Bitcoin 51% Attack Cost Calculator
Calculate the theoretical cost of a 51% attack on Bitcoin based on current hash rate, hardware costs, and electricity prices. See why the network is secure.
What Does a 51% Attack on Bitcoin Cost?
A 51% attack occurs when a single entity gains control of more than half of a proof-of-work network's hash rate, allowing them to rewrite recent transaction history and double-spend coins. For Bitcoin, the cost of executing such an attack has grown to the point where researchers at Coin Metrics, Duke University, and Charles Schwab have independently concluded that it is economically unfeasible.
As of October 2026, Bitcoin's network hash rate is approximately 950 EH/s. An attacker would need to deploy roughly 475 EH/s of dedicated mining hardware: enough to outpace every existing miner on the network combined. The following table breaks down the estimated costs using current-generation ASIC pricing and industrial electricity rates.
| Cost Component | Estimate | Assumptions |
|---|---|---|
| ASIC hardware | ~$10.5 billion | 1.76M Antminer S21 XP units at $6,000 each (270 TH/s per unit) |
| Data center infrastructure | ~$4.8 billion | 6.4 GW of cooling, racking, and power distribution at ~$750K per MW |
| Electricity (per month) | ~$231 million | 6.4 GW continuous draw at $0.05/kWh industrial rate |
| Electricity (per year) | ~$2.8 billion | Same rate, sustained operation |
| Total (first year) | ~$18 billion+ | Hardware + infrastructure + 12 months of electricity |
These figures are conservative. They assume hardware is available at retail pricing and ignore the supply-chain bottleneck that would drive ASIC prices far higher if anyone attempted to purchase 1.76 million units. They also exclude land acquisition, network connectivity, staffing, and the opportunity cost of capital.
Hardware Requirements and Supply Constraints
The latest generation of Bitcoin ASIC miners delivers dramatically better efficiency than hardware from even two years ago. The Bitmain Antminer S21 XP family represents the current performance frontier, with efficiency ratings around 12 to 13.5 joules per terahash. The following table compares current-generation models.
| Model | Hash Rate | Power Draw | Efficiency | Price | Units for 475 EH/s |
|---|---|---|---|---|---|
| Antminer S21 XP | 270 TH/s | 3,645 W | 13.5 J/TH | ~$6,000 | ~1,759,000 |
| Antminer S21 XP Hyd | 473 TH/s | 5,676 W | 12.0 J/TH | ~$10,500 | ~1,004,000 |
| Antminer S21 XP Immersion | 300 TH/s | 4,050 W | 13.5 J/TH | ~$6,500 | ~1,583,000 |
Even using the most efficient hydro-cooled units, an attacker would need over one million ASICs. Global ASIC manufacturing capacity is limited to a few hundred thousand units per quarter across all manufacturers combined. Researchers at Coin Metrics highlighted this bottleneck in their 2024 analysis, noting that acquiring enough chips alone could push costs above $20 billion due to supply-driven price increases. The attacker would also be competing with legitimate miners who are continuously purchasing new hardware.
For a broader view of the mining hardware landscape, see our Bitcoin mining hardware comparison.
Electricity and Infrastructure Costs
Deploying 475 EH/s of S21 XP hardware would draw approximately 6.4 gigawatts of continuous power. For context, that exceeds the total generating capacity of many small countries and is roughly equivalent to six large nuclear power plants running at full output. The electricity cost varies dramatically by region.
| Region | Industrial Rate ($/kWh) | Monthly Cost (6.4 GW) | Annual Cost |
|---|---|---|---|
| Texas (PPA) | $0.04 - $0.07 | $184M - $322M | $2.2B - $3.9B |
| US Average Industrial | ~$0.089 | ~$409M | ~$4.9B |
| Kazakhstan | ~$0.04 | ~$184M | ~$2.2B |
| Paraguay (Hydro) | ~$0.03 | ~$138M | ~$1.7B |
| Germany | ~$0.18 | ~$829M | ~$9.9B |
Beyond raw electricity, the attacker must build or lease data center space with adequate cooling infrastructure. Air-cooled mining facilities typically cost $500,000 to $1 million per megawatt to construct, while immersion-cooled setups run higher. At 6.4 GW of demand, infrastructure buildout alone reaches several billion dollars and would take 12 to 24 months to complete: a timeline during which the network's hash rate would continue to grow.
Attack Cost Comparison Across PoW Chains
Bitcoin's attack cost dwarfs every other proof-of-work blockchain. Smaller PoW chains have been successfully attacked multiple times, demonstrating that hash rate directly determines security. The contrast illustrates why Bitcoin's security model works: the cost to attack scales with the value protected.
| Network | Consensus | Est. 1-Hour Attack Cost | Known Successful Attacks |
|---|---|---|---|
| Bitcoin | SHA-256 PoW | $10M+ | None |
| Litecoin | Scrypt PoW | ~$50K - $100K | None confirmed |
| Bitcoin Cash | SHA-256 PoW | ~$25K - $75K | None confirmed |
| Ethereum Classic | Etchash PoW | ~$5K - $20K | Multiple (2019, 2020) |
| Bitcoin Gold | Equihash PoW | ~$1K - $5K | Yes (2018, $18M+ stolen) |
| Bitcoin SV | SHA-256 PoW | ~$5K - $15K | Multiple (2021, 4+ reorgs) |
Ethereum Classic suffered a series of 51% attacks in August 2020 that disrupted over 10,000 blocks and resulted in millions of dollars in double-spends. Bitcoin SV was hit by at least four separate reorg attacks between June and July 2021. Bitcoin Gold lost over $18 million to a 51% attack in 2018. In each case, the low hash rate relative to available rental hash power made the attack profitable.
Bitcoin has never suffered a successful 51% attack. The combination of dedicated ASIC hardware (which cannot be repurposed to attack other chains), enormous capital requirements, and strong economic disincentives makes the attack impractical. For a deeper analysis of how mining pool concentration affects this equation, see the hash rate distribution tracker.
Defense Mechanisms Beyond Raw Hash Rate
Hash rate is the primary security metric, but Bitcoin has multiple overlapping defense layers that make 51% attacks even harder to execute successfully.
Node Decentralization
Bitcoin's network includes tens of thousands of full nodes operated independently worldwide. These nodes enforce consensus rules regardless of what miners produce. An attacker controlling 51% of hash rate can reorder transactions and double-spend, but they cannot change the rules of the protocol: they cannot inflate the supply, steal coins from addresses they don't control, or remove the block size limit. Nodes would simply reject blocks that violate consensus rules.
Social Consensus and Emergency Response
If a sustained 51% attack were detected, the Bitcoin community has the option of deploying a user-activated soft fork to change the mining algorithm, rendering the attacker's ASIC investment worthless. This "nuclear option" has never been needed, but its existence functions as a deterrent. The attacker knows that a multi-billion-dollar hardware investment could be made obsolete by a coordinated software update, which represents social consensus operating as a final layer of defense.
Confirmation Depth and Exchange Policies
The practical goal of most 51% attacks is double-spending: depositing coins on an exchange, trading them, withdrawing, then rewriting the chain to reverse the original deposit. Exchanges defend against this by requiring multiple block confirmations before crediting deposits. Bitcoin's standard of 6 confirmations (roughly one hour) means an attacker must sustain their majority hash rate for at least that long, multiplying the cost. Many exchanges require even more confirmations for large deposits.
Economic Disincentives
An attacker who acquires $10+ billion in mining hardware has a strong incentive to mine honestly rather than attack. Honest mining generates block rewards and transaction fees, providing a return on investment. A successful attack would crash the Bitcoin price, destroying the value of both the attacker's hardware (which is useful only for Bitcoin mining) and any Bitcoin they hold. The attacker is, in effect, burning down a house they just bought.
How Layer 2s Inherit Bitcoin's Security
Bitcoin's security budget protects not only the base layer but also the Layer 2 protocols built on top of it. Networks like the Lightning Network and Spark anchor their state to Bitcoin's blockchain, meaning their transaction finality is ultimately backed by the same proof-of-work security that costs billions to overcome.
When a user settles a transaction on Spark, the final settlement can reference Bitcoin's base layer. This means that attacking a Spark transaction with the same finality guarantees as an on-chain Bitcoin transaction would require the same prohibitive cost: control of 51% of Bitcoin's hash rate. Layer 2 solutions effectively inherit Bitcoin's security without duplicating its energy expenditure, a design that enables fast, low-cost payments while maintaining the strongest settlement assurances in cryptocurrency.
For a comprehensive overview of how different Layer 2 architectures relate to Bitcoin's base-layer security, see our research on the Bitcoin second-layer scaling landscape.
The Security Budget and Future Hash Rate Growth
Bitcoin's block subsidy is currently 3.125 BTC per block (post-April 2024 halving). At approximately $78,000 per BTC, miners earn roughly $12.8 billion annually in subsidies alone. Transaction fees contribute an additional ~0.6% on top, based on recent weekly data from btc.network.
This revenue funds the hash rate that makes attacks expensive. As the subsidy halves every 210,000 blocks (approximately every four years), the network will increasingly depend on transaction fees to maintain its security budget. The next halving in 2028 will reduce the subsidy to 1.5625 BTC per block. Whether fee revenue can compensate remains an open question explored in depth in our research on Bitcoin's fee-only security future.
Despite the halving schedule, Bitcoin's hash rate has grown at an average of roughly 51% per year since November 2022, driven by improvements in ASIC efficiency and expanding mining operations globally. If this trend continues, the cost to attack will keep rising even as the subsidy declines: a race between hardware efficiency gains and diminishing block rewards.
Frequently Asked Questions
How much would a 51% attack on Bitcoin cost in 2026?
Based on the current network hash rate of approximately 950 EH/s, the hardware cost alone to deploy 475 EH/s of latest-generation ASICs exceeds $10 billion. Adding data center infrastructure and electricity pushes the total above $18 billion for the first year. In practice, supply constraints on ASIC manufacturing would drive the real cost even higher.
Has Bitcoin ever been 51% attacked?
No. Bitcoin has never suffered a successful 51% attack. The network's hash rate has been too large and too dominated by dedicated ASIC hardware to make such an attack economically viable. Other proof-of-work chains with lower hash rates, including Ethereum Classic, Bitcoin Gold, and Bitcoin SV, have been successfully attacked.
Could a nation-state execute a 51% attack on Bitcoin?
A nation-state could theoretically allocate the resources, but the attack would take 12 to 24 months to execute due to ASIC manufacturing lead times and infrastructure construction. During that period, the network would likely detect the buildup through increased ASIC demand and respond. The community could change the mining algorithm via a soft fork, rendering all the attacker's specialized hardware worthless overnight.
What is the difference between a 51% attack and a Sybil attack?
A 51% attack requires controlling the majority of mining hash power to rewrite transaction history. A Sybil attack involves creating many fake identities (nodes) to gain disproportionate influence over the network. Bitcoin's proof-of-work consensus makes Sybil attacks irrelevant for block production because influence is determined by hash rate, not node count.
Does the Bitcoin hash rate need to keep growing for the network to stay secure?
Not necessarily. Security depends on the cost to attack relative to the value that can be stolen. As long as the cost of acquiring 51% of the hash rate significantly exceeds the potential profit from a double-spend, the network is secure. Improvements in ASIC efficiency mean that hash rate can grow even if total mining revenue stays flat or declines slightly.
Why can't an attacker just rent hash power instead of buying hardware?
Bitcoin uses the SHA-256 algorithm with dedicated ASIC hardware that has no meaningful secondary market for rental. Unlike GPU-mineable coins where hash power can be rented on platforms like NiceHash, there is no rental market with anywhere near enough SHA-256 hash rate to approach 51% of Bitcoin's network. The total hash rate available for rent represents a negligible fraction of Bitcoin's 950 EH/s.
What happens during a 51% attack?
The attacker mines blocks privately, building an alternative chain longer than the public one. They send a transaction (for example, depositing BTC on an exchange), wait for confirmations, then broadcast their longer private chain. The network switches to the longer chain per the longest chain rule, reversing the original transaction. The attacker keeps both the exchanged assets and the original BTC. This is why exchanges require multiple confirmations before crediting large deposits.
This tool is for informational purposes only and does not constitute financial or security advice. Cost estimates are approximate and based on publicly available hardware pricing, hash rate data, and industrial electricity rates as of October 2026. Actual attack costs would differ based on market conditions, supply availability, and operational factors. Always verify current data before making decisions.
Build with Spark
Integrate bitcoin, Lightning, and stablecoins into your app with a few lines of code.
Read the docs →
