Ravencoin's Developers Asked for a Softer Rollback. The Mining Pools Told Them No
A flaw let blocks lie about their own height and skip the proof-of-work check entirely. Then two mining pools that control most of the hashrate decided which four days of history would be deleted, overruled the project's own developers, and wrote the patch themselves.

Ravencoin's KAWPOW algorithm exists to make mining expensive. That is the entire point of proof of work: you cannot add to the chain unless you have burned real computation to earn the right. On August 7, 2026, at 15:44:01 UTC, somebody added a block without burning anything.
The flaw sat in a header field called nHeight, which declares what position a block claims to occupy in the chain. That value is supposed to be checked against where the block actually sits. It never was. Manipulate the field and the block takes a validation path that skips the full proof-of-work verification entirely. An attacker could mint valid-looking blocks for free, and vulnerable nodes accepted them as legitimate history.
The first forged block landed at height 4,487,776. Between heights 4,489,527 and 4,491,615, a stretch of 2,089 blocks, roughly 96 turned out to be fake. Ravencoin's own notice records something worse than the original attack: once the trick was demonstrated on mainnet, similar invalid blocks started appearing from other sources. People watched it work and copied it.
Ravencoin published nothing for three days. The network notice came on August 10, by which point Upbit had already suspended RVN deposits and withdrawals on its own initiative, citing a network issue. Bitget and Bitvavo followed. RVN fell about 19% to $0.00288, cutting the market cap to roughly $47.3 million.
Then the interesting part. Fixing a chain that has swallowed invalid blocks means deciding which version of history is real, and on a proof-of-work network that decision belongs to whoever controls the hashrate. On Ravencoin, that is two pools. 2Miners and RavenMiner between them command a majority of the network's computing power, and they announced they were mining a replacement chain that excluded everything from height 4,487,776 onward.
Ravencoin's own developers asked them to reconsider. The developer who published the network notice wrote plainly: "I asked the pools to consider a more recent recovery point to reduce the impact on users, services and exchanges."
The pools declined and proceeded with the earlier point regardless.
That decision erases roughly three to four days of Ravencoin's history. Every transaction confirmed after 15:44 UTC on August 7 disappears from the accepted record. Payments, exchange deposits, withdrawals, all of it. Some transactions may return to the mempool and get processed again. There is no guarantee any of them will. RavenMiner suspended payouts entirely while the competing chains resolve, warning that mining rewards earned during the disputed window could simply evaporate.
The emergency patch, version 4.6.1.1-hf1, was written and shipped by 2Miners, not by Ravencoin. It rejects forged blocks and hardcodes a checkpoint at height 4,487,775. Ravencoin's own GitHub notes conceded there was no core release patching both the KAWPOW flaw and a separate asset transfer quantity overflow bug, and maintainer Hans Schmidt told operators to run the mining pool's code in the meantime. Restarting a node on the patched software takes hours, because it replays about 4.49 million blocks and 28 million transactions to rebuild state from scratch.
This is Ravencoin's third consensus failure. In June 2020 attackers exploited a different flaw to mint roughly 315 million RVN, about 1.5% of the 21 billion supply, worth around $5.7 million at the time. Lead developer Tron Black said then that "the vulnerability does not allow the stealing of RVN or assets that you own and control," and noted the extra coins had already been mixed with legitimate RVN on an exchange, which made a rollback impossible. Six years later the same chain rolled back four days without much difficulty, because this time the pools wanted to.
Ravencoin's hashrate swelled after Ethereum's 2022 merge sent a wave of displaced GPU miners looking for somewhere to point their hardware. More hashrate normally means more security. Here it meant more concentration, and concentration meant that when the chain needed rescuing, the rescue was carried out by two commercial entities who overruled the project's developers about how much of everyone else's history to throw away.
The vulnerability is patched. The deeper problem is not, and it is the one nobody wants stated out loud: on a chain where two pools hold the majority, immutability is not a property of the software. It is a preference that those two pools currently happen to share.
The Aftermath
The KAWPOW flaw is patched, but the patch came from 2Miners rather than Ravencoin's core team, and at the time of writing no core release addressed both that flaw and a separate asset transfer quantity overflow bug. Exchanges that credited deposits during the disputed window absorb the loss if those blocks are discarded, the same way NEAR Intents lost 11,000 LTC and THORChain lost 10 LTC during Litecoin's April 2026 reorg. Mining rewards earned in the contested period may not be honoured. No attacker has been identified, and because the exploit produced blocks rather than stolen coins, there is no stolen balance to trace or recover.
COMMENTS