Hus☐ — drhus.com · personal register Record № 0001 · Good standing · Upd. 2026-07-21
Schedule A — Writings free 🪂 Exhibit A-3 · this page

The Realistic, Lucrative Case of an Ethereum Classic Attack

A 51% attack on Ethereum Classic is not a theoretical risk. It is a rentable service with a market price, and in May 2018 the price is low enough to profit. This article prices it.

§ 1The premise

Proof-of-work security rests on one inequality: the cost of attacking the chain must exceed the reward. For Bitcoin and Ethereum the inequality holds, because an attacker would first have to build the hardware. It stops holding for any chain that shares its algorithm with a much larger sibling.

Ethereum Classic shares Ethash with Ethereum. Roughly 2.5% of Ethereum's hashpower is enough to control 51% of Ethereum Classic. The attacker doesn't need to build anything. The hardware exists, it is already plugged in, and hashpower marketplaces will rent it by the hour.

§ 2The arithmetic

The numbers below use network figures from May 2018 and list prices from public rental markets. They are conservative on purpose.

VariableValueBasis
Hashpower required ≈ 2.5% of Ethereum's ETC / ETH network hashrate ratio
Cost, owned hardware ≈ US$55 million GPUs at market price, worst case
Cost, rented a fraction of that, by the hour hashpower marketplace list prices
Attack window hours, not weeks exchange confirmation depths
Potential extraction up to ≈ US$1 billion double-spends plus a short position

Read the last two rows together. The attack does not need to break the chain. It needs to break confirmations — long enough to double-spend deposits on exchanges, while a short position monetizes the panic.

Security is not a property of the chain. It is a budget, and Ethereum Classic's budget is set by its bigger sibling's spare capacity.

§ 3Why it pays

Exchanges credit ETC deposits after a fixed number of confirmations, tuned for honest conditions. A renter with 51% can privately mine a longer chain, deposit, sell, withdraw, then release the private chain and erase the deposit. Every exchange that confirmed too fast pays once. Derivatives let the attacker be paid a second time, in advance, for the damage.

None of this requires new research. It requires a credit card and the willingness to be first.

§ 4What should change

Exchanges should scale confirmation depth to the rentable share of a chain's algorithm, not to its price chart. Chains that hold a minority of their own algorithm's hardware should treat rental markets as their real threat model. And robustness should be indexed and published, so the market prices it before an attacker does. That index is a separate piece of work — I call it Rindex.

postscript · verified 2019-01-07

Eight months after publication, Ethereum Classic was 51%-attacked the way the arithmetic said it would be. Coinbase halted ETC after detecting chain reorganizations with double-spends of roughly US$1.1 million (219,500 ETC). The theoretical column became the news column.

A-3a

Press that covered it

2018-05
Investopedia Coverage of the study's rental-cost model for proof-of-work security.
2018-05
Cointelegraph “51% attack on Ethereum Classic would cost $55 mln” — headline treatment of the arithmetic.
2018-05
The Next Web On rentable hashpower as the quiet flaw in smaller proof-of-work chains.
2018
CryptoBriefing Follow-up analysis citing the study after the January 2019 attack.

Original publication: medium.com/@HusamABBOUD · quoted here with its ledger updated.