Skip to content
Saturday, August 29, 2026 · Global Edition
L4 News
BLOCKCHAIN · WEB3 · ASSETS
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
Home / Blockchain

What is a 51% attack?

A 51% attack is what happens when one party commands most of a blockchain's power — it can rewrite recent history, but far less than headlines imply.

One large voting bloc dominating a sparse town assembly hall
A 51% attack is one side of the room outvoting the rest — possible in small rooms, costly in large ones.

A 51% attack is what happens when a single miner or coordinated group controls a majority of a blockchain's computing power or stake, and uses it to rewrite recent history. The attacker can double-spend coins and censor transactions. The attack cannot steal other people's funds, change the rules, or create coins out of thin air.

The standing disclaimer first: L4 News publishes information, not investment advice. Crypto assets can lose most or all of their value quickly, and nothing on this site is a reason to buy any of them. This article explains an attack on networks, not a case for or against any asset.

How does a 51% attack actually work?

The attacker quietly mines a private branch of blocks while the honest network builds its public one. Because the attacker controls most of the hashing power, the private branch eventually grows longer, and the network's own rules force everyone to switch to it. The rewritten stretch is where the double-spends live.

The classic script has four moves. The attacker deposits coins to an exchange and lets it see the payment confirm; privately, they build a parallel version of history in which those same coins went elsewhere; they withdraw real goods or different coins from the exchange; then they release the longer branch. The network adopts it, the deposit vanishes from the official history, and the exchange is short what it released. The 2018 NIST overview of blockchain technology describes this majority-power exposure plainly: whoever commands most of the work can define the recent past.

Why 51 and not 90? A majority simply means winning the block race on average rather than occasionally. That is enough to overtake the honest branch eventually — and the deeper the intended rewrite, the more work it takes, which is why attacks rewrite hours, never years.

Has a 51% attack ever actually happened?

Yes, several times, and not on the giants. Bitcoin Gold suffered one in May 2018, with double-spends totalling around 18 million dollars per analyses published that month. Ethereum Classic was attacked in January 2019 — Coinbase detected deep reorganizations, paused deposits and attributed about 1.1 million dollars in double-spends to it — and again in August 2020.

The pattern repeats: the victims are proof-of-work chains with modest mining power, and the weapon is often rented. Marketplaces let anyone hire hashing capacity by the hour, so an attacker does not need to own hardware — just enough budget to out-muscle a small network for an afternoon.

The aftermath also repeats. Exchanges raise confirmation counts for the affected chain, or suspend it; some delist. The chain itself usually survives with a scar, its history intact apart from the rewritten stretch, because the attack never touches the parts of the protocol that matter long-term.

How close has Bitcoin itself come?

Uncomfortably close, once. In June 2014 the mining pool GHash.io briefly controlled more than half of Bitcoin's total hashrate, according to contemporaneous mining data, and publicly pledged afterward to keep its share capped. No majority attack on Bitcoin has ever been carried out; the episode remains a warning, not a precedent.

Bitcoin's defense since then has been size. Its mining industry is distributed across continents, pools watch each other's shares nervously — customers fled GHash.io after the episode — and the cost of majority hardware or rented power tracks the size of the industry itself. Concentration remains a studied risk, but a stranger one: nobody has crossed the line since.

What would it mean for users of large chains?

So far, history and economics both say: not much, most of the time. Overwhelming a major chain means out-spending its entire global mining industry, and renting that much power is rarely feasible for the largest networks. Exchanges also respond fast, raising confirmation counts for chains that show reorganizations. Smaller chains stay the realistic targets.

The risk to a user of a large chain is therefore indirect: brief congestion, exchange delays, ugly headlines. For a user of a small chain, the practical exposure is a payment to someone attentive enough to accept it before enough confirmations — which is exactly what high-value recipients wait through.

None of this is a promise. Security budgets shift as subsidies halve and fee markets evolve, and researchers argue about the long-term arithmetic in papers and post-mortems alike. The honest summary for a newcomer: majority attacks are a demonstrated, priced-in risk on small chains and an unrepeated one on the giants, and the gap between those two words is the security budget.

What can an attacker not do with 51%?

Take your coins or rewrite the law. A majority cannot spend funds it lacks keys for, cannot mint beyond the schedule, and cannot change the protocol — nodes, not miners, enforce the rules by refusing invalid blocks. It can censor, reorder recent history and double-spend its own coins. That list ends there.

Think of a majority miner as a newspaper printer who can reorder today's pages — the analogy breaks down here: printers can also invent stories, while an attacker's blocks must still pass every rule check on every node, or the network discards them instantly. The miner produces the paper; the nodes are the law.

An attacker with 51% canAn attacker with 51% cannot
Double-spend the attacker's own coinsSpend coins from wallets it has no keys for
Censor transactions by skipping themChange supply schedules or consensus rules
Reorder the most recent blocksRewrite deep, long-settled history
Shake confidence and cause delistingsSeize balances, freeze wallets, or mint freely

For readers, the proportions matter. A 51% attack is a real, demonstrated threat to small networks and a mostly theoretical one for the largest — and in both cases it is an attack on ordering, not on ownership.

Jacob Hoffman

Independent editorial contributor focused on AI, cybersecurity, digital privacy, technology explainers.

Jacob Hoffman approaches crypto and AI with curiosity, but starts with the question most people skip: what could go wrong?

More about Jacob Hoffman

Frequently Asked Questions

Could a 51% attack happen on Bitcoin today?
Not impossible, but it has never been done. It would mean out-computing the entire honest mining industry on the largest proof-of-work network, then profiting before exchanges halt deposits — a poor trade on paper. The realistic targets are chains with small, rentable mining power.
Does a successful attack mean the chain is worthless?
It means the chain's security budget was too small for its exposure, at least that week. Ethereum Classic kept operating through attacks in 2019 and 2020, and services adapted by raising confirmation counts. Worth is a market question; the security lesson is an engineering one.
Can proof-of-stake chains suffer 51% attacks?
The equivalent exists: a majority of staked coins could finalize conflicting histories. But the attack requires buying or corrupting a majority stake, and slashing destroys much of it the moment the attack lands — the weapon partly self-destructs. Different economics, same lesson about concentration.
What should I do when a small chain suffers an attack?
Wait for more confirmations than usual before treating anything as settled, expect exchanges to extend deposit delays or suspend the chain, and distrust urgent fix-it messages — incidents breed phishing. If you hold assets on that chain, no action is strictly required; your keys still control your funds.