What would a 51% attack on Litecoin actually cost? The math
Analysis

What would a 51% attack on Litecoin actually cost? The math

TL;DR

A number-by-number look at what it would take to buy or rent enough Scrypt hashrate to rewrite Litecoin's chain. The short version: hundreds of millions up front, hardware you can't actually buy, and a payoff that doesn't come close.

People ask this question the way they ask what it would cost to buy the Moon. It sounds like a fun thought experiment until you start writing down the numbers, and then it turns into a logistics problem that no amount of money quite solves. So let's write down the numbers.

A 51% attack means one party controls more than half the network's mining power. With that majority you can rewrite recent history: mine a secret chain, then release it to overwrite the public one. That's the whole trick. Everything below is about what it costs to get that majority on Litecoin, and why the answer is uglier than the hardware price alone suggests.

All figures here are August 2026. Hashrate wanders, ASIC prices move, and coin prices do whatever they feel like. I'll flag the soft numbers as estimates. The conclusion doesn't hinge on any single one.

The one-line answer

To out-hash Litecoin today you'd need to spend somewhere in the region of three-quarters of a billion dollars on machines you cannot actually buy in that quantity, burn roughly a million dollars a day in electricity, and at the end of it double-spend an amount that exchanges will happily cap in the low tens of millions. The economics are upside down. They've been upside down for fifteen years, which is roughly how long Litecoin has gone without a successful 51% attack.

Now the arithmetic.

What 51% actually buys you (and what it doesn't)

This matters because most people wildly overestimate the prize. Controlling the majority of hashrate lets you do exactly three things:

  • Double-spend your own coins. Send LTC to an exchange, trade or withdraw, then reorg the chain so your original deposit never happened. You get the withdrawal and your coins back.
  • Reorg recent blocks. Orphan blocks other miners found, censor transactions, deny confirmations for a while.
  • Grief the network. Make it unreliable, tank confidence, dump the price if you're short.

That's it. Here's what a 51% attacker categorically cannot do. You can't steal coins from wallets you don't control — you have no one's private keys. You can't conjure LTC out of thin air or change the 84 million coin cap; nodes reject blocks that break the issuance rules, majority or no majority. Reversing old transactions gets harder with every block of depth, since you'd have to redo all the work above them; a majority held long enough could in principle rebuild weeks of history, but the cost and visibility grow the whole time, so deep history is frozen in practice rather than by rule. And you can't force anyone to accept an invalid block. The rules are enforced by every full node, not by the miners.

So the ceiling on the prize is set by how much you can double-spend before anyone notices. And exchanges get a vote on that.

The standard defense is confirmation counts. An exchange that credits an LTC deposit after 6 confirmations is betting you can't secretly out-mine 6 blocks. Raise it to 60 and the bet gets far safer. After the merge-mining-era attacks on smaller chains, exchanges got twitchy and cranked confirmation requirements on anything with thin security. A double-spend that needs a 30-block reorg to land is a very different engineering problem than one needing 3.

Cost component one: buying the hardware

Litecoin is secured by Scrypt ASICs. As of August 2026 the network hashrate sits around 2.9 PH/s — CoinWarz clocked it near 2.86 PH/s, other trackers put it a touch higher into the 3.1 PH/s range. Call it 2.9 PH/s and hold the exact figure loosely; it's an estimate that drifts daily.

To hold a majority you don't need to match the network. You need to beat it. If honest miners keep producing H, your share is your hashrate divided by (H plus yours), and to clear 50% you need slightly more than the entire current network. In round terms: you must add another ~2.9 PH/s of your own.

The current flagship air-cooled machine is the Bitmain Antminer L9 at 17 GH/s, listed around $4,490. Do the division:

2,900,000 GH/s needed / 17 GH/s per unit = ~170,600 machines

170,600 units x $4,490 = ~$766 million

So the hardware bill lands near $770 million, give or take. Swap in ElphaPex's DG2+ at 20.5 GH/s and you'd need about 141,000 units instead — fewer boxes, similar order of magnitude on spend once you price them. Either way you're north of half a billion dollars just for silicon. That's the optimistic line item, because it assumes the machines exist to be bought.

The supply problem nobody wants to talk about

They don't. You cannot walk up to Bitmain and order 170,000 L9s. The entire annual production run of Scrypt ASICs across every manufacturer is a fraction of that, and it's spoken for by farms that pre-order batches months out — the ElphaPex units ship in scheduled batches, not from a warehouse. Try to buy the world's Scrypt hashrate and two things happen. Lead times stretch into years, and the price of every unit climbs as you eat the supply. You'd be the entire market.

By the time your machines arrived — assuming a manufacturer would even take the order, and assuming they didn't quietly tip off the Litecoin community that someone was buying an attack's worth of gear — the network would have grown, difficulty would have adjusted, and your 2.9 PH/s would no longer be a majority. It's a treadmill. You're buying hashrate to beat a target that moves up partly because you're buying hashrate.

This is the part that turns a $770 million spreadsheet into a fantasy. The money is almost the easy bit. The hardware simply isn't sitting on a shelf.

Cost component two: power and hosting

Say you cleared the impossible and got the machines. Now you have to run them. Each L9 pulls about 3,570 watts. Multiply out:

170,600 units x 3,570 W = ~609 MW

That's the draw of a mid-sized power station, dedicated to your attack. At an industrial $0.07/kWh:

609,000 kW x 24 h = 14.6 million kWh/day

14.6M kWh x $0.07 = ~$1.02 million/day in electricity

Run it for a month while you set up and execute, and that's roughly $31 million in power on top of the hardware. Plus hosting: 609 MW of load needs substations, cooling, and a building the size of a distribution warehouse. That infrastructure doesn't exist idle and unclaimed. You'd be building or commandeering one of the largest mining facilities on Earth, which is not a discreet activity.

Rentable Scrypt hashrate versus Litecoin network hashrateLTC network~2.9 PH/sNiceHash rentable~0.22 PH/s (about 7% of the network)Rentable Scrypt capacity is a rounding error against Litecoin's total. Bars to scale.

The rental route: why it's dead for Litecoin

Here's where attackers on smaller chains found their opening, so it's worth being precise about the history. You don't have to own hashrate. You can rent it on marketplaces like NiceHash, where miners sell their capacity by the hour to whoever pays most. No hardware, no power bill, no lead time. That's how the cheap attacks happened.

Bitcoin Gold got hit in May 2018 — an attacker double-spent around $18 million across exchanges — and again in January 2020, with two deep reorgs over ten blocks each. Ethereum Classic took three separate 51% attacks in August 2020 alone; the first double-spent roughly $5.6 million, the second about $1.7 million, and the third reorged over 7,000 blocks. Several of those runs were powered by rented hashpower, ETC's most notably from NiceHash-style marketplaces.

Why those chains and not Litecoin? Because the rentable pool has to be large relative to the target. BTG and ETC each had a market where you could rent a majority of the network's hashrate for a few hours for tens of thousands of dollars. The attack cost less than the payday. Simple.

Now look at the Scrypt rental market. NiceHash's total available Scrypt capacity runs around 215 TH/s — that's 0.215 PH/s. Against Litecoin's ~2.9 PH/s, the entire rentable Scrypt supply on the largest marketplace is about 7% of the network. You could rent every last hash on offer and not come close to 20%, let alone 51%. There is no rental route to a Litecoin majority. The pool is a puddle.

And that puddle exists partly because Litecoin is big. Miners rent out spare capacity; there isn't a spare Litecoin-network's-worth of Scrypt gear lying around uncommitted. The rental attack is a small-chain disease. Litecoin outgrew it years ago.

FactorBitcoin Gold (2018/2020)Ethereum Classic (Aug 2020)Litecoin (2026)
Rentable hashrate vs networkMajority rentableMajority rentable~7% at most
Attack method usedRented + ownedRented hashpowerNo viable route
Approx. double-spend take~$18M (2018)~$5.6M + $1.7MCapped low by exchanges
Merge-mining defenseNoneNoneYes (DOGE + LTC)
Successful 51% attacksMultipleThree in one monthZero in ~15 years

The merge-mining complication most analyses skip

This one changes the math and almost nobody includes it. Since 2014, Litecoin and Dogecoin have been merge-mined via AuxPoW. A Scrypt miner does one unit of work and gets paid in both coins at once — the same hashes secure both chains simultaneously. It's not a split. You mine LTC and DOGE from the identical effort.

Two consequences follow, and both raise the effective attack cost.

First, the honest miners you're trying to out-hash are being paid twice. Their revenue is LTC block rewards plus DOGE block rewards, and DOGE has a permanent tail emission of 10,000 coins per block forever. At roughly $0.07–0.09 per DOGE (an estimate, it moves), that's real money stacked on top of the LTC reward. More miner revenue means more hashrate stays online, which means the wall you're climbing is taller and the difficulty is higher than LTC's price alone would justify.

Second, the attacker's own payout is shakier than it looks. Coinbase rewards need 100 blocks to mature before they can be spent, a successful attack tends to crater the very prices the attacker would be paid in, and a failed one orphans every secretly mined block outright. If the attack chain wins, its rewards do eventually mature — so this doesn't double the attacker's costs — but it stacks delay and price risk on top of the hardware burn while honest miners keep collecting both coins uninterrupted. Analyses that model Litecoin as a single-coin Scrypt network still understate the defender's staying power. Merge mining is a security subsidy, and it's larger than it looks.

The cost stack against the prize

Put it together. Even ignoring the fact that you can't buy the hardware, the up-front spend is roughly $770 million on machines and tens of millions in monthly power, against a double-spend prize that exchanges will choke down to the low tens of millions if you're quick and lucky. The two sides of the trade aren't in the same universe.

Attack cost stack versus plausible double-spend proceeds~$770MHardware~$31MPower (1 month)~$20MDouble-spend takeBars to scale. The prize is a sliver of the spend — and this ignores that the hardware isn't buyable.

The hardware bar dwarfs everything. That's the honest shape of it. You spend three-quarters of a billion to maybe extract twenty million, and then you're holding 170,000 depreciating ASICs, a wrecked LTC price you helped crash, and the attention of every exchange and law-enforcement body that cares. Rational profit motive isn't in this picture anywhere.

The caveat: state-level actors don't do spreadsheets

Everything above assumes the attacker wants to make money. That's the flaw in the reasoning, and it's worth saying plainly. A nation-state that wanted to discredit or destabilize Litecoin for political reasons runs a different calculation. $770 million is a rounding error in a defense budget. The prize isn't the double-spend — it's the damage.

Even then, the hardware supply problem bites. A state actor still can't summon 170,000 Scrypt ASICs that don't exist, still needs 600 MW of power somewhere, and still leaves an enormous physical and financial footprint that's hard to hide. It's not impossible for an adversary who treats cost as no object. It's just extraordinarily hard, extraordinarily loud, and — given merge mining and Litecoin's sheer size — far more work than attacking almost any other proof-of-work chain. If your threat model includes hostile governments, Litecoin is a bad target, not a safe one. Just a bad one.

The bug that wasn't an attack: April 2026

One thing to clear up, because it gets conflated constantly. In April 2026 Litecoin experienced a 13-block chain reorganization. This was not a 51% attack. It was a software bug.

The root cause sat in the Mimblewimble Extension Block (MWEB) validation code. An earlier March incident let an attacker fabricate an 85,034 LTC peg-out by feeding the peg-out process mismatched MWEB input data; those funds were later returned for a bounty. The April event was a follow-on: upgraded nodes correctly rejected the malformed MWEB block, but a flaw in how they handled it caused certain mining RPC calls to hang. Upgraded miners stalled. Un-upgraded miners kept extending an invalid chain, which grew to 13 blocks before upgraded miners coordinated and reorged it out. In the churn, a cross-chain intent platform reportedly lost around 11,000 LTC. Litecoin Core v0.21.5.4 patched both the inflation bug and the mining stall.

Notice what did the damage. Not hashrate. A validation bug and a node-handling flaw. Nobody out-mined the network; the network temporarily disagreed with itself because of buggy code, and then the valid chain won. A 51% attack is an economic and physical assault on the network's mining power. The MWEB reorg was an engineering failure in an optional privacy feature. Different problem, different fix, different threat entirely. Conflating the two is how you end up with headlines that scare people about the wrong thing.

The distinction cuts both ways, honestly. Litecoin's proof-of-work base layer has never been 51%-attacked in about fifteen years. But the MWEB episode is a reminder that hashrate isn't the only attack surface. Code is. The chain that's economically impossible to out-mine can still get hurt by a bad merge into an extension block. Security is the whole stack, not just the hashrate number.

Frequently asked questions

Has Litecoin ever been 51% attacked?

No. In roughly fifteen years of operation, Litecoin's proof-of-work layer has never suffered a successful majority-hashrate attack. The April 2026 13-block reorg was caused by an MWEB validation bug and a mining-node stall, not by anyone controlling the hashrate. It's a real incident and worth understanding, but it belongs in a different category from a 51% attack.

Why can't someone just rent the hashpower like they did with Ethereum Classic?

Because the rentable Scrypt market is tiny relative to Litecoin. The largest marketplace offers roughly 0.22 PH/s of Scrypt capacity against Litecoin's ~2.9 PH/s network — about 7%. The ETC and Bitcoin Gold attacks worked because a majority of those networks' hashrate was rentable for a few hours at low cost. That option simply doesn't exist at Litecoin's scale.

How does merge mining with Dogecoin make Litecoin harder to attack?

Scrypt miners earn LTC and DOGE from the same work via AuxPoW. That extra DOGE revenue keeps more hashrate online defending the chain, raising the wall an attacker must climb. And while honest miners keep collecting both coins uninterrupted, an attacker's secretly mined rewards sit unspendable until coinbase maturity and are exposed to the price crash the attack itself would cause — a drag most attack-cost estimates leave out.

Could a government or state actor pull it off?

Possibly, if it treated cost as irrelevant and wanted to damage rather than profit. The roughly $770 million hardware bill is trivial for a state budget. But money isn't the binding constraint — Scrypt ASICs in the required quantity don't exist to be bought, and running them needs around 600 MW of power and a facility you can't hide. It's not flatly impossible for a determined adversary, just enormously hard and impossible to do quietly.

If someone did get 51%, could they steal my coins?

No. A 51% attacker can double-spend their own coins and reorg recent blocks, but they can't touch coins in wallets they don't hold the keys to, can't create new coins beyond the protocol's rules, and rewriting deep history would mean sustaining majority hashrate for weeks in full public view — possible on paper, unworkable in practice. Your holdings are protected by your private keys and by every full node enforcing the consensus rules — none of which a hashrate majority overrides. The realistic victims are exchanges accepting deposits with too few confirmations, which is why they raise confirmation counts when security looks thin.

Jarosław Wasiński
Jarosław Wasiński
Editor-in-chief · Crypto, forex & macro market analyst

Independent analyst and practitioner with over 20 years of experience in the financial sector. Actively involved in forex and cryptocurrency markets since 2007, with a focus on fundamental analysis, OTC market structure, and disciplined capital risk management. Creator of MyBank.pl (est. 2004) and Litecoin.watch — platforms delivering reliable, data-driven financial content. Author of hundreds of in-depth market commentaries, structural analyses, and educational materials for crypto and forex traders.

20+ years in financial marketsActive forex & crypto trader since 2007Founder of MyBank.pl (2004) & Litecoin.watch (2014)Specialist in fundamental analysis & risk management

Track Litecoin in real time

Live rates for 30+ currencies, updated every second

Open dashboard