Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia How the network works · Entry 392

What a 51% attack can and cannot do to Bitcoin

Theme
How the network works
Sources
8 cited records
Reading time
About 9 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for What a 51% attack can and cannot do to Bitcoin
FactDetailSource
What it takesA sustained majority can outpace the remainder in expectation; a smaller share can still succeed probabilistically[1][2]
What it allowsReversing the attacker’s own recent transactions; keeping others out of blocks[2][1]
What it does not allowSpending other people’s coins or creating coins out of thin air[1][5]
GHash.io concentrationContemporary researchers, as reported by CoinDesk, estimated GHash.io near 55% for almost 24 hours on 12–13 June 2014[4]
GHash.io’s pledgeTo stay under 39.99% of the network, July 2014[4]
Bitcoin Gold, May 2018Roughly $18 million double-spent against exchanges[7]
Ethereum Classic, August 2020More than 3,000 blocks rewritten; about 800,000 ETC double-spent[8]
Historical reporting limitThe attack model does not establish a complete historical census of attempts or successes[2]
01

A majority of hash power, not of coins, nodes or people

Bitcoin’s chain is extended by miners, who compete to find the next block by running enormous numbers of hashing calculations. Hash rate is the speed of that guessing across the whole network. Whoever finds a valid block first decides which transactions go in it, and the network follows the chain with the most accumulated work. So a miner with more than half of the hash rate will, over time, build a longer chain than everyone else combined. That is the whole basis of the attack, and it is why it is measured in hash power rather than in coins owned or nodes run. How mining works and what hash rate is each have their own article.

The white paper anticipated this in 2008. Its security argument is explicitly conditional: the system is secure “as long as honest nodes collectively control more CPU power than any cooperating group of attacker nodes.” Section 11 then asks what happens if that condition fails and an attacker generates an alternate chain faster than the honest one. The answer is narrower than most people expect.

02

What a majority can do: rewrite recent blocks and refuse to include transactions

Because the attacker can out-build the honest chain, they can mine a private branch and release it later to replace the public one. Any transaction in the replaced blocks that is not also in the attacker’s branch simply vanishes from history. That lets the attacker pay someone, wait for the payment to confirm, collect whatever was bought, then publish a branch in which the same coins were sent back to themselves instead. That is the double spend, and the Bitcoin Wiki notes that with more than half of the hash rate it succeeds with certainty, given enough time.

The wiki adds the uncomfortable corollary: no number of confirmations can prevent it, though waiting for more raises the attacker’s cost, because they must redo more blocks. A majority miner can also censor. By refusing to include certain transactions, and by orphaning blocks that other miners find, they can keep chosen payments off the chain for as long as they keep the majority. Both powers last only while the hash power lasts.

03

What it cannot do: steal coins, mint coins or change the rules

Here the white paper is unusually direct. Out-mining the network “does not throw the system open to arbitrary changes, such as creating value out of thin air or taking money that never belonged to the attacker.” Every node checks every block against the rules, and a block that spends coins without a valid signature, or pays a miner more than the schedule allows, is rejected by every honest node no matter how much work sits behind it. An attacker “can only try to change one of his own transactions to take back money he recently spent.”

Two economists at the Federal Reserve Bank of New York made the same point in November 2014: a majority miner could refuse to validate transactions or reverse their own, but “no one can add false transactions to the blockchain.” That is the job of nodes, not miners. It also means the supply cap is out of reach; a majority miner cannot award themselves extra coins, because the 21 million limit is enforced by every node that validates. Changing the rules themselves is a different thing entirely, covered in soft forks and hard forks.

04

A historical concentration episode: GHash.io in June 2014

In June 2014 a single mining pool, GHash.io, grew large enough to test the theory. Researchers writing at the Hacking, Distributed blog recorded it holding about 55 percent of the network’s hash rate for almost 24 hours, from 12 June to 13 June 2014, as CoinDesk reported the following month. A pool is not a single miner; it is thousands of miners pointing their machines at one coordinator, who could in principle direct all of that power. (See how pools work.) The cited pool statement denied participation in a majority attack; that is the operator’s statement, not an audit of every payment.

The pool’s operator, CEX.IO, put out a statement within days: “We never have and never will participate in any 51% attack or double spend against bitcoin.” By then the pool’s share had fallen to about 31 percent. It called for a round table of large pools and industry figures, which met in London on 9 July 2014. Out of that came a public pledge that GHash.io would keep its share under 39.99 percent of the network. CoinDesk’s Jon Matonis noted at the time that the pledge was “very unenforceable,” and that by 13 July the pool’s share had already fallen to about 34.6 percent as miners left.

The New York Fed economists framed why a pool in that position might not attack even if it could: a majority miner earns a large, steady income from block rewards, and an attack that visibly broke Bitcoin would collapse the value of the thing being mined. Their calculation was dated 2014 and the numbers have changed since, but the shape of the argument has not. Whether it still holds as the block subsidy halves is a question they raised themselves.

05

Where it has actually happened: smaller proof-of-work coins

On smaller coins the attack is not theoretical. In May 2018 Bitcoin Gold, a coin that had forked from Bitcoin, was hit by an attacker who gained majority hash power and double-spent deposits at exchanges, roughly $18 million worth by CoinDesk’s later accounting. Exchanges had been crediting deposits after five confirmations; afterwards they raised the requirement to 50. That spring CoinDesk listed Monacoin, Zencash, Verge and Litecoin Cash as also attacked, and pointed at the enabling condition: marketplaces such as NiceHash let anyone rent a large amount of hash power for a few hours.

Bitcoin Gold was hit again on 23 January 2020, twice in one day, with two chain reorganizations involving attempted double spends of about 1,900 and 5,267 BTG. The Bitcoin Gold team said it did not know whether the attacker successfully withdrew value from an exchange. James Lovejoy, a researcher at the MIT Digital Currency Initiative, traced the attacker’s mining address and estimated the rented hash power cost about 0.2 bitcoin per reorganization, roughly what the attacker earned back in block rewards. Ethereum Classic suffered worse in August 2020: a reorganization of more than 3,000 blocks that double-spent slightly over 800,000 ETC, worth about $5.6 million, using hash power that cost about 17.5 bitcoin, followed five days later by a second reorganization of more than 4,000 blocks. Its developers urged exchanges to “significantly raise confirmation times.”

The pattern is consistent. The attack works where hash rate is cheap to rent relative to what can be stolen, and the practical defense is to make the target wait longer than the attacker can afford. Bitcoin has a different hardware market and hash-rate scale; these smaller-chain incidents do not establish a reproducible present attack cost or a complete history of Bitcoin attacks.

06

Why “51 percent” is a simplification in both directions

Less than half can still work, sometimes. The white paper’s table shows an attacker with 30 percent of the hash rate has about a 4 percent chance of reversing a payment buried ten blocks deep, and the payment needs to be 24 blocks deep before the chance falls below 0.1 percent. That is why exchanges vary their confirmation requirements with the size of a deposit. Equally, more than half does not mean success is instant; the attacker still has to out-mine the honest chain from behind, and the deeper the target, the longer it takes.

The documented bugs and accidental splits that reorganized Bitcoin’s chain are catalogued in our consensus incidents dossier. They are worth reading next, because they show what recovery looks like when it is validity rules, not raw hash power, that decide which chain survives.

Direct answers

Questions people ask

Has Bitcoin ever had a 51% attack?

The cited historical reporting discusses GHash.io’s 2014 concentration and attacks on smaller chains. It is not a complete audit of every Bitcoin payment, so this entry does not claim to prove that no double spend or majority attack ever occurred.

Could a 51% attacker steal my bitcoin?

No. The white paper is explicit that even an attacker who out-mines the network cannot take money that never belonged to them or create coins from nothing, because every node rejects invalid transactions. The attack is limited to reversing the attacker’s own recent payments and keeping transactions out of blocks.

How much would a 51% attack on Bitcoin cost?

There is no reliable single figure, because it depends on the hash rate at the time and whether that much hardware can be rented at all. The August 2020 attack on Ethereum Classic used rented hash power costing about 17.5 bitcoin; the cited material does not supply a reproducible current cost for an equivalent attempt on Bitcoin.

What do exchanges do to protect against 51% attacks?

They raise the number of confirmations required before crediting a deposit, which forces an attacker to rewrite more blocks. After the May 2018 Bitcoin Gold attack, exchanges went from five confirmations to 50, and Ethereum Classic developers asked exchanges to significantly raise confirmation times after the August 2020 attacks.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

A majority-hash attack uses enough computing power to outpace the honest chain over time, enabling censorship or attempts to reverse the attacker’s payments. Even a higher-work chain must satisfy node validation rules: hash power alone cannot forge signatures or exceed permitted issuance. Less than half of hash power can still give a probabilistic chance of a reorganization, so 51 percent is not a threshold below which every payment is safe.

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
What it takes: A sustained majority can outpace the remainder in expectation; a smaller share can still succeed probabilistically

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
What it allows: Reversing the attacker’s own recent transactions; keeping others out of blocks

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
What it does not allow: Spending other people’s coins or creating coins out of thin air

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
GHash.io concentration: Contemporary researchers, as reported by CoinDesk, estimated GHash.io near 55% for almost 24 hours on 12–13 June 2014

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
GHash.io’s pledge: To stay under 39.99% of the network, July 2014

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
Bitcoin Gold, May 2018: Roughly $18 million double-spent against exchanges

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
Ethereum Classic, August 2020: More than 3,000 blocks rewritten; about 800,000 ETC double-spent

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
Historical reporting limit: The attack model does not establish a complete historical census of attempts or successes

Scope: Bitcoin. Verification: verified · 2026-10-02T16:01:48.343Z.

Link to this claim
Revision history
  1. — Initial Bitcoin encyclopedia entry at this permanent URL.
  2. — Revised direct answer to preserve source scope and qualifications. Corrected key fact: What it takes Corrected key fact: Historical reporting limit Corrected FAQ: Has Bitcoin ever had a 51% attack? Corrected scope or wording: nobody has done the equivalent on Bitcoin, and the wiki records no successful attempt Corrected scope or wording: Nobody alleged that GHash.io did anything with it. Corrected scope or wording: Bitcoin’s own hash rate is what makes the same arithmetic prohibitive there, and it i Corrected scope or wording: The incidents that have actually rewritten Bitcoin’s chain were not attacks at all bu Corrected scope or wording: two chain reorganizations that double-spent about 1,900 and 5,267 BTG. Corrected scope or wording: The closest call on Bitcoin: GHash.io in June 2014 Corrected key fact: GHash.io concentration Removed categorical no-attack and attack-cost conclusions, attributed historical hash-share estimates, and distinguished attempted reorganizations from proven exchange losses.
  3. — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Bitcoin: A Peer-to-Peer Electronic Cash SystemSatoshi Nakamoto · 2008bitcoin.org

    Section 11 states that a majority attacker cannot create value or take others’ money, only reverse their own recent spends, and tabulates attacker success by hash-power share and depth.

    Locator: Section 11 states that a majority attacker cannot create value or take others’ money, only reverse their own recent spends, and tabulates attacker success by hash-power share and depth. · Retrieved: 2026-10-02T15:04:11.761440+00:00Open source
  2. Majority attackBitcoin Wiki

    Describes the attack, states that no number of confirmations prevents it but waiting raises the cost, and records that it has never succeeded on Bitcoin though it has on small altcoins.

    Locator: Describes the attack, states that no number of confirmations prevents it but waiting raises the cost, and records that it has never succeeded on Bitcoin though it has on small altcoins. · Retrieved: 2026-10-02T14:48:51.169678+00:00Open source
  3. Ghash.io: We Will Never Launch a 51% Attack Against BitcoinPete Rizzo · 2014-06-16CoinDesk (reporting)

    Reports CEX.IO’s statement that it never has and never will take part in a 51% attack, its call for a round table, and that the pool held about 31% at the time.

    Locator: Reports CEX.IO’s statement that it never has and never will take part in a 51% attack, its call for a round table, and that the pool held about 31% at the time. · Retrieved: 2026-10-02T14:48:53.658996+00:00Open source
  4. The Bitcoin Mining Arms Race: GHash.io and the 51% IssueJon Matonis · 2014-07-17CoinDesk (reporting)

    Reports GHash.io at 55% for almost 24 hours on 12 to 13 June 2014, the London round table of 9 July, the 39.99% pledge, and the fall to about 34.6% by 13 July.

    Locator: Reports GHash.io at 55% for almost 24 hours on 12 to 13 June 2014, the London round table of 9 July, the 39.99% pledge, and the fall to about 34.6% by 13 July. · Retrieved: 2026-10-02T14:48:53.639914+00:00Open source
  5. Bitcoin: How Likely Is a 51 Percent Attack?Rod Garratt and Rosa Hayes · 2014-11-24Liberty Street Economics, Federal Reserve Bank of New York

    Explains that a majority miner can refuse or reverse transactions but cannot add false ones, notes GHash.io briefly exceeding half in June 2014, and argues future rewards deter an attack.

    Locator: Explains that a majority miner can refuse or reverse transactions but cannot add false ones, notes GHash.io briefly exceeding half in June 2014, and argues future rewards deter an attack. · Retrieved: 2026-10-02T14:48:51.761708+00:00Open source
  6. Blockchain’s Once-Feared 51% Attack Is Now Becoming RegularAlyssa Hertig · 2018-06-08CoinDesk (reporting)

    Reports the May 2018 attacks on Bitcoin Gold and other coins, exchanges moving from five to 50 confirmations, and the role of rented hash power from NiceHash.

    Locator: Reports the May 2018 attacks on Bitcoin Gold and other coins, exchanges moving from five to 50 confirmations, and the role of rented hash power from NiceHash. · Retrieved: 2026-10-02T14:48:53.621008+00:00Open source
  7. Bad Actors Rent Hashing Power to Hit Bitcoin Gold With New 51% AttacksDaniel Palmer · 2020-01-27CoinDesk (reporting)

    Reports the two 23 January 2020 reorganizations double-spending about 1,900 and 5,267 BTG, James Lovejoy’s estimate of about 0.2 BTC per attack in rented hash power, and the roughly $18 million May 2018 attack.

    Locator: Reports the two 23 January 2020 reorganizations double-spending about 1,900 and 5,267 BTG, James Lovejoy’s estimate of about 0.2 BTC per attack in rented hash power, and the roughly $18 million May 2018 attack. · Retrieved: 2026-10-02T14:48:53.437971+00:00Open source
  8. Ethereum Classic Suffers Second 51% Attack in a WeekSebastian Sinclair · 2020-08-06CoinDesk (reporting)

    Reports a reorganization of more than 3,000 blocks double-spending about 800,000 ETC (about $5.6 million) with hash power costing about 17.5 BTC, a second of more than 4,000 blocks, and developers’ advice to raise confirmation times.

    Locator: Reports a reorganization of more than 3,000 blocks double-spending about 800,000 ETC (about $5.6 million) with hash power costing about 17.5 BTC, a second of more than 4,000 blocks, and developers’ advice to raise confirmation times. · Retrieved: 2026-10-02T14:48:53.855643+00:00Open source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “What a 51% attack can and cannot do to Bitcoin.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/51-percent-attack/