Why Bitcoin's Attack Costs Matter for Valuation
Key takeaways:
- In our view, the cost of executing a 51% attack on the Bitcoin network may rise with network growth, as higher hashrate could increase both the capital and coordination required, which could reduce the likelihood of such attacks. We interpret this as suggesting that Bitcoin's security may be economically self-reinforcing.
- Under the assumptions used in our analysis, even when incorporating large double-spend assumptions, the estimated total cost of attack—including capital expenditures (capex), energy, and competition—may exceed the potential extractable value, particularly when accounting for market and network responses.
- We believe that real-world constraints—hardware supply, energy infrastructure, time-to-build, and miner competition—may make it difficult to acquire and sustain majority hashrate, meaning the threshold for a 51% attack could be a moving and increasingly unreachable target.
- Our findings suggest that one way to frame bitcoin's value is through five interacting constraints: scarcity, energy, competition, probability, and limited extractable value, which together may help explain why attack costs could remain structurally higher than potential rewards under certain circumstances.
A 51% attack is an attempt—whether by an individual or a group—to control more than half of a blockchain network. Having 51% control of a blockchain network could theoretically give an attacker the ability to receive block rewards, transaction fees from previously mined blocks, and potentially capture double-spend transactions.
We previously analyzed the bitcoin miners' pivot to high-performance computing (HPC) for artificial intelligence (AI), and why we feel that increases network security over the long run. In our view, when more miners are active on the network, the blockchain may become more resistant to attack when network participation is broader because majority control of the network may become more difficult for any single entity or coordinated group. For a decentralized, permissionless, public blockchain, this is a core feature to enable trust in the network. In the case of a 51% attack, the attacker could theoretically alter previous transactions, delay transactions in process, and affect the ability for the correct version of the network to be maintained going forward.
Before diving in, it's helpful to define a few key concepts. Percent of Bitcoin network hashrate refers to a miner's estimated share of the total computing power securing the Bitcoin network. Operating hashrate represents the amount of computing power that an individual miner or mining company is actively running through its mining equipment.
Network hashrate is the estimated aggregate computing power contributed by all miners participating in the Bitcoin network. While a miner's operating hashrate can be compared against total network hashrate to estimate its share of the network, the two metrics measure different things and should not be used interchangeably.
A mining pool is a group of bitcoin miners that combine their computing power to improve their chances of successfully mining blocks. Any rewards earned are then distributed among participants based on the amount of computing power they contribute, subject to the pool's payout structure and applicable fees.
As the Bitcoin network continues to grow, its security potentially becomes self-reinforcing. Attempts at a 51% attack may become more expensive and may be limited by physical capex constraints and mathematics.
For example, the cost of executing a 51% attack rises with network growth, as higher hashrate increases both the capital (for hardware and energy) and coordination required, which could make attacks less economically feasible at scale, depending on assumptions about costs, timing, and potential payoff. Hashrate is the total computational power used by miners to secure the network and validate transactions. In mining, a hash is a single attempt to solve Bitcoin's cryptographic puzzle. One exahash is equal to one quintillion hashes. Hashrate is measured in exahashes per second (EH/s) and a higher hashrate is generally associated with a more secure network, although it isn't the only factor affecting network security.
In this article, we explore the economics of a 51% attack, why the Bitcoin network's growth has historically made it cost prohibitive to achieve this type of attack, and how this analysis can be used to estimate a fair value for proof-of-work cryptocurrencies like bitcoin. Proof-of-work is a process where computers (miners) compete to solve a mathematical puzzle. The first miner to find the solution earns the right to add the next block of transactions to the blockchain and receives a reward.
The Blockchain trilemma
Vitalik Buterin (co-founder of the Ethereum blockchain), coined the term "the blockchain trilemma," which describes a feature of many blockchain ecosystems wherein they must optimize two of three core variables—security, decentralization, and scalability—at the relative expense of the third.
Scalability refers to how fast a blockchain network can process transactions. The primary issue that security aims to solve is a situation where an individual, or group of individuals, could take control of 51% of the network and potentially censor (block, manipulate, or delay) transactions. Decentralization refers to how broadly control and participation are distributed across a network, including who can validate transactions, enforce rules, and influence changes to the protocol. In Bitcoin, network changes generally require broad adoption by the participants that run and enforce the software—such as node operators, miners, developers, exchanges, wallet providers, and users—rather than approval from a single central authority. Bitcoin owners do not vote on changes simply by holding bitcoin, and miners alone cannot rewrite the network’s rules without the broader network accepting those changes. This distribution of roles helps limit the ability of any one party to unilaterally control the system. This means changes to the network generally require broad adoption by the participants responsible for validating and enforcing the network's rules, helping ensure that no single party can unilaterally control the system.
The 10 largest publicly traded bitcoin miners by operating hashrate represent 35.4% of the Bitcoin network hashrate
Source: Schwab and Securities and Exchange Commission annual Form 10-K filings, as of June 30, 2026.
Operating hashrate reflects each miner's most recently reported active mining capacity. Percentages are calculated by comparing each miner's reported operating hashrate with estimated total Bitcoin network hashrate to approximate that miner's share of total network hashrate. Total network hashrate is approximately 1,000 EH/second. All corporate names and market data shown are for illustrative purposes only and are not a recommendation, offer to sell, or a solicitation of an offer to buy any security and are not intended to be, nor should they be construed as, a recommendation to buy, sell, or continue to hold any investment.
Key debate: Is bitcoin really decentralized if four mining pools represent about 70% of network hashrate?
Greater decentralization may improve network security, in our view. The smaller the share of total hashrate a miner has, the less likely they are to successfully complete a 51% attack. For example, if an attacker with a 7% share of network hashrate wanted to change the previous six blocks, the probability they could do so for six consecutive blocks before the honest miners produce just one block is .076, or .000012%.
The block reward is given to the miner who is the first to generate the correct output. The process is designed to be difficult to predict or manipulate. The outputs are random. The only way to produce the output faster is if a miner has more computing power than other miners on the network. That means the miner with the most powerful computers can produce more guesses, but it does not guarantee they will produce the correct output before other miners with similar computing power.
While the 10 largest publicly traded bitcoin miners by operating hashrate collectively represent 35.4% of the Bitcoin network hashrate (based on Schwab analysis of data reported in miners' Securities and Exchange Commission annual Form 10-K filings as of June 30, 2026), a common criticism is that many of the miners on the network operate in mining pools. According to HashrateIndex.com, four mining pools represented roughly 70% of observed Bitcoin network hashrate as of June 30, 2026, though that figure reflects pooled mining activity rather than direct ownership or control by a single entity. One perspective on this debate is that due to the high concentration in these mining pools, Bitcoin is highly centralized. The other perspective points to the fact that individual miners make up the mining pool and are thus economically incentivized to maintain the honest blockchain. If a miner or group of miners were trying to put forth false versions of the blockchain, the rest of the miners may have economic incentives to reject or counter that version, though outcomes would depend on market and network conditions.
Schwab's perspective is that although mining pools do concentrate compute (which is the ability of a system to perform calculations at scale), ultimately the economic incentives and competition among individual miners may help support the integrity of the blockchain. When there is true consensus, that keeps miners working together. Otherwise, they may exit the pool, or start a different pool, to maintain the correct version of the blockchain, though doing so could involve operational or economic frictions. Understanding the actual incentives for mining reinforce our view that Bitcoin is not centralized, even when accounting for mining pools.
Summary of crypto key debates
072926 Ferraioli Table 1
| Cryptocurrency | Sector | Industry | Industry Standard Network Effects | Leading Market Share | Scalability | Tokenomics | Key Debate(s) | Trading Range | Current Valuation |
|---|---|---|---|---|---|---|---|---|---|
| Bitcoin | Foundational Networks | Store of Value | ✔️ | ✔️ | ❌ | Below Average |
1) Quantum risk 2) Miner pivot to AI 3) Halving cycle persists? 4) Mining pools create centralization |
0.75x-2x Inefficient Miner Production | 0.68 Miner Production |
| Ether | Foundational Networks | Smart Contract Platform | ✔️ | ✔️ | ❌ | Average | Ethereum scalability | 40x - 70x Market Cap/"GDP" | 25x Market Cap/"GDP" |
| XRP | Foundational Networks | Store of Value | ❌ | ❌ | ✔️ | Below Average | Store of value or smart contract? | 0.1x to 0.4x Market Cap/Transfer Volume | 0.25x Market Cap/Transfer Volume |
| Sol | Foundational Networks | Smart Contract Platform | ❌ | ❌ | ✔️ | Above Average | Expand beyond meme trading? | 20x - 100x Market Cap/"GDP" | 33x Market Cap/"GDP" |
The Bitcoin blockchain is secured through a proof-of-work consensus mechanism, which ultimately results in two costs being associated with producing bitcoin: fixed costs, like mining equipment (fleets of mining rigs that run on application-specific integrated circuits, or ASICs, developed solely for bitcoin mining); and variable costs, like energy to power a data center.
The high energy costs to produce bitcoin may contribute to making it more secure. The idea behind proof-of-work is that attempting a 51% attack is prohibitively expensive, so miners are generally economically incentivized to use computing power to validate blocks rather than attempt an attack.
While a sovereign actor, like a foreign government, could theoretically have the resources to attempt a 51% attack, such an attack may be difficult to execute due to the time it would take to procure the equipment needed to control the network, the energy resources needed, and the ultimate uncertainty of whether it will be profitable.
But an attacker might attempt to gain 51% control because they could potentially receive the block rewards, transaction fees from previously mined blocks, and capture double-spend transactions, which could be quite significant relative to block rewards. Double spending is when a user spends the same cryptocurrency more than once.
Understanding the economics of a 51% attack suggests that higher production costs may contribute to greater resistance to certain attack scenarios. The economics can also explain why mining costs are a critical feature of a proof-of-work blockchain and why we use miner production costs as one of several metrics for valuing bitcoin, alongside other factors like market demand, liquidity, network activity, regulatory developments, and broader macro conditions.
How does competition increase the production cost of bitcoin and reduce the likelihood of a 51% attack?
The Bitcoin blockchain is a combination of timestamping and finality of previous settlements. Digiconomist estimates it currently requires about 3.75 gigawatt hours (GWh) of energy to mine a block. To provide some conservatism in our analysis, we assume it requires 2 to 3 GWh of energy to create a block. For each historical block an attacker is looking to alter, they must use the same energy (2 to 3 GWh) per block, at the same time every other miner on the network is working to secure the next block (and therefore creating a copy of the correct historical blockchain).
The cost of an attack is calculated with this formula:
Cost of attack = energy per block × blocks to rewrite × competitive multiplier
The competitive multiplier (additional energy and cost an attacker may need to overcome competition from honest miners) is critical because if you only have 50% share of network hashrate, progress is slow. But if you have 60% to 70% share of network hashrate, you may be able to catch up—but at an enormous cost.
To put some numbers in this example: if 3 GWh of energy is needed per block, and the attacker wants to alter the previous six blocks, that requires 18 GWh of energy—which is enough to power nearly 2,000 U.S. homes for a year.
This example illustrates why reversing confirmed blocks is difficult in practice and how an attack requires industrial-scale coordination. If the attacker controlled 60% of the network's hashrate, they could potentially outpace the network in terms of block creation, but there are significantly higher costs compared to honest mining.
The cost to maintain that attack becomes (note that attacker share refers to the attacker's share of total network hashrate, and defender share refers to the remaining share controlled by honest miners):
Energy required per block × [1 / (attacker's share of network hashrate – defender's share of network hashrate)]
Or in our example: 1 / (0.6 – 0.4) = 5
This means the attacker needs 90 GWh—five times the baseline 18 GWh. Using $40 (the average cost of wholesale electricity according to the Energy Information Administration as of June 30, 2026) per megawatt-hour, this means the attack costs $3.6 million to alter the previous six blocks. The gain if the attacker were to alter the history and capture the block rewards and transaction fees for the previous six blocks, using $75,000 as a hypothetical price for bitcoin, would be $1.5 million for the six block rewards and transaction fees. Under these assumptions, even at the high end of the estimated transaction fees, the estimated cost of the attack would exceed the estimated rewards—meaning the attacker would still lose money.
This example only reflects mining rewards and transaction fees and does not incorporate the significantly larger double-spend value that could be captured in a successful attack—which could increase the potential payoff to the $100 million to $300 million range. This makes an attack appear economically attractive on a static basis, but executing and monetizing such an attack is highly uncertain. We assume a maximum double-spend value of approximately $100 million to $300 million, representing roughly 1%-5% of a typical day of on-chain value transfer. While Bitcoin settles significantly more value in aggregate, a successful double-spend generally requires concentrating activity into a limited number of transactions that can be reversed and monetized before counterparties, exchanges, or the network respond. This assumption is illustrative and intended to approximate the practical upper bound of economically realizable value from a single attack event.
If successful in reversing the previous six blocks, the attacker doesn't need to maintain the false chain at the elevated cost because it would become the consensus chain. As a result of the attack, two scenarios might happen: (1) The network carries on with the false history; or (2) the network collapses—either voluntarily through a fork, where the chain splits into two or more separate branches, or a complete loss of confidence in the network. One scenario in which the attack may be viable is if the network carries on with the altered history, which ignores one key aspect of a decentralized blockchain network—competition among miners and economic self-interest.
All of this assumes the attacker already has the infrastructure available to support this attack. A simplistic method of calculating how much upfront capex would be required to take over 51% or more of the Bitcoin network requires some information about bitcoin mining rigs. Each mining rig has its own measure of terahashes per second (TH/s). TH/s is the unit of measurement for computational power, or the number of cryptographic hash calculations a device or network can perform in one second. One terahash equals one trillion hash attempts per second.
To estimate the number of machines needed to reach 51% of the Bitcoin network's hashrate, we first estimate the required hashrate: 940 EH/s × 51% = 479.4 EH/s. Because 1 EH/s equals 1,000,000 TH/s, this equals 479,400,000 TH/s. Assuming a mining rig capacity of 270 TH/s, the estimated machine count is 479,400,000/270, which equals approximately 1.78 million machines. Because machines must be purchased as whole units, this would round to about 1,775,556 machines. At an estimated $2,950 per machine (which is what a standard Antminer S21 200TH/s costs), upfront hardware capex would be approximately $5.24 billion, or about $5.2 billion, before considering energy infrastructure, procurement timing, deployment delays, or other operating costs.
Total upfront capex by control-share scenario
Source: Schwab as of June 30, 2026. For illustrative purposes only.
A simple analysis suggests it takes about $5.2 billion in upfront hardware capex to generate 51% of the Bitcoin network's hashrate.
This methodology is flawed because it assumes an attacker could acquire enough mining rigs at a single point in time and immediately deploy them. It also doesn't consider that a utility-grade energy source would be needed to power this operation, which if not available, would need to be built. Finally, how the Bitcoin network responds to miners coming onto the network would also limit the viability of this attack.
Why a 51% attack could get harder over time
Perhaps the most important aspect to analyze is how the network responds to the 51% attack. The key factors of the analysis include a targeted share of network hashrate, assumptions on mining equipment costs, assumptions on time to acquire the mining equipment and build required energy infrastructure, ongoing energy costs, organic network hashrate growth, and how honest miners may respond. First, it takes time to deploy the attack. In our analysis, we used (a very aggressive) two years for the complete buildout. During this period, the blockchain's hashrate would continue to grow. Network hashrate has grown 51% a year on average since November 2022 according to data from Glassnode as of June 30, 2026. So for every year that passes, the amount of network you could control based on initial capex assumptions decreases.
Beyond the moving target of network hashrate, a new miner joining the network doesn't replace existing hashrate, it may increase it, again pushing up total network hashrate. This assumes existing miners remain active. In this instance, the miner now controls even less than they initially aimed to. The potential success of a 51% attack may ultimately be limited by supply chain constraints, energy constraints, and game theory.
Studying a theoretical 51% attack may put valuing bitcoin into perspective by looking at different features of the Bitcoin blockchain
A fair value (FV) model for bitcoin can be framed as the interaction of five constraints that impact three core blockchain features—decentralization, security and scalability. This framework is illustrative and based on assumptions that may change materially over time, however it's important to examine those five constraints:
- Fixed supply (monetary constraint): inelastic issuance that drives scarcity and price formation.
- Energy barrier (physics): the cost to produce blocks and rewrite history.
- Competition (game theory): ongoing miner rivalry that enforces that cost.
- Uncertainty (probability): stochastic block production and attack success risk. Stochastic refers to a process that is inherently probabilistic, where outcomes are influenced by chance and can only be described in terms of likelihoods rather than certainty.
- Limited extractable value (security constraint): bounded potential economic upside from attacks.
Bitcoin is shaped by these five interacting constraints that jointly determine its decentralization, security, and scalability trade-offs. Fixed supply creates a hard monetary constraint that may contribute to scarcity and long-term value, while the energy barrier imposes a physical cost on block production and history rewrites, anchoring security in real-world resources.
Competition among miners acts as a game-theoretic enforcement mechanism, ensuring that this cost is continuously maintained through entry and exit dynamics, reducing the likelihood of sustained economic rents. At the same time, uncertainty in block production introduces probabilistic finality—meaning transactions become more secure over time, but never instantaneously—limiting throughput and contributing to latency. Finally, limited extractable value bounds the economic incentive for attacks, as the potential gains from double-spends, censorship, or maximum extractable value (MEV) are constrained relative to the cost of execution. Together, these constraints may support network security through decentralization, while also imposing inherent limits on scalability, reflecting a system optimized for trust minimization rather than transaction speed. Economic rents are persistent excess profits, throughput is the number of transactions a network can process over a given period, and censorship is the intentional delaying, blocking, or exclusion of transactions from the network.
A potential fair value model for bitcoin
Source: Schwab.
For illustrative purposes only. P is the current market price of bitcoin which is the maximum of the scarcity implied value or the energy barrier. Mcompetition, Muncertainty and Mattack represent factors that are converted into price multipliers. Mcompetition is a function of competition elasticity—or how fast competition responds to the profitability of mining bitcoin. Muncertainty measures the probability that an attacker can successfully override the honest chain, given relative hashrate and confirmation depth. Mattack is the limited extractable value, which determines how much can actually be stolen in a successful 51% attack.
Wrapping it all up
Our analysis suggests that, under the assumptions we used, a 51% attack could be costly and complex, making it difficult to attack the Bitcoin blockchain and potentially making it more secure. As a result, bitcoin's valuation may be supported, in part, by the high estimated cost of a 51% attack relative to any potential extractable value attackers could gain.
By comparison, networks with lower estimated attack costs or greater concentration may face different security trade-offs than Bitcoin, depending on network design, hashrate, participation, and other factors. This could lead to a lower valuation when compared to bitcoin.
In our article for August, we will take a deeper dive into the mathematics behind our analysis and compare bitcoin and Zcash, which is one such network with lower estimated attack costs and greater concentration.
Many mainstream investors place little premium on the decentralization and security aspects of a cryptocurrency, but these aspects are important to the value of a cryptocurrency. These characteristics may not be fully reflected in market prices, but weaknesses in decentralization or security could become important valuation considerations.
As always, you should keep in mind that all cryptocurrencies are relatively new and due to their novel and unproven nature, reliable methods for estimating performance may not be available. The regulatory landscape for crypto is still evolving. Cryptocurrencies may be subject to potential encryption breaking, illiquidity and increased risk of loss. Theft, scams and fraud have been a factor to deal with, and if you decide to invest in crypto directly remember that there may not be an effective way to recover assets if they're stolen or lost. Investing in cryptocurrencies involves risk, including the risk of total loss of principal invested. Cryptocurrencies such as bitcoin, Ether, XRP, Sol, and Zcash are highly volatile, are not backed or guaranteed by any central bank or government; are not deposits; are not FDIC insured; are not SIPC protected; and lack many of the regulations and consumer protections that legal-tender currencies and regulated securities have. Spot markets on which cryptocurrencies trade are relatively new and largely unregulated, and therefore, may be more exposed to fraud and security breaches than established, regulated exchanges for other financial assets or instruments. Due to the high level of risk, investors should view digital currencies as a purely speculative instrument.