morally acceptable would replace an objective check with a subjective power that can be expanded or abused. They framed permissionless access and no-KYC swapping as part of THORChain's core proposition.
  • Away from the debate, v3.21 was in stagenet testing. Chad said it is intended to unblock churn-related fixes, Zcash, a subsequent Monero launch path, app-layer fixes and transaction-signing work. Dynamic fees were active for ShapeShift, Symbiosis and Edge Wallet, while SwapKit revenue share still awaited fixes on SwapKit's side.

THORChain's safety design distinguishes an objective solvency halt from selective censorship. Nodes can pause a chain or network to protect funds, but the protocol has no individual-transaction blocklist control.

1. A Safety Halt Is Not a Transaction Blocklist

The question behind the episode was direct: if a transaction is associated with stolen funds or an unpopular actor, can THORChain stop it? The hosts' answer was that the protocol does not have a control for selectively removing an individual trade. It is designed to process swaps through open rules, not to judge a sender or recipient.

That does not mean nodes are powerless during a real risk event. THORChain has automatic halts and emergency pause controls because it holds native assets in validator-managed vaults. If the network's accounting does not add up, or an external chain behaves abnormally, stopping activity can be the prudent response. The key distinction the hosts made is between an objective condition, such as suspected insolvency, and an attempt to label a particular transaction good or bad.

"The math isn't mathing. Is the protocol insolvent? Is there something wrong happening? That's what triggers the halt." (Kenton)

Kenton and Denny walked through a recent external-chain incident as the practical example. A node noticed unusual outbound activity and a price discrepancy, then used the emergency control to pause operations for roughly an hour. Other operators reviewed the situation, attributed it to arbitrage conditions rather than an insolvency event, and resumed the network. A pause costs nodes fees, so it is not a neutral or profitable default. It is a defensive action when the alternative could be a larger loss.

The distinction matters because a network-wide pause is visible, costly and reversible through node consensus. A selective blocklist would be a different kind of system, one that first needs a party capable of making subjective decisions about specific users and transfers. The show argued that THORChain was not built with that capability.

https://raynalytics.net/dashboards/nakamoto-coefficient

2. The Network Can React, but No Founder Controls It

Chad used the discussion to clarify a recurring misconception about protocol controls. Mimir settings and feature flags can look like administrative powers from the outside, but he said they are ultimately governed by node operators. A developer can propose code or advocate for a setting. The validator set decides whether to run the release and whether to turn an available feature on.

"I don't determine anything that happens on the protocol. I talk about things and advocate for things, but at the end of the day, it is the nodes who operate the network." (Chad)

The current release process illustrates that separation. Before v3.21 can activate, nodes need to test and adopt it. If enough operators reject a version, the release does not proceed because forcing an upgrade without agreement could halt consensus. The same separation applies to a feature such as revenue share: code may be ready and technically switchable, but the network's operators can vote it back off if the broader set does not agree.

Chad said the network had around 115 nodes at the time of the recording, roughly 99 active and 15 standby. That is not an argument that more validators always make a system better. More nodes add communication and operational cost, while the protocol's fee-funded security model must still make running a node economically viable. But it does mean the protocol's authority is spread across independent operators rather than concentrated in its founder or a private operator group.

The hosts also pointed to examples of disagreement: contested votes around Ethereum trading during the Bybit response, nodes overriding an earlier THORFi setting, and ADR30 taking time to gather consensus. Slow or failed agreement can be frustrating. In their view, that friction is also evidence that no individual can simply impose an outcome.

THORChain's censorship debate turns on two different tests. Solvency is an objective network condition. A decision about whether a particular user or transaction is acceptable is a subjective judgment the protocol does not encode.

3. Why the Hosts Draw the Line at Objective Conditions

The episode did not deny that theft and exploitation cause real harm. The hosts repeatedly condemned the underlying crime in the Bybit case. Their argument was about the proposed remedy. Once a protocol can decide that one transaction deserves intervention, they said, someone must define the next exception, maintain the list and control how the power is used.

"The mechanism of censorship is the problem. It isn't stopping that one bad transaction that we can all agree is wrong." (Kenton)

Their comparison was to the early internet and the old cryptography debates. Open systems can be used badly, but requiring permission to access the system changes who can participate and who can be excluded. Denny argued that a censorship mechanism can be repurposed against people with unpopular views or people living under restrictive governments. Kenton made a related point: the protocol's job is to provide neutral infrastructure, not to decide who deserves access to it.

This is a philosophical claim, not a statement that risk disappears. THORChain's design still has operational risks, and the hosts acknowledged that a swap underway during an exploit or a halt can be delayed or exposed. They contrasted that bounded transaction risk with leaving a larger balance under a centralized exchange's custody. The core claim was narrower: native-asset swapping through a self-custody system should not depend on a standing permission or an identity check.

The hosts' framing also explains why they treat privacy as more than a feature request. They cited data-breach and physical-security risks around KYC databases, while noting that fiat on- and off-ramps can still impose their own requirements. THORChain itself does not require an account or KYC to submit a swap, which is the property they are defending in this debate.

The protocol's intended safety response is prevention and network solvency checks, not a selective seizure tool. Self-custody keeps the user's wider wallet outside the swap path, while a temporary pause can protect the network during a verified risk event.

4. Security Means Prevention, Not a Power to Seize

Kenton's practical response was that preventing theft is a better security goal than trying to recover funds after a theft. He described bridges and centralized venues as attractive targets because they concentrate custody. THORChain's model instead keeps users in self-custody until a specific swap is submitted, then settles that swap through the protocol's vault and outbound process.

"The solution isn't better censorship. It's better security, better prevention." (Kenton)

That design does not make every outcome perfect. The hosts said a swap can be held up during a network halt, and an exploit during the active swap window is still a risk. They also acknowledged THORFi as the event where individual users were materially affected. But they stressed that a user's separate wallet balance does not sit inside a centralized account merely because they are making a trade.

The episode's strongest claim is therefore not that THORChain can make crime vanish. It is that adding a targeted seizure mechanism would create a new attack surface, political pressure point and custody-like control, while doing little to address the upstream failures that lead to stolen funds in the first place. The network's existing safety controls are meant to protect collective solvency, not to transform nodes into transaction arbiters.

v3.21 was in stagenet testing at recording. The planned path was software validation, node adoption, a churn that can create the Zcash pool, then additional testing before a subsequent Monero launch. Fee experiments remain measured rather than assumed wins.

5. v3.21, Privacy-Chain Work and the Revenue Tests Still in Motion

The censorship discussion arrived alongside a concrete engineering update. Chad said v3.21 had reached stagenet testing and was intended to address a churn-related slashing regression, app-layer issues, BFT signing issues and transaction problems. The release still needed validation and node adoption, so none of those fixes were presented as already live at recording.

Zcash was described as ready pending a successful churn that could create its pool. Chad said the team intended to test through the weekend and following week, then move toward Monero as a fast follow only if the remaining validation held up. This is a continuation of the stability and privacy-chain work covered in Podcast #235, not a calendar promise for either chain.

"We have to run the experiment. We have some data that they're going to give us access to on their side, we have some dashboards on our side, and we'll be paying attention." (Chad)

The other live test is economic. Chad said the dynamic-fee model was active for ShapeShift, Symbiosis and Edge Wallet. Separately, a SwapKit revenue-share launch had been delayed while SwapKit addressed bugs. The proposed starting logic is to share about 20% of the revenue generated through that flow so the partner can improve quotes. Whether that creates enough additional volume to offset the giveback is the real question, not an assumed result.

The roadmap threads fit the broader theme of the episode. Release gates, pool launches and fee settings are all subject to testing and node-controlled activation. The protocol can change, but its operators are meant to make those changes through visible technical evidence and consensus rather than through a permanent discretionary control.

What to Watch

  • v3.21 validation and adoption: whether stagenet testing clears the way for node voting, the churn fix and the next release.
  • Zcash and Monero: whether Zcash reaches pool creation after churn, and whether the follow-on Monero testing supports a subsequent launch.
  • Safety controls in practice: future pauses, their stated solvency rationale and how quickly node operators reach a decision to resume.
  • Revenue experiments: dynamic-fee performance for ShapeShift, Symbiosis and Edge Wallet, plus whether SwapKit resolves its issues and launches revenue share.
  • The censorship debate: whether critics and supporters can keep the technical distinction clear between a network-safety halt and the ability to blacklist an individual transaction.
Raynalytics

More THORChain data, check out raynalytics.net

Follow Raynalytics for more Weekly Analytics and Podcast recaps.

Try the World’s Leading Bitcoin DEX

No sign up required. Easy to use.