← Ravencoin Consensus Vulnerability Exploit (August 2026)1 decision on this page
Audit log
Every state-changing event for Ravencoin Consensus Vulnerability Exploit (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-14 23:21:51ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Cr4Cm7KvViBw…zYe79rbBsha256 → base58
verifying row…canonical bytes (20644 B) ▸
{"actor":"system:backfill","investigation_id":"06c78961-71f4-45b4-8c5c-095eeb41b058","kind":"publish","page_slug":"ravencoin-consensus-vulnerability-exploit-august-2026","published_at":"2026-08-14T23:21:51.826Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ravencoin Consensus Vulnerability Exploit (August 2026)","sections":[{"content":"The vulnerability exists in Ravencoin's KAWPOW proof-of-work block header validation logic. According to 2Miners, the pool that identified and patched the flaw, the nHeight field embedded in KAWPOW block headers was not verified against a block's actual position in the blockchain. An attacker who manipulated this field could reach a shortcut validation path that skipped the full memory-intensive proof-of-work check entirely, accepting a supplied mix hash without confirming that any genuine ProgPoW mining had occurred. This allowed an attacker to produce invalid blocks at a cost described by 2Miners as 'orders of magnitude cheaper' than legitimate mining. The exploit does not directly steal funds from wallets; rather, it corrupts the chain's integrity by allowing invalid blocks to be inserted into the canonical chain, which vulnerable nodes accepted as valid.","heading":"Exploit Mechanism","severity":"critical","sources":[{"credibility":2,"name":"Ravencoin falls 19% as consensus flaw splits network","type":"news_article","url":"https://crypto.news/ravencoin-falls-as-consensus-flaw-splits-network/"},{"credibility":2,"name":"Ravencoin Faces 3-Day Reorg After Critical KAWPOW Exploit","type":"news_article","url":"https://coinpaper.com/34130/ravencoin-faces-3-day-reorg-after-critical-kawpow-exploit"},{"credibility":2,"name":"Ravencoin Crashes 20% as Critical Exploit Threatens to Rollback Network","type":"news_article","url":"https://decrypt.co/375330/ravencoin-crashes-critical-exploit-threatens-rollback"}]},{"content":"The first confirmed invalid block appeared at height 4,487,776 at 15:44:01 UTC on August 7, 2026, according to the official Ravencoin network notice posted to the project's X account. Exploitation continued undetected for approximately three days before being disclosed publicly on August 11, 2026. A sample analysis of blocks between heights 4,489,527 and 4,491,615 identified 96 affected blocks out of 2,089 examined, indicating a meaningful but not total contamination rate in that range. No affected blocks were found in samples checked prior to height 4,487,776. Nodes began reporting database errors as a downstream symptom of the corrupted chain state. The identity of the attacker or attackers is unknown as of the date of this investigation.","heading":"Scope and Timeline of Exploitation","severity":"critical","sources":[{"credibility":1,"name":"Project Raven / RVN / Ravencoin on X — official network notice","type":"official","url":"https://x.com/Ravencoin/status/2086862580014850412"},{"credibility":2,"name":"Ravencoin Consensus Vulnerability Disrupts Network Integrity","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/11/ravencoin-consensus-vulnerability/"},{"credibility":1,"name":"Ravencoin could roll back four days of transactions after critical block flaw","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/11/ravencoin-could-roll-back-four-days-of-transactions-after-critical-block-flaw"}]},{"content":"Mining pool 2Miners released emergency patch version 4.6.1.1-hf1 on August 10, 2026, from its own GitHub repository. The patch enforces proper height validation from block 4,487,776 onward, sets a checkpoint at block 4,487,775 (the last known-good block), and automatically rebuilds a node's chainstate and asset database if they are found to be out of sync. The initial restart following the patch can take several hours because the software replays approximately 4.49 million blocks and 28 million transactions. Both 2Miners and RavenMiner, which together control a majority of the network's hashrate, began mining on a competing chain that excludes all blocks in the exploited branch from height 4,487,776 onward. Ravencoin's core development team requested that the pools choose a more recent recovery point to minimize the volume of transactions that would be reversed; both pools declined that request and proceeded with the checkpoint at block 4,487,775. The patch was issued by 2Miners rather than Ravencoin's own team, which reporting by cryip.co described as inactive. RavenMiner stated its nodes are running the emergency fix and committed to covering any payout shortfalls arising from the reorganization; it confirmed that miner earnings from before the attack window are unaffected.","heading":"Emergency Patch and Recovery Response","severity":"high","sources":[{"credibility":2,"name":"Ravencoin's Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team","type":"news_article","url":"https://cryip.co/ravencoin-consensus-failure-fix-mining-pool-not-core-team/"},{"credibility":2,"name":"Ravencoin Faces 3-Day Reorg After Critical KAWPOW Exploit","type":"news_article","url":"https://coinpaper.com/34130/ravencoin-faces-3-day-reorg-after-critical-kawpow-exploit"},{"credibility":1,"name":"Ravencoin could roll back four days of transactions after critical block flaw","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/11/ravencoin-could-roll-back-four-days-of-transactions-after-critical-block-flaw"}]},{"content":"Upbit (South Korea) suspended RVN deposits and withdrawals on August 10, 2026, and placed an investment warning on RVN trading pairs, citing the exploited vulnerability. Bitget suspended RVN transfers beginning August 10, citing wallet maintenance. Bitvavo (Netherlands) suspended RVN movement as a precautionary measure. KuCoin also issued a public notice describing the network as impacted. The Ravencoin project advised treating all transaction confirmations after block 4,487,775 as potentially reversible until network stability was restored. Users who received RVN between August 7 and the chain's stabilization should treat those confirmations as unresolved, as the ongoing reorganization effort by 2Miners and RavenMiner could erase up to three to four days of transaction history if the clean chain accumulates sufficient work to become dominant. Trading remained active on affected exchanges despite transfer suspensions, creating a risk that market prices reflected a chain state that may be rolled back.","heading":"Exchange Suspensions and User Risk","severity":"critical","sources":[{"credibility":2,"name":"Upbit Suspends Ravencoin (RVN) Deposits and Withdrawals Amid Network Issue","type":"news_article","url":"https://cryptorank.io/news/feed/a2053-upbit-suspends-ravencoin-deposits-withdrawals"},{"credibility":2,"name":"Ravencoin Falls 18% as Exchanges Suspend RVN Transfers","type":"news_article","url":"https://www.cryptotimes.io/2026/08/11/ravencoin-falls-18-as-exchanges-suspend-rvn-transfers/"},{"credibility":2,"name":"Ravencoin Network Hit by Hack, Exchanges Halt RVN Deposits and Withdrawals","type":"news_article","url":"https://www.kucoin.com/news/flash/ravencoin-network-hit-by-hack-exchanges-halt-rvn-deposits-and-withdrawals"},{"credibility":2,"name":"Ravencoin Faces Deep Reorg Risk After Consensus Bug Exploited, Exchanges Told To Suspend RVN Flows","type":"news_article","url":"https://mpost.io/ravencoin-faces-deep-reorg-risk-after-consensus-bug-exploited-exchanges-told-to-suspend-rvn-flows/"}]},{"content":"RVN fell approximately 19.1% within 24 hours of the August 11 public disclosure, trading at around $0.00288, according to crypto.news. Market capitalization declined to approximately $47.3 million. One source (Decrypt) reported a single-day loss of approximately 20.4% on the RVN/USDT pair, and CoinDesk reported a 17% decline to approximately $0.0029. CoinTrust noted the token was down approximately 77% over the prior year, establishing that the exploit occurred during a period of extended decline for RVN. The token shed approximately 50% from late-May 2026 levels near $0.0055 even before the exploit was publicly disclosed.","heading":"Market Impact","severity":"high","sources":[{"credibility":2,"name":"Ravencoin falls 19% as consensus flaw splits network","type":"news_article","url":"https://crypto.news/ravencoin-falls-as-consensus-flaw-splits-network/"},{"credibility":2,"name":"Ravencoin Crashes 20% as Critical Exploit Threatens to Rollback Network","type":"news_article","url":"https://decrypt.co/375330/ravencoin-crashes-critical-exploit-threatens-rollback"},{"credibility":1,"name":"Ravencoin could roll back four days of transactions after critical block flaw","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/11/ravencoin-could-roll-back-four-days-of-transactions-after-critical-block-flaw"}]},{"content":"Multiple outlets noted that the emergency patch (v4.6.1.1-hf1) was released from a mining pool's GitHub repository rather than from Ravencoin's own core team, with cryip.co reporting that 'upstream Ravencoin development is inactive.' The core team's request that pools adopt a gentler rollback point was declined, with the pools proceeding on their own judgment. This incident is consistent with a documented pattern across the project's history in which critical bugs have been discovered and addressed by outside parties rather than the internal team. Raptoreum discovered asset-layer vulnerabilities in 2019; CryptoScope identified the 2020 inflation exploit; and 2Miners identified and patched the August 2026 KAWPOW flaw. The degree to which the core team's current activity level or composition has changed since 2020 is not independently verified in sources reviewed for this investigation.","heading":"Governance and Development Activity Concerns","severity":"high","sources":[{"credibility":2,"name":"Ravencoin's Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team","type":"news_article","url":"https://cryip.co/ravencoin-consensus-failure-fix-mining-pool-not-core-team/"}]},{"content":"The August 2026 incident is the third significant consensus-level failure in Ravencoin's history, according to reporting by cryip.co. In September 2018, a double-spend attack rewrote 22 blocks; the response capped future reorganizations at 60 blocks. In 2019, the Raptoreum team discovered four asset-layer bugs, including one enabling unauthorized sub-asset minting; Ravencoin patched the issues and paid bounties, and none were exploited live. Between May and July 2020, an attacker exploited a flaw introduced by a community code submission to inject approximately 315 million extra RVN into reissuance transactions over seven weeks, representing approximately 1.5% of the total supply cap. CryptoScope identified the pattern and alerted Ravencoin, which patched the network by block 1,304,352 on July 4, 2020. CoinDesk and CryptoPotato covered the 2020 incident at the time. The recurrence of consensus-level vulnerabilities across different components of the codebase (block reorganization limits in 2018, asset-layer logic in 2020, and KAWPOW header validation in 2026) is a documented pattern.","heading":"Historical Pattern of Consensus Failures","severity":"high","sources":[{"credibility":2,"name":"Ravencoin's Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team","type":"news_article","url":"https://cryip.co/ravencoin-consensus-failure-fix-mining-pool-not-core-team/"},{"credibility":1,"name":"Bad Ravencoin Code Allows Attackers to Generate Coins Without Mining","type":"news_article","url":"https://www.coindesk.com/markets/2020/07/03/bad-ravencoin-code-allows-attackers-to-generate-coins-without-mining"},{"credibility":2,"name":"Hackers Exploit Vulnerability in Ravencoin Protocol to Mint 315 Million Fake RVN Coins","type":"news_article","url":"https://cryptopotato.com/hackers-exploit-vulnerability-in-ravencoin-protocol-to-mint-315-million-fake-rvn-coins/"}]},{"content":"As of the date of this investigation (August 14, 2026), the chain reorganization was in progress but no sources confirmed its completion or full network stabilization. The Ravencoin project advised users and services to treat all confirmations after block 4,487,775 as potentially reversible. Exchange transfer suspensions at Upbit, Bitget, and Bitvavo remained in effect per the most recent reporting available. Users should verify directly with exchanges and the Ravencoin project whether deposits and withdrawals have been reopened and whether the clean chain has achieved sufficient dominance before treating any RVN transaction confirmed after August 7, 2026 as final. This page will require updating when the reorganization concludes and exchanges resume normal operations.","heading":"Resolution Status","severity":"high","sources":[{"credibility":1,"name":"Project Raven / RVN / Ravencoin on X — official network notice","type":"official","url":"https://x.com/Ravencoin/status/2086862580014850412"},{"credibility":2,"name":"Ravencoin Faces 3-Day Reorg After Critical KAWPOW Exploit","type":"news_article","url":"https://coinpaper.com/34130/ravencoin-faces-3-day-reorg-after-critical-kawpow-exploit"}]}],"sources_used":[{"credibility":1,"name":"Project Raven / RVN / Ravencoin on X — official network notice","type":"official","url":"https://x.com/Ravencoin/status/2086862580014850412"},{"credibility":1,"name":"Ravencoin could roll back four days of transactions after critical block flaw — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/11/ravencoin-could-roll-back-four-days-of-transactions-after-critical-block-flaw"},{"credibility":2,"name":"Ravencoin Crashes 20% as Critical Exploit Threatens to Rollback Network — Decrypt","type":"news_article","url":"https://decrypt.co/375330/ravencoin-crashes-critical-exploit-threatens-rollback"},{"credibility":2,"name":"Ravencoin falls 19% as consensus flaw splits network — crypto.news","type":"news_article","url":"https://crypto.news/ravencoin-falls-as-consensus-flaw-splits-network/"},{"credibility":2,"name":"Ravencoin drops to record low as miners move to reverse exploited chain — crypto.news","type":"news_article","url":"https://crypto.news/ravencoin-drops-to-record-low-as-miners-move-to-reverse-exploited-chain/"},{"credibility":2,"name":"Ravencoin Faces 3-Day Reorg After Critical KAWPOW Exploit — CoinPaper","type":"news_article","url":"https://coinpaper.com/34130/ravencoin-faces-3-day-reorg-after-critical-kawpow-exploit"},{"credibility":2,"name":"Ravencoin Faces 3-Day Reorg After Critical KAWPOW Exploit — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/432e8-ravencoin-faces-3-day-reorg-after-critical-kawpow-exploit"},{"credibility":2,"name":"Ravencoin Consensus Vulnerability Disrupts Network Integrity — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/11/ravencoin-consensus-vulnerability/"},{"credibility":2,"name":"Ravencoin's Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team — cryip.co","type":"news_article","url":"https://cryip.co/ravencoin-consensus-failure-fix-mining-pool-not-core-team/"},{"credibility":2,"name":"Ravencoin Falls 18% as Exchanges Suspend RVN Transfers — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/11/ravencoin-falls-18-as-exchanges-suspend-rvn-transfers/"},{"credibility":2,"name":"Upbit Suspends Ravencoin (RVN) Deposits and Withdrawals Amid Network Issue — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/a2053-upbit-suspends-ravencoin-deposits-withdrawals"},{"credibility":2,"name":"Ravencoin Network Hit by Hack, Exchanges Halt RVN Deposits and Withdrawals — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/ravencoin-network-hit-by-hack-exchanges-halt-rvn-deposits-and-withdrawals"},{"credibility":2,"name":"Ravencoin Faces Deep Reorg Risk After Consensus Bug Exploited, Exchanges Told To Suspend RVN Flows — Metaverse Post","type":"news_article","url":"https://mpost.io/ravencoin-faces-deep-reorg-risk-after-consensus-bug-exploited-exchanges-told-to-suspend-rvn-flows/"},{"credibility":2,"name":"Ravencoin Faces Four-Day Blockchain Rollback After Attack — CoinTrust","type":"news_article","url":"https://www.cointrust.com/market-news/ravencoin-faces-four-day-blockchain-rollback-after-attack"},{"credibility":1,"name":"Bad Ravencoin Code Allows Attackers to Generate Coins Without Mining — CoinDesk (2020)","type":"news_article","url":"https://www.coindesk.com/markets/2020/07/03/bad-ravencoin-code-allows-attackers-to-generate-coins-without-mining"},{"credibility":2,"name":"Hackers Exploit Vulnerability in Ravencoin Protocol to Mint 315 Million Fake RVN Coins — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/hackers-exploit-vulnerability-in-ravencoin-protocol-to-mint-315-million-fake-rvn-coins/"},{"credibility":2,"name":"Ravencoin Token Drops 19% Amid Blockchain Reorganization Risk — ForkLog","type":"news_article","url":"https://forklog.com/en/ravencoin-token-drops-19-amid-blockchain-reorganization-risk/"},{"credibility":2,"name":"Ravencoin faces four-day rollback after consensus flaw — Arabian Post","type":"news_article","url":"https://thearabianpost.com/ravencoin-faces-four-day-rollback-after-consensus-flaw/"}],"summary":"On August 7, 2026, an attacker exploited a critical consensus vulnerability in the Ravencoin (RVN) network by manipulating the nHeight field in KAWPOW block headers to bypass proof-of-work verification. Invalid blocks were accepted by vulnerable nodes beginning at block height 4,487,776, prompting exchanges Upbit, Bitget, and Bitvavo to suspend RVN deposits and withdrawals and causing RVN to fall approximately 19% to around $0.00288. An emergency patch (v4.6.1.1-hf1) was released on August 10, 2026 by mining pool 2Miners rather than Ravencoin's core development team, marking at least the third significant consensus-level failure in the network's history.","timeline":[{"date":"2018-09-01","event":"First known consensus failure: double-spend attack rewrites 22 Ravencoin blocks; response caps future reorganizations at 60 blocks.","source":"Ravencoin's Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team","source_url":"https://cryip.co/ravencoin-consensus-failure-fix-mining-pool-not-core-team/"},{"date":"2020-07-02","event":"Ravencoin discloses second major consensus failure: attacker exploited coinbase logic to mint approximately 315 million unauthorized RVN tokens over seven weeks. CryptoScope alerted the team; patched at block 1,304,352 on July 4, 2020.","source":"Bad Ravencoin Code Allows Attackers to Generate Coins Without Mining — CoinDesk","source_url":"https://www.coindesk.com/markets/2020/07/03/bad-ravencoin-code-allows-attackers-to-generate-coins-without-mining"},{"date":"2026-08-07","event":"First invalid KAWPOW block accepted by vulnerable Ravencoin nodes at height 4,487,776 at 15:44:01 UTC. Exploitation begins. Attacker manipulates nHeight header field to bypass proof-of-work verification.","source":"Project Raven / RVN / Ravencoin on X — official network notice","source_url":"https://x.com/Ravencoin/status/2086862580014850412"},{"date":"2026-08-10","event":"Mining pool 2Miners releases emergency patch v4.6.1.1-hf1 from its own GitHub repository, setting a checkpoint at block 4,487,775 and enforcing proper nHeight validation. Upbit and Bitget suspend RVN deposits and withdrawals. Bitvavo follows with a precautionary suspension.","source":"Ravencoin falls 19% as consensus flaw splits network — crypto.news","source_url":"https://crypto.news/ravencoin-falls-as-consensus-flaw-splits-network/"},{"date":"2026-08-11","event":"Ravencoin publicly discloses the vulnerability via official X account. 2Miners and RavenMiner begin mining a competing clean chain from block 4,487,775, excluding the exploited branch. Ravencoin's core team requests a gentler rollback point; pools decline. RVN falls approximately 19% to around $0.00288. CoinDesk, Decrypt, and crypto.news publish coverage.","source":"Ravencoin could roll back four days of transactions after critical block flaw — CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/11/ravencoin-could-roll-back-four-days-of-transactions-after-critical-block-flaw"},{"date":"2026-08-14","event":"Chain reorganization in progress as of this investigation. No sources have confirmed completion of the reorg or reopening of exchange deposits and withdrawals. Status remains unresolved.","source":"AVOID.NET investigation — current date","source_url":"https://avoid.net"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 01fbeca4-9578-47c1-aae8-c7fe7d2484a0
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.