When Ravencoin’s development team asked the two mining pools now rebuilding its blockchain to pick a less disruptive recovery point, the pools said no. That exchange, disclosed by Ravencoin’s own notice, sits at the center of what has happened to the network over the past four days. It is a striking admission for a project that has now weathered three separate breakdowns in its consensus or asset layer since 2018. What happens to the current fork, and to the three days of transactions caught in it, is no longer a decision Ravencoin’s own team is making alone.
Ravencoin Network Notice
A critical consensus vulnerability has been demonstrated and exploited on the Ravencoin network.
The issue caused invalid blocks to be accepted by vulnerable nodes. The first known invalid block appeared at height 4,487,776 on 2026-08-07 15:44:01 UTC.…
— Project Raven 🦅/ RVN / Ravencoin (@Ravencoin) August 10, 2026
What Actually Happened
The first fraudulent block was accepted at height 4,487,776, mined just before 4pm UTC on August 7. The flaw sat in a header field called nHeight, part of Ravencoin’s KAWPOW proof of work validation. That field is supposed to be checked against a block’s actual position in the chain. It never was. Exploiting the gap let an attacker submit blocks without doing the computational work KAWPOW is meant to require in the first place, effectively minting valid-looking blocks for free.
Once the flaw was demonstrated on mainnet, Ravencoin’s notice says similar invalid blocks began appearing from other sources as well, suggesting the trick was copied once it became visible. Between block heights 4,489,527 and 4,491,615, a stretch of 2,089 blocks, roughly 96 turned out to be forged. Nodes running the standard software started crashing on restart with database errors, and syncing broke down entirely as clean nodes rejected peers that were serving corrupted headers.
The patch, v4.6.1.1-hf1, addresses this directly: it enforces proper height validation from block 4,487,776 onward, adds a checkpoint at block 4,487,775 to lock in the last known-good history, and rebuilds a node’s chainstate and asset database automatically if they fall out of sync. The release notes are direct about who needs to act: “every node operator, pool, exchange and explorer should upgrade.” The notes also warn that the first restart after upgrading can take several hours, since the software has to replay a large stretch of blockchain history to rebuild its state.
Pools Take Over the Recovery
2Miners and RavenMiner, which together hold most of the network’s mining power, responded by building a competing chain that discards everything after block 4,487,776. If that chain outruns the compromised one, close to three days of Ravencoin transaction history gets rewritten. Ravencoin has told exchanges to treat everything confirmed after block 4,487,775 as unsettled, and warned that reversed deposits and withdrawals won’t automatically reappear or reconfirm. Exchanges including Upbit and Bitvavo paused RVN deposits and withdrawals while the fork plays out. RVN itself was trading down close to 18% in the day after the notice went out, around $0.0036.
The Request That Got Turned Down
Before the pools settled on 4,487,776 as their starting point, Ravencoin’s team asked them to consider a more recent recovery point instead, one that would have spared a larger share of recent transactions from being unwound. The pools declined and went ahead with the earlier point regardless. Ravencoin’s own attempt to soften the impact on users and exchanges did not survive contact with the people actually running the recovery.
Built Somewhere Else
The code fixing the bug did not come from Ravencoin’s development team either. It shipped from 2Miners’ own GitHub repository as an emergency release, and the release notes say plainly why: upstream Ravencoin development is inactive, no fix had been published, and 2Miners decided to ship one itself rather than wait.
Friction over who actually owns a fix, and who gets credit or compensation for finding the problem in the first place, has come up elsewhere in crypto recently too. THORChain is currently facing similar accusations from a researcher who says a flaw he reported was patched quietly and without payment.
Three Failures, Three Outside Fixes
This is not the first time something has broken in how Ravencoin’s chain or its asset system holds up.
- September 2018: a double-spend attack rewrote 22 blocks. Lead developer Tron Black’s team responded by capping how far any future reorganization could reach, set at 60 blocks by default.
- 2019: a team from a separate project, Raptoreum, found four bugs in how Ravencoin’s asset issuance and reissuance worked, including one that would have let someone mint sub-assets they had no rights to. Ravencoin fixed all four across two releases and paid a bounty for the disclosure. None were ever exploited live.
- May to July 2020: one of those same weak points got used for real. An attacker found a way to inject RVN value into asset reissue transactions, adding roughly 500,000 RVN every two hours for about seven weeks, spreading it across addresses and moving it through exchanges before anyone caught it. By the time CryptoScope spotted the pattern while resyncing a block explorer on June 29, the total had reached about 301.8 million RVN, close to 1.4% of Ravencoin’s 21 billion coin supply cap. Ravencoin shipped a fix within days and enforced it at block 1,304,352 on July 4.
In each of those cases, the party that caught or fixed the problem sat outside Ravencoin’s own team: Raptoreum in 2019, CryptoScope in 2020. This month adds a third name to that list. 2Miners wrote the patch, and decided on its own how far back to roll the chain, over the objection of the team whose name is on the project.
Ravencoin’s case involved no user funds moving hands. That is not always true of vulnerabilities like this: a wallet-generation flaw called Ill Bloom has already drained millions of dollars from thousands of accounts since May.
Whichever chain wins the current fork race will settle the immediate question of which three days of transactions actually count. It won’t settle who is responsible for catching the next bug before it reaches mainnet, or for deciding how the network responds when one does. On both of those questions, this month’s events left the answer sitting with the pools, not with Ravencoin.
AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.
We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

















