garden→free→this essay
The Realistic, Lucrative Case of an Ethereum Classic Attack
Freed from root: what security actually costs on a small proof-of-work chain. The root note asked the question; this essay priced it.Proof-of-work security is usually described as a fortress. It is closer to a rental market. The question that started this essay was simple: how much would it actually cost to control 51% of Ethereum Classic’s hashrate for a few hours — and could the attacker come out ahead.At the time of writing, ETC carried roughly 4% of the hashpower of its larger sibling, Ethereum, while trading on every major exchange.
The answer, in 2018, was uncomfortable. Hashpower marketplaces existed whose whole business was renting mining capacity by the hour.NiceHash and similar marketplaces let anyone rent Ethash capacity with no commitment beyond the hour paid for. Against a chain the size of ETC, the rental bill for a majority of the network came to thousands of dollars per hour — not millions. That is a budget, not a moat.
A 51% attack on Ethereum Classic was not a theoretical exercise. It was a trade with a visible price, a visible payoff, and no visible defender.
The payoff side was just as concrete. An attacker with majority hashpower can double-spend: deposit coins on an exchange, sell them, withdraw, then reorganize the chain so the deposit never happened. The exchange absorbs the loss. Every hour of rented majority was an option on that trade.The essay also priced the short side — borrowing and selling ETC before an attack the market has not noticed yet.
I published the numbers. The point was not to invite the attack; it was to show that the incentive already existed, and that pretending otherwise protected no one. Security budgets should be read the way an attacker reads them.
In January 2019, the scenario stopped being hypothetical. Ethereum Classic was 51%-attacked; exchanges reported double-spends in the millions of dollars, and Coinbase halted ETC transactions.January 2019. The attack followed the shape priced here: rented hashpower, exchange deposits, chain reorganizations. The essay went from analysis to postmortem without changing a word.
The lesson survived the news cycle and outgrew the chain: a system’s honesty is worth exactly what it costs to corrupt it, plus one dollar. That reading of security — adversarial, priced, unsentimental — is the same one I bring to registries and entities now.