pull down to refresh

@daily_btc_lore | Daily Bitcoin History Threads

July 16, 2014 | 12 years ago today

GHash.io Promised Not to Attack BitcoinGHash.io Promised Not to Attack Bitcoin


A month earlier, one mining pool briefly held enough hashrate to rewrite Bitcoin's ledger at will. The fix wasn't a line of code. It was a handshake in a London conference room.

On July 16, 2014, GHash.io, then the largest mining pool in the world, pledged to cap its own share of Bitcoin's hashrate at 39.99%. It remains one of the strangest moments in Bitcoin's history: the network's security model was, for a few weeks, propped up by a promise.

What 51% of the hashrate actually buys youWhat 51% of the hashrate actually buys you

Bitcoin's core security assumption is that no single party controls a majority of the network's mining power. When that assumption breaks, three attacks become possible, and it's worth being precise about what they are and are not.

The double-spend. A majority miner can mine a private chain in secret while spending coins on the public chain. Pay an exchange, wait for confirmations, withdraw a different asset. Meanwhile, the attacker's hidden chain, which does not contain that payment, grows faster than the public one because the attacker has more hashrate than everyone else combined. Release the longer chain, and every node on the network switches to it automatically. That's not a bug; it's the longest-chain rule doing exactly what it was designed to do. The original payment simply never happened. The exchange is left holding nothing.

Transaction censorship. A majority miner can refuse to include specific transactions, or anyone's transactions, in the blocks it mines. Worse, it can orphan blocks mined by honest miners that do include those transactions, since its chain will always outpace theirs. The ledger stops being neutral. Confirmation becomes a permission granted by one company.

Denial of finality. Even without stealing anything, a majority miner can keep reorganizing the chain, making it impossible for anyone to trust that a confirmed transaction stays confirmed.

What a 51% attacker cannot do matters too: it cannot steal coins from addresses it doesn't control, forge signatures, or change the supply schedule. Full nodes reject invalid blocks regardless of how much work is behind them. But "your confirmed payments can be erased and your transactions can be blacklisted" is quite bad enough.

June 12-13, 2014: it stops being theoreticalJune 12-13, 2014: it stops being theoretical

For years the 51% attack lived in whitepapers and forum threads. Then, over roughly a day spanning June 12-13, 2014, GHash.io crossed the majority threshold and hit approximately 55% of Bitcoin's hashrate.

Nothing malicious happened. But the community's reaction was immediate and severe. Developers and commentators urged miners to point their hardware elsewhere. Forums filled with attack scenarios and arguments about whether the threat was overblown. The price wobbled. An emergency industry roundtable was scheduled for July 9 in London to hammer out a response.

It's worth understanding why a pool got this big in the first place, because the problem was structural. Mining pools exist to smooth variance: a small miner solo-mining might wait years to find a block, but by pooling hashrate with thousands of others and splitting rewards proportionally, they get a steady income stream. The economics reward joining the biggest, most reliable pool with the lowest fees and best payout scheme. GHash.io charged zero fees and offered merged perks through its parent exchange CEX.io, so hashrate flowed in. Pooling is individually rational and collectively dangerous: every miner making the sensible personal choice pushed one operator toward majority control.

The critical detail is that pool participants didn't control what their hashrate did. The pool operator decided which transactions went into blocks and which chain to extend. Thousands of independent machines, one point of decision.

The London pledgeThe London pledge

The answer came on July 16, 2014, at a mining industry summit in London. GHash.io CIO Jeffrey Smith committed the pool to a self-imposed ceiling of 39.99% of network hashrate, promising to redirect incoming miner hashrate to other pools whenever GHash approached the threshold. CoinDesk covered the announcement: https://www.coindesk.com/markets/2014/07/16/ghash-commits-to-40-hashrate-cap-at-bitcoin-mining-summit/

The summit drew a cross-section of the 2014 mining industry: Peernova, KnCMiner, Spondoolies Tech, the Bitcoin Foundation, and BitGo, whose CEO Will O'Brien framed the moment bluntly, saying industry leaders themselves had to "make changes that build confidence."

Read that sentence again and notice what it implies. The fix for a trustless system's biggest scare was a trust exercise. No protocol change shipped. No enforcement mechanism existed. If GHash quietly blew past 40%, the only consequence would be reputational. The cap was a gentleman's agreement about the security of a system explicitly designed to not need gentlemen.

Peter Todd's objection: behavioral fixes vs structural fixesPeter Todd's objection: behavioral fixes vs structural fixes

Bitcoin developer Peter Todd had already put his money where his analysis was. During the June scare he sold half of his own bitcoin holdings, a move that made headlines on its own. His reaction to the London pledge cut to the core problem: GHash, he observed, "seemed much more focused on getting trust" than on restructuring the system so that trust wasn't needed.

This is the distinction that makes the episode worth remembering. A behavioral fix says: the dangerous actor promises to behave. A structural fix says: the danger is removed regardless of anyone's intentions. Todd's argument was that a pool which must promise not to attack you is itself the vulnerability. The promise doesn't fix the flaw; it advertises it. GHash's cap changed nothing about the pool's capabilities, only its stated intentions, and intentions can change with an ownership transfer, a government order, or a hack of the pool's infrastructure.

The structural fixes people discussed at the time, like getting block-template selection out of pool operators' hands entirely, took years longer. Ideas in that lineage eventually resurfaced in protocols like Stratum V2, which lets individual miners choose their own transactions. In 2014, none of that existed. The promise was all there was.

Voting with hashrateVoting with hashrate

What actually defused the crisis wasn't the pledge. It was miners leaving.

Pool participants are customers, and hashrate is the most liquid loyalty in Bitcoin. Repointing a mining rig to a different pool takes about a minute of configuration and costs nothing. When GHash became a reputational liability, miners who held bitcoin, and whose future income was denominated in it, faced a simple calculation: a 51% scare hurts the bitcoin price, and the bitcoin price is their revenue. Staying in the biggest pool stopped being the rational choice the moment the pool's size itself became a threat to the value of the thing being mined.

This is a genuine market mechanism, not just community sentiment. Miners hold a direct financial stake in the network's credibility, and they can act on it instantly and unilaterally. It's messier and slower than a protocol rule, and it depends on miners paying attention, but in June and July 2014 it demonstrably worked. Hashrate dispersed. GHash never regained its peak share.

The pledge held, and it didn't matterThe pledge held, and it didn't matter

Here's the epilogue that carries the real lesson. GHash.io kept its word. There was no attack, no secret chain, no censorship. And the pool died anyway.

The reputational damage from the June incident kept driving miners to competitors through 2014 and 2015. GHash's share of the network collapsed from majority to marginal, and the pool eventually shut down entirely. Being trustworthy wasn't enough, because the market had internalized Todd's point: it didn't want a pool whose trustworthiness mattered.

That's the enduring takeaway from July 16, 2014. Bitcoin's biggest mining scare was resolved not by an emergency patch but by social pressure, an unenforceable promise, and thousands of miners quietly moving their hashrate. The system's defense turned out to be economic gravity rather than code. Whether that's reassuring or unsettling is, twelve years later, still a fair debate. Both sides of it were argued in a London conference room the day the biggest miner in the world promised to be good.


Part of an ongoing series on Bitcoin history. Follow @daily_btc_lore on X for daily threads.

A hashpool mining SHA256 named Ghash, lol.

reply