← back to the blog

Bitcoin Explained · July 12, 2026

By Adam Whistler

What Is a 51% Attack on Bitcoin?

Padlock over binary code representing blockchain security

Bitcoin's security model rests on a simple assumption: no single entity controls a majority of the computing power securing the network. As of mid-2026, that assumption is closer to being tested than it's been in over a decade, two mining pools, Foundry USA and AntPool, now combine for a bit more than half of Bitcoin's total hash rate. That's a real, measurable shift worth understanding, even though the actual attack it enables remains far less likely than the headline makes it sound.

What a 51% attack actually lets someone do

Bitcoin's ledger is secured by miners competing to solve computational puzzles, with the longest valid chain accepted as the true history. If a single entity or coordinated group controls more than half of that computing power, they can, in principle, out-race the rest of the network to build an alternate chain, allowing them to reverse their own recent transactions (enabling double-spending), censor specific transactions from being confirmed, or reorganize recently mined blocks. What it cannot do is steal coins from someone else's wallet, rewrite history from years ago, or change Bitcoin's fixed supply, the attack only threatens recent transaction finality, not the protocol's fundamental rules.

The current concentration, and why it happened

Foundry USA, backed by Digital Currency Group, holds roughly a third of Bitcoin's hash rate on its own, while AntPool, owned by ASIC manufacturer Bitmain, adds close to another fifth. Combined, multiple independent trackers put their share above 51% as of mid-2026, the highest concentration level in more than a decade. The top three pools together are frequently cited as controlling upward of 80% of global hash rate. This didn't happen overnight, both pools' shares have grown steadily over the past year as mining consolidates around a small number of large, well-capitalized operators with access to cheap power and the newest hardware.

Why this almost certainly won't turn into an actual attack

The only time a pool ever crossed the 50% threshold was GHash.io, briefly, for a few days in June 2014, and it voluntarily reduced its own share afterward specifically because of the backlash, demonstrating that the community response itself is a real check even without a technical one. Foundry and AntPool are known, identifiable, revenue-generating businesses, not anonymous actors, and an actual attack would immediately crater confidence in Bitcoin, the very asset their entire business depends on. Cost estimates for what a real attack would require vary enormously across analysts, from roughly $10 billion to over $1 trillion depending on whether the calculation assumes buying hardware outright or renting existing hash power, but every credible estimate agrees it's an enormous, economically irrational sum for an attack with no clear profitable outcome. It's also worth being precise about Bitcoin's actual track record here: unlike smaller proof-of-work chains, Ethereum Classic and Bitcoin Gold have both suffered real, successful 51% attacks before, Bitcoin itself never has.

The more realistic risk hiding underneath

A full attack isn't the only thing concentration enables. In 2023, F2Pool filtered out transactions from addresses on US sanctions lists, a form of "soft censorship" that required nowhere near a majority of hash rate, just a pool operator's own policy decision. That's arguably the more realistic near-term concern than a dramatic double-spend attack: not one entity rewriting history, but a handful of large, regulated pool operators quietly shaping which transactions get confirmed. Protocol-level responses are already in motion, Stratum V2, a mining protocol upgrade supporting encrypted connections and letting individual miners choose their own block templates rather than relying entirely on their pool operator, is gaining hardware support specifically to push censorship resistance back down to individual miners rather than pool operators.

The private key for every Bitcoin wallet on Earth is on this website, even Satoshi's. But even if you try for a million years, you'll never find a funded one.

Try the key collider now

What this means for you

A 51% attack, even a successful one, would threaten unconfirmed or very recently confirmed transactions, not funds already settled with many confirmations behind them, and it absolutely cannot touch a private key it doesn't control, no attack on mining changes who controls which Bitcoin. For the fuller comparison of how proof-of-work's security model differs from the alternative, see proof of work versus proof of stake, explained, and for the broader picture of what can and can't actually be hacked in Bitcoin, see can Bitcoin actually be hacked.