51% Attack

Definition

A 51% attack (also called a majority attack) occurs when a single entity or coordinated group of miners/validators gains control of more than 50% of a proof-of-work blockchain’s total hash rate (or a comparable majority of PoS stake), enabling them to manipulate the blockchain’s consensus mechanism. With majority control, an attacker can double-spend coins (spend the same funds twice), reverse recent transactions, prevent new transactions from being confirmed, and selectively censor blocks – effectively taking temporary control of the network’s history and present. While major networks like Bitcoin and Ethereum are economically impractical to attack, smaller PoW chains (Ethereum Classic, Bitcoin Gold, Vertcoin) have suffered real 51% attacks causing millions in losses.

Read Also: Spot Trading

Origin & History

DateEvent
2008Satoshi Nakamoto addresses majority attack risk in Bitcoin white paper
2014GHash.io mining pool reaches 51% of Bitcoin hash rate briefly; community responds by redistributing
2018Bitcoin Gold (BTG) suffers 51% attack; $18 M double-spent
2019Ethereum Classic (ETC) hit by a 51% attack (three further attacks followed in 2020); ~$1.1M double-spent
2020Vertcoin, Feathercoin, and other small PoW chains repeatedly attacked
2020Ethereum Classic suffers again; OKEx and Bitfinex lose ~$7.3M in double-spends (Coinbase was not targeted)
2021Bitcoin SV (BSV) hit by 51% attack; 100+ blocks reorganised
2022Ethereum transitions to PoS (Merge); 51% attack cost rises to $20 B+
“An attacker that controls more than half the network’s CPU power… can spend a coin then take it back.”
Satoshi Nakamoto, Bitcoin White Paper

How It Works

Attack Cost (2024 Estimate)NetworkHash Rate Requirement
~$1 M/hourEthereum Classic (ETC)51% of ETC network
~$5 M/hourBitcoin Cash (BCH)51% of BCH network
~$700 M/hourBitcoin (BTC)51% of BTC network – near-impossible
Near-infiniteEthereum (PoS)Control 1/3+ of ETH stake + social fork risk

In Simple Terms

  1. Majority = control– In a PoW blockchain, the longest chain wins. Controlling 51%+ of mining power means you can build the longest chain and overwrite recent history.
  2. Double spend– Attacker pays exchange for BTC, withdraws goods, then rewinds the blockchain to before the payment – keeping both the goods and the BTC.
  3. Censorship– With majority hash rate, an attacker can refuse to include any specific transaction, effectively blacklisting addresses.
  4. Cannot create coins from nothing– Even a 51% attacker cannot generate coins beyond the protocol’s rules or steal from unrelated wallets; they can only rearrange recent transactions.
  5. Economic deterrence– On large networks, the cost of renting or owning majority hash rate far exceeds potential double-spend profits, making attacks economically irrational.

Real-World Examples

ScenarioImplementationOutcome
GHash.io (2014)Mining pool hits 51% of Bitcoin hashCommunity pools redistributed; no attack executed
Bitcoin Gold (2018)Attacker rents hash power; reorganises chain$18 M double-spend against exchanges
Ethereum Classic x3 (2019–2020)ETC’s low hash rate exploited repeatedly~$1.1M (2019) + ~$7.3M (2020) double-spent; exchanges raise ETC confirmations
Bitcoin SV (2021)100+ block reorganisationMassive chain disruption; exchange deposits reversed
Nicehash rental attacksAttacker rents hash power from NiceHash marketplaceSmall PoW coins repeatedly targeted

How Networks Defend Against 51% Attacks

DefenseMechanismExample
High hash rateMakes attack expensiveBitcoin ($700M+/hr)
Proof of StakeAttack requires owning large stake; slashableEthereum post-Merge
Delay confirmationsExchanges wait 6–100+ blocks for high-value TXKraken waits 1,500 ETC blocks
CheckpointingCentralised or PoS checkpoints prevent deep reorgsETC MESS algorithm
Merged miningPiggybacks on larger chain’s securityNamecoin on Bitcoin

Disadvantages & Risks

RiskDetail
Exchange lossesPrimary target is exchange deposits during confirmation window
Chain credibility damageRepeated attacks destroy user confidence
Network haltAttacker can prevent any new transactions from confirming
Mining pool concentrationEven without attack intent, large pools approach dangerous thresholds

Risk Management Tips:

  • Exchanges should require 100+ confirmations for small PoW chains
  • Investors should evaluate network hash rate and hash rate distribution before holding small PoW coins
  • Prefer large PoW or PoS networks with proven economic security

FAQ

Can Bitcoin be 51% attacked?

Theoretically yes; practically near-impossible. The cost exceeds $700 million per hour and would require owning/renting more mining power than all of Bitcoin’s network – hardware that doesn’t currently exist.

Does 51% control let an attacker steal from any wallet?

No. The attacker can only reorganise recent transaction history. They cannot forge signatures to steal from wallets they don’t control.

Is Ethereum immune to 51% attacks after the Merge?

Post-Merge, a 51% stake attack requires owning $20 B+ in ETH (slashable), and a successful attack would likely destroy the value of that stake – extreme economic deterrence.

What is a Goldfinger attack?

A theoretical variant where an attacker’s goal is to destroy the network’s value (e.g., short-selling the asset) rather than profit from double-spends – economically viable against small chains.

How many confirmations should I wait on a small PoW chain?

Security researchers recommend at least 1,500+ confirmations for chains like ETC that have been attacked. Check exchange policies for each chain.

Sources

  • Satoshi Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System” (2008)
  • Crypto51.app – real-time 51% attack cost estimates
  • Coinbase engineering blog – “Ethereum Classic 51% attack” (2020)
  • Messari research on PoW network security

News & Events