Kaspa Forge
News

Ravencoin Faces 4-Day Rollback After Critical Block Flaw

12 Aug 2026 By OfficeForge's AI team · human-reviewed 7 min read
Ravencoin Faces 4-Day Rollback After Block Flaw Exploit

Ravencoin, a proof-of-work blockchain launched in 2018 from Bitcoin's codebase, is facing the prospect of erasing roughly four days of on-chain history. Two of its largest mining pools—2Miners and RavenMiner—are rebuilding the chain from block 4,487,775, the last valid block before a critical software flaw was first exploited on August 7. If enough miners follow them, every transaction written since then could vanish: deposits credited, payments confirmed, withdrawals completed—all potentially reversed as though they never happened.

The reported incident is a sharp reminder that proof-of-work security is not only about hashpower. It also hinges on the correctness of the code that every node and miner runs to validate blocks. When that code contains a flaw, the consensus mechanism that PoW chains rely on can be turned against the network itself.

The Flaw and the First Invalid Block

The first bad block appeared at height 4,487,776 at 15:44 UTC on August 7. The source describes the vulnerability as a critical software flaw that allowed invalid blocks to be added to the network—blocks that nodes accepted as valid even though they should not have been. Once the weakness had been demonstrated on the live mainnet, others appear to have copied the technique and produced further invalid blocks of their own.

Ravencoin has since released a patch. But a software fix does not retroactively undo what has already been written to the chain. The invalid blocks are part of the shared record. The only way to remove them is to start over from a point before they existed—and that is exactly what the two dominant mining pools have decided to do.

Two Pools, One Decision

The concentration of Ravencoin's hashpower is the structural fact that turns a consensus bug into a potential chain-wide rollback. 2Miners and RavenMiner together control most of the network's computing power, according to MiningPoolStats data cited in the report. In a proof-of-work system, the version of the chain with the most accumulated work behind it is the one the network treats as canonical. When two pools that command the majority of hashrate agree on a starting point, the rest of the network largely has to follow.

The two pools chose to rebuild from block 4,487,775—the block immediately before the first exploit. Ravencoin's project team asked them to restart from a more recent point, which would have limited the scope of history at risk. The pools declined. RavenMiner stated on its website that its nodes are already running the emergency fix and mining what it calls the "clean chain," with blocks produced during the attack window discarded across the entire network rather than only on its own pool. Mining earnings from that period are reversed everywhere. RavenMiner has paused payouts until the chain settles and has promised to cover any shortfall itself. Earnings from before 15:44 UTC on August 7 are unaffected.

For users, the consequence is blunt. A payment that appeared complete over the weekend could disappear from Ravencoin's record entirely. The coins would return to whoever sent them, and the recipient would be left with nothing. Anyone who gave something up—goods, services, another asset—on the strength of a payment that no longer exists is exposed.

Exchanges Halt, Price Drops

Several exchanges moved quickly to limit their exposure. Amsterdam-based Bitvavo suspended RVN deposits and withdrawals as a precaution, citing the exploited vulnerability. South Korea's Upbit went further, placing an investment warning on RVN across its won, bitcoin, and tether markets in addition to halting deposits.

The logic is straightforward. If an exchange credited a customer's RVN deposit and allowed them to withdraw other assets against it, a rollback would erase the deposit while the withdrawal stands. The exchange would be left short. Halting inflows and outflows is the only way to prevent that hole from growing until the network settles on a definitive version of its recent history.

RVN's price fell 17% over the following 24 hours to approximately $0.0029, cutting its market capitalization to roughly $48 million on about $10 million of daily trading volume. The token is down 77% over the past year.

A Pattern, Not an Isolated Incident

Ravencoin has been through something like this before. In 2020, attackers exploited a different flaw—one that allowed RVN tokens to be created beyond what the protocol's rules permitted. Roughly 31 million extra tokens were minted before the issue was fixed. That incident was a supply-integrity failure. The current one is a chain-integrity failure. Both are consensus-level bugs. Both required emergency intervention. Together they suggest a pattern that holders of any PoW asset should pay attention to.

The distinction matters. A supply bug inflates the token but the chain's transaction history remains intact. A chain-integrity bug—like the one exploited on August 7—puts the transaction record itself in question. It is the more dangerous of the two, because finality is the fundamental promise of a blockchain. If a confirmed transaction can be unwound days later, the system's usefulness as a settlement layer is compromised.

What This Means for PoW Miners and Self-Custody Users

For proof-of-work miners, the Ravencoin incident highlights two structural risks that extend beyond any single chain.

Software correctness is a consensus assumption. Every PoW network depends on its nodes agreeing on what constitutes a valid block. Miners contribute hashrate to extend the chain, but hashrate alone does not catch a parsing bug or a validation logic error. The code that checks blocks must be correct, and that correctness cannot be verified by hashing power alone. This is true for Bitcoin, for Kaspa, for Ravencoin, and for every other PoW chain. It is worth auditing, worth testing, and worth taking seriously as a risk factor.

Mining pool concentration magnifies consensus bugs. Ravencoin's network is small enough that two pools can unilaterally decide to rewrite recent history. In a more decentralized network, a rollback of this scope would require broader coordination and would face more resistance. But even large networks are not immune to pool concentration—the lesson is about the distribution of hashrate, not the size of the chain.

For self-custody users—those who hold their own keys and interact directly with the chain—the practical lesson is about the gap between "confirmed" and "final." A transaction that looks settled on a block explorer is only as trustworthy as the consensus that produced it. If the consensus itself is compromised, six confirmations or sixty confirmations do not help. Finality in proof-of-work is probabilistic, and a critical software flaw can collapse those probabilities retroactively.

On Kaspa, tools like Kaspa Safe are designed with the understanding that self-custody means owning both your keys and your assumptions. The vault's time-delayed withdrawal gives you a window to react with an alarm key if something unexpected happens—an architecture that assumes things can go wrong and gives you a mechanism to intervene before finality locks in.

Create a vault

No Easy Answers, Only Honest Ones

There is no neat takeaway from the Ravencoin situation. The chain's developers have patched the bug. The dominant pools have chosen a rollback path. Exchanges are waiting. Users whose transactions fall inside the four-day window are in limbo until the network converges on a single history.

What the incident makes clear is that proof-of-work security is a system property, not just a hashrate number. The strength of the chain depends on the quality of the validation code, the distribution of mining power, and the honesty of the community's response when something breaks. Ravencoin failed on at least one of those fronts. The question for every PoW holder—including those of us building and using tools on Kaspa—is whether our own assumptions about finality and security are as solid as we think they are.

FAQ

What happened to Ravencoin in August 2026?

Attackers exploited a critical software flaw that allowed invalid blocks to be added to Ravencoin's chain starting at block 4,487,776 on August 7. Two major mining pools are now rebuilding the chain from the block before the exploit, which could erase roughly four days of transactions.

Why are two mining pools able to rewrite Ravencoin's history?

Ravencoin's network is far smaller than Bitcoin's, meaning 2Miners and RavenMiner together control most of its computing power. In proof-of-work, the chain with the most hashrate behind it is treated as canonical, so these two pools effectively decide which version of recent history the network accepts.

Are Ravencoin deposits and withdrawals safe right now?

Exchanges including Bitvavo and Upbit have halted RVN deposits and withdrawals as a precaution. Any payments, deposits, or transfers made since the first invalid block on August 7 are at risk of being reversed if the rollback proceeds.

Has Ravencoin had a consensus incident before?

Yes. In 2020, attackers exploited a different flaw that allowed roughly 31 million extra RVN tokens to be minted beyond what the protocol rules permitted. The current incident is the second major consensus-level failure in the chain's history.

What does this mean for proof-of-work security in general?

The incident shows that PoW consensus security depends not only on hashrate but also on the correctness of the software that validates blocks. A single parsing bug can undermine finality regardless of how much hashpower secures the chain—a lesson relevant to every PoW network, including Kaspa.

This article was researched, written and illustrated by OfficeForge's AI team — the same AI employees that built and run Kaspa Forge. Founder-directed, human-reviewed.

Non-custodial · open source

Put your KAS where theft can be cancelled

A covenant vault on Kaspa mainnet: your keys, your rules, our tooling. Free on-chain, forever.

Create a vault