A missing nHeight check in Ravencoin's KAWPOW validation let attackers append forged blocks with no real proof-of-work, forcing RVN freezes and a rollback to block 4,487,775.
On August 7, 2026, at 15:44 UTC, block 4,487,776 became the first invalid block accepted onto the Ravencoin chain through a critical consensus vulnerability: vulnerable nodes never verified that the nHeight field in a block header matched the block's actual position in the chain, and manipulating it reached a validation path that accepted blocks without genuine KAWPOW proof-of-work. The exploit ran unnoticed for roughly three days before public disclosure on August 10. Because forged blocks poisoned the chain from height 4,487,776 onward, the mining pools controlling majority hashrate began mining a clean chain from the last valid block, a reorganization that stands to roll back roughly three days of transaction history. Exchanges including Upbit and Bitget froze RVN deposits and withdrawals, and the token fell about 19% to a record low. No direct theft has been confirmed, but every transaction confirmed after block 4,487,775 is potentially reversible, which is precisely the guarantee a proof-of-work chain exists to provide.
Ravencoin uses KAWPOW, a variant of ProgPoW, as its proof-of-work algorithm. KAWPOW verification takes the block height as an input: the height selects the ProgPoW period that determines which randomized program hashes the header, so a verifier must know where in the chain a block sits to check its work. Ravencoin block headers therefore carry an explicit nHeight field.
The vulnerability was that vulnerable nodes never validated this declared nHeight against the block's actual position in the chain. According to the emergency release notes, a manipulated nHeight could steer validation into a path that skipped full proof-of-work verification and accepted the mix hash supplied in the header without confirming that genuine ProgPoW work stood behind it. Blocks created this way carried no real mining work and were, in the words of the release, orders of magnitude cheaper to produce than honest blocks at the same difficulty.
That economic asymmetry separates this incident from a 51% attack. Rewriting history on a healthy proof-of-work chain requires out-mining the entire honest network for the duration of the attack. Here, an attacker needed only to craft headers that exploited the validation shortcut, paying a tiny fraction of the honest cost per block while vulnerable nodes treated the result as valid.
The first invalid block was accepted at height 4,487,776 on August 7, 2026, at 15:44:01 UTC. The forgeries were interleaved with honest blocks rather than wholesale: a sample of 2,089 blocks between heights 4,489,527 and 4,491,615 analyzed by the 2Miners pool contained 96 compromised blocks, while blocks mined before August 7 showed no signs of exploitation.
No direct theft from the exploit itself had been confirmed at publication, and that is not where the damage concentrates. The exploit broke settlement finality: once majority hashrate commits to a clean chain from block 4,487,775, every transaction confirmed after that height can be reversed, and any party that irrevocably released goods, fiat, or other crypto against RVN deposits during the exploit window carries double-spend exposure. The trust model is the same one that makes bridges DeFi's weakest link: any service that credits value based on another system's confirmations inherits that system's failure modes.
The market reaction was immediate. RVN fell roughly 19% and traded as low as $0.002754 on August 12, a record low, cutting the market capitalization to about $47 million while daily volume exceeded $18 million. Upbit, Bitget, and Bitvavo suspended RVN deposits and withdrawals, with Upbit keeping spot trading open.
This is not Ravencoin's first consensus-layer failure. In 2020, a vulnerability allowed the creation of 315 million unauthorized RVN, about 1.5% of the maximum supply, then worth roughly $5.7 million. The 2026 incident is more severe in kind: rather than inflating supply, it invalidated the chain's core guarantee that recorded history is expensive to rewrite.
The fix came from a mining pool rather than the core team. 2Miners shipped emergency release 4.6.1.1-hf1, which rejects any block whose declared header height does not match its actual chain position, adds a checkpoint at block 4,487,775 anchoring the chain to the last uncompromised state, and rebuilds chain state where damaged index data prevents a node from continuing.
2Miners and RavenMiner, together controlling a majority of network hashrate, began mining a clean chain from block 4,487,775 that deliberately excludes the exploited branch. Once that chain becomes dominant, transactions confirmed on the exploited branch return to the mempool with no guarantee of reconfirmation. A Ravencoin core developer said the pools were asked to consider a more recent recovery point to reduce the impact on users, services, and exchanges, and that the request was declined. The project advised exchanges to keep RVN transfers suspended until the network reaches a stable state, without committing to a timeline.
The uncomfortable part of the timeline is the detection gap: forged blocks entered the chain for roughly three days and thousands of blocks before anyone noticed. Consensus failures, like smart contract exploits, are visible on-chain long before official announcements. On EVM chains, a machine-readable feed such as Defimon's WebSocket attack stream exists to close exactly this gap, letting exchanges and protocols pause deposits within seconds of a confirmed attack instead of days.
Starting August 7, 2026, at block height 4,487,776, attackers exploited a critical consensus vulnerability in Ravencoin's KAWPOW proof-of-work validation. Nodes never checked the nHeight field in block headers against a block's actual chain position, and manipulating it allowed blocks with no genuine mining work to be accepted. The exploit ran for roughly three days before disclosure on August 10. Majority mining pools began mining a clean chain from block 4,487,775, exchanges froze RVN transfers, and the token fell about 19% to a record low.
KAWPOW verification uses the block height as an input, so Ravencoin headers carry an explicit nHeight field. Vulnerable nodes never validated that field against the block's true position in the chain. A crafted nHeight steered validation into a path that skipped full proof-of-work verification and accepted the header's supplied mix hash, so forged blocks carried no real ProgPoW work and were orders of magnitude cheaper to produce than honest blocks at the same difficulty.
Transactions confirmed after block 4,487,775, mined around 15:44 UTC on August 7, 2026, sit on the exploited branch and face reversal once the clean chain mined by 2Miners and RavenMiner becomes dominant. Reversed transactions return to the mempool but are not guaranteed to reconfirm. Transactions confirmed at or before block 4,487,775 are unaffected. Exchanges including Upbit and Bitget suspended RVN deposits and withdrawals until the network stabilizes.
Yes. In 2020, a vulnerability let an attacker mint about 315 million unauthorized RVN, roughly 1.5% of the maximum supply and worth about $5.7 million at the time. The August 2026 incident is more severe in kind: rather than inflating supply, it broke the proof-of-work guarantee itself, allowing invalid blocks onto the chain and forcing a multi-day rollback of transaction history.
Connect in minutes. Every attack across major chains, as JSON, in under a second.
@DefimonAlerts