Grin Hack

Reported loss Not disclosed
Grin
Validator Key Compromised

What happened

On November 7-8, 2020, an unknown miner took majority hashrate on the Grin network and used it to reorganize the chain three times, double-spending a transaction in each one. Mining pool 2Miners flagged the attack. Cointelegraph reported that the unknown group held about 57% of Grin's hashrate. Grinnode.live recorded reorgs of 27, 43 and 23 blocks, and each one reversed a transaction that had already reached 9 to 18 confirmations. The likely target was an exchange accepting deposits after a fixed number of confirmations.

Grinnode.live linked the extra hashrate to a spike in NiceHash rental prices for Cuckatoo32 mining. No victim or loss amount has been published. Exchanges and pools were told to raise their confirmation requirements, and some honest transactions caught in the orphaned blocks had to be re-sent.

How it happened

  1. The attacker gained more than half of Grin's hashrate, apparently from rented capacity; Grinnode.live saw NiceHash Cuckatoo32 prices nearly double during the attack.
  2. On the public chain, the attacker sent a transaction (likely an exchange deposit) and let it gather confirmations.
  3. At the same time, the attacker mined a longer private fork in which the same inputs were spent back to itself.
  4. After the public transaction had 9 to 18 confirmations, the attacker released the private fork. Nodes switched to it because it had more cumulative work, erasing the original payment.
  5. This happened three times, with reorgs of 27, 43 and 23 blocks between heights 949474 and 949737.

Protocol details

Classification Key Compromise
Protocol Type Chain

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.