Bitquery reported on August 7, 2020 that the Ethereum Classic network’s second majority-hash attack in five days had successfully double-spent 238,306 ETC, which the analytics company valued at about $1.68 million. The finding turned a deep chain reorganization detected on August 6 into a quantified loss estimate and showed that the incident was not merely a client synchronization problem.

Bitquery’s reconstruction covered 4,236 consecutive blocks, from height 10,935,623 through 10,939,858. It placed the reorganization at August 6, 2020, 02:54:27 UTC and the first privately mined block at August 5, 2020, 11:50:20 UTC, implying a private-mining window of 15 hours and six minutes. Those timestamps and block counts are the measurement window for this account.

What the forensic report established

According to Bitquery, seven transfers totaling 465,444 ETC—then valued by the firm at roughly $3.3 million—were included in the attacker’s privately mined chain. The company said it could verify successful double-spends totaling 238,306 ETC. It attributed 143,000 ETC to an address it believed belonged to Bitfinex and 95,650 ETC to an unidentified crypto service.

Those service identifications were analytical attributions, not confirmations from the named exchange or the unidentified recipient. Bitquery also said the attacker collected 14,234.30 ETC in block rewards, which it excluded from the $1.68 million double-spend estimate. Its dollar figures were contemporaneous approximations attached to ETC amounts, not a documented exchange-wide loss audit or a time-weighted market-price series.

The mechanics mattered more than the dollar conversion. A proof-of-work chain follows the valid history with the greatest accumulated work. An attacker with dominant rented hash power can mine an alternative history privately, spend coins on the visible chain, and later reveal the heavier private chain. If nodes accept it, the earlier public history is displaced and transactions thought settled can disappear. Bitquery said the likely hash-power source was NiceHash’s DaggerHashimoto market, but described that link probabilistically.

A protocol-security problem became an institutional problem

The August 6 reorganization followed another attack spanning July 31 and August 1, 2020. The recurrence compressed what could have been treated as a one-off operational failure into a direct challenge to Ethereum Classic’s settlement assurances. For exchanges and custodians, the practical issue was confirmation depth: a transaction could accumulate thousands of blocks and still be displaced if an attacker could privately build more work.

CoinDesk’s August 7 report independently relayed Bitquery’s 4,236-block finding, the 238,306 ETC estimate and the additional block rewards. It also reported that Ethereum Classic Labs had retained Kobre & Kim to investigate and pursue criminal charges. That response showed the event crossing from protocol operations into exchange risk management, forensic attribution and possible law-enforcement action.

The same date produced an early technical response. A draft posted to the Ethereum Classic improvement-proposal repository on August 7 proposed adapting PirlGuard, under which a peer presenting a privately mined branch would face a penalty tied to the number of blocks being reversed. The proposal was explicitly a draft requiring community consensus; it was evidence of urgency, not an implemented fix.

What was known on August 7

By August 7, the defensible conclusion was narrow but serious: Ethereum Classic had accepted a 4,236-block competing history, and Bitquery’s address-level analysis indicated at least 238,306 ETC had been double-spent. The exact ultimate loss borne by each service, the attacker’s identity and whether the suspected hash power came from the named marketplace were not independently established.

Later statements from Ethereum Classic Labs on August 10 described the August 6 incident as a 51% attack and put the theft at approximately $1.7 million. That later confirmation supports the event-day account, but it does not eliminate the attribution and valuation limits that existed on August 7.

Primary sourceBitquery — Ethereum Classic Attack: Catch Me If You Can, August 7, 2020

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.