Ethereum Classic suffered a majority-hash attack in the opening hours of August 1, 2020, when a privately mined chain overtook the public chain and replaced more than 3,500 blocks. Forensic work published on August 5 concluded that the reorganization enabled 807,260 ETC to be double-spent.

The event mattered beyond the immediate loss. It demonstrated how a proof-of-work network with comparatively limited mining power could produce apparently confirmed transactions that were subsequently removed from its accepted history. Exchanges and other businesses relying on block confirmations faced the resulting settlement risk.

A longer chain rewrote the ledger

Bitquery reconstructed the episode using two Ethereum Classic datasets: the chain ultimately accepted by the network and the discarded history retained by an OpenEthereum node. Its analysis placed the common ancestor at block 10,904,146 and identified attacker-produced replacement blocks beginning at height 10,904,147.

According to that reconstruction, the attacker began private mining on July 31 at 16:36 UTC. Between July 31 at 18:00 UTC and August 1 at 02:50 UTC, ETC was returned to an exchange through intermediary addresses on the publicly visible chain. Bitquery reported that the withheld blocks were released on August 1 at 04:53 UTC, replacing those transactions with transfers controlled by the attacker.

Bitquery counted 807,260 ETC in double-spends and estimated their contemporaneous value at $5.6 million. It separately estimated that acquiring the necessary hash power cost approximately 17.5 BTC, then valued at $192,000. Those dollar amounts are Bitquery’s event-period estimates, not independently calculated Coinburn prices; the report does not specify a single exchange price or precise valuation timestamp.

Detection did not immediately establish the full loss

Coinbase’s internal monitoring provides a separate primary account. Coinbase said its blockchain-security system detected abnormal block production at 11:10 p.m. PST on July 31 and traced the disruption to a massive reorganization recorded at 10:57 p.m. PST. The company subsequently found approximately 800,000 ETC—valued by Coinbase at about $5.8 million—double-spent across 53 orphaned transactions.

Coinbase said none of those transactions targeted its platform and that it increased its ETC confirmation requirement after detecting the reorganization. Its account also described a network partition: pruned Parity nodes rejected the unusually deep replacement chain, while non-pruned Parity and Geth nodes accepted it.

The primary records therefore agree on the central facts but not on every timestamp or dollar estimate. Bitquery’s August 1 time is stated in UTC, while Coinbase used PST in its August 21 report. Their $5.6 million and $5.8 million figures also reflect different analyses or valuation conventions. The token count is more useful than either rounded dollar estimate.

Why the attack mattered

A majority-hash attack does not create arbitrary coins or reveal users’ private keys. It allows an attacker controlling sufficient mining power to build a competing chain, invalidate transactions in the displaced history and reuse the same assets elsewhere. The August 1 reorganization showed that waiting for many confirmations was not necessarily enough when an adversary could sustain a private chain for roughly 12 hours.

For exchanges, the lesson was operational: confirmation policies had to reflect a network’s available hash power and the potential depth of a hostile reorganization. For Ethereum Classic, it was a protocol-security warning because the network had already experienced a confirmed double-spend attack in January 2019.

Confirmation published after August 1

The full transaction-level account was not established publicly on August 1. Bitquery published its quantified analysis on August 5, and Coinbase published its independent account on August 21. An Ethereum Classic community retrospective subsequently summarized the August 1 incident as an approximately 3,693-block reorganization involving an estimated 807,260 ETC.

Those subsequent records confirm what occurred on August 1, but their findings should not be mistaken for information available to every network participant at the moment the competing chain appeared.

Primary sourceBitquery — Attacker Stole 807K ETC in Ethereum Classic 51% Attack, August 5, 2020

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.