SwapSS learn

The Qubic hashrate episode, and what a majority miner can actually do

In August 2025 a pool called Qubic announced it had mined more than half the Monero blocks in a sample window. A month later an 18-block reorganization removed about seventy minutes of chain history. Both events were real, and both were reported as if Monero had been cracked open. The distinction the headlines skipped is the one that matters: mining power decides the order transactions appear in, never what they say.

What happened, in order

On 11-12 August 2025 Qubic published its own claim of crossing the threshold: 63 blocks out of a 122-block window. Independent write-ups disputed that a sustained majority had been demonstrated at all, and an analysis from the RIAT Institute argued the 51 percent framing was unproven. The concrete event came a month later. On 14 September 2025 an 18-block reorganization replaced roughly seventy minutes of history. The researcher Rucknium, who published the closest analysis of it, found the pool responsible held a large but minority share and had an exceptional run of luck: 20 blocks in 66 minutes, about a 5 percent outcome for a miner holding 40 percent of the network.

  • 11-12 August 2025: a public claim of 63 blocks inside a 122-block window.
  • 14 September 2025: an 18-block reorganization replaces about seventy minutes of chain.
  • 115 transactions dropped out of the chain; roughly three quarters later reappeared spending the same outputs.

What a majority of hash power actually buys

Hash power is a vote on ordering, and that is the whole of it. With enough of it a miner can refuse to include particular transactions in its own blocks, mine in private and later publish a longer chain that displaces recent blocks, and use that displacement to take back a payment it made itself. Every item on that list is about which transactions exist and in what sequence. Nothing on it is about reading them.

What it cannot do: read, spend, or forge

Mining produces no keys. Amounts stay behind confidential transactions, destinations behind stealth addresses, and the spend behind its ring, exactly as they are for every other observer. A miner cannot move coins it does not own, cannot forge a signature, cannot alter someone else’s transaction, and cannot mint XMR outside the block reward. The oldest summary of the limit still holds: an attacker can only try to change one of his own transactions, to take back money he recently spent.

The privacy damage that did happen, and why it is a different mechanism

There was real privacy harm, and it is worth understanding precisely because it was not decryption. When the 18 blocks were undone, wallets rebuilt and rebroadcast their transactions. A rebuilt transaction spends the same real output but draws a fresh set of decoys around it. Two versions of one spend, two rings, and in the case Rucknium documented the two rings overlapped on exactly one output - which is therefore the real one, by elimination. The chain gave up the answer because the same secret was published twice in different disguises. That is a consequence of history being rewritten, not of anyone gaining the ability to look inside a transaction.

What it meant if you were holding or sending XMR

No coins were destroyed. Funds in dropped transactions went back to the sending wallet, and the recipient simply never received them, which from the outside looks like a payment that vanished. No merchant publicly reported losing money to a double-spend. The people exposed to this class of event are the ones who treat a first sighting as settlement; anyone waiting for confirmations experienced a delay and nothing else. It is also the clearest argument for the ten-block spend lock: eighteen blocks overwhelmed it that day, and it still bounds every ordinary reorganization that happens in a normal week.

Common questions

The questions this episode generates most often, answered against what was actually measured rather than what was posted.

  • Was Monero’s privacy broken? No. No key was exposed and no amount or address became readable. The measurable harm was confined to transactions that were dropped and re-sent with different decoys.
  • Could the pool steal coins? No. Mining does not produce signatures. The only payment a majority miner can reverse is one it made itself.
  • Did anyone lose funds? No public loss was reported, and coins from dropped transactions returned to the wallets that sent them.
  • Is the ten-block lock enough? It was not deep enough on 14 September 2025. A deeper lock would delay everyone’s spending every day, to defend against an event that needs both large hash power and unusual luck.
  • What should a service have done differently? Wait for confirmations instead of first sighting. That removes the entire class of problem at a cost of minutes.