Ethereum Classic suffered another majority-hashrate attack disclosed on August 6, 2020, only five days after the network’s preceding major reorganization. The incident replaced more than 4,000 blocks of accepted transaction history and prompted infrastructure providers to suspend Ethereum Classic services while they assessed the competing chain.

The event mattered beyond the affected transactions. Ethereum Classic used proof-of-work and shared its Ethash mining algorithm with the much larger Ethereum network. Its comparatively limited committed computing power meant an attacker could potentially obtain enough external hashpower to build a heavier private chain, publish it and displace blocks that recipients had already treated as confirmed.

What was known on August 6

The Block reported at 2:20 a.m. Eastern time on August 6 that mining-pool operator Bitfly had identified the attack and that Binance had confirmed a reorganization of more than 4,000 blocks beginning around Ethereum Classic block 10,935,622. Bitfly stopped ETC miner payouts, while Binance suspended ETC deposits and withdrawals, according to the contemporaneous report.

Those suspensions were operational safeguards, not evidence that every ETC transaction had failed. A chain reorganization removes one sequence of blocks from the canonical history and substitutes another. Ordinary reorganizations can occur naturally near a chain’s tip, but a replacement extending across thousands of blocks is exceptional. With majority mining power, an attacker can privately mine an alternative history and use it to reverse transactions, creating the conditions for a double spend.

The value affected by the August 6 incident was not established in the initial public report. That limitation is important: the observable reorganization established that transaction history had been replaced, but the number of blocks alone did not identify the ultimate victim, prove the value successfully withdrawn from a service or determine the attacker’s net proceeds.

Why the repeat attack changed the risk calculation

A second deep reorganization in five days showed that the preceding incident was not an isolated operational fault. It challenged a basic commercial assumption surrounding proof-of-work settlement: after enough confirmations, a recipient normally treats reversal as economically impractical.

For exchanges and custodians, increasing the number of required confirmations could make an attack longer and more expensive. It also imposed a practical cost on legitimate users because deposits would remain unavailable for longer. Suspending transfers eliminated immediate deposit-crediting exposure but reduced ETC’s usefulness while the network and its service providers investigated.

The attack did not demonstrate that proof-of-work systems generally had identical security. Majority attacks depend on the computing power committed to a particular chain, the availability and price of compatible rentable hashpower, exchange controls, and the value that can be extracted before operators respond. Ethereum Classic’s circumstances on August 6 were specific to its network and surrounding market infrastructure.

Later analysis clarified the scale

Coinbase published a primary technical analysis on August 21, 2020. Its non-pruned node logs showed a common ancestor at block 10,935,622, 4,244 orphaned blocks and 4,353 replacement blocks. Coinbase calculated that producing the replacement chain required approximately 18.1 hours of majority hashpower, assuming a constant 15-second block interval.

Coinbase also identified approximately 460,000 ETC in double-spend transactions, valued by Coinbase at about $3.2 million, across nine orphaned transactions. That dollar figure was a retrospective estimate published on August 21 rather than an event-day market measurement; Coinbase did not specify a single execution venue or exact pricing timestamp. Coinbase said it was not the target and lost no funds.

On August 7, a draft Ethereum Classic improvement proposal suggested penalizing deep reorganizations. Its appearance documented an immediate protocol-level response, but the draft was neither an adopted rule nor a deployed protection on August 6. The verified August 6 record therefore remained stark: more than 4,000 accepted blocks had been displaced, and service providers had to compensate for a security failure the protocol had not prevented.

Primary sourceCoinbase — Perspective on the August 2020 Ethereum Classic double-spend incidents

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.