Market snapshot · Bitcoin price$77,735Network hashrate936 EH/sDifficulty127.45 T

Pools & payouts

PDoS research models a profitable liveness attack on PoW pools

Source report: 2026-09-11 · Editorial analysis published: 2026-09-14

A new preprint combines block-header deterrence with revenue extraction from a victim pool. It is a research result, not evidence of a live attack.

Archival cryptocurrency mining equipment; not a pool or experiment named in the PDoS paper
Illustrative archive photograph; not the specific product or facility described in the news. Converted to WebP; resized where needed. Marco Krohn · CC BY-SA 4.0

Analysis and practical implications

This section is our analysis and illustrative calculations, separate from the source report.

A new preprint, not a reported incident

Researchers Junjie Hu, Tianzhu Han and Na Ruan submitted a 34-page, ten-figure paper to arXiv on September 11 under the title “PDoS: A Profitable Denial-of-Service Attack against Proof-of-Work Blockchain Liveness.” The work presents an economic attack model for proof-of-work systems. It does not report that Bitcoin, a named mining pool or a particular ASIC was attacked in production. ArXiv makes the manuscript directly available, but the page does not state that it has completed peer review. The correct news event is publication of a research preprint and its claimed result, not discovery of an ongoing network outage.

How the proposed hybrid works

The authors describe PDoS as combining a block-header signal that deters rational miners with parasitic revenue extraction inside a victim pool. Earlier incentive-based denial-of-service models could discourage participation but forced the attacker to keep absorbing losses. In the new construction, the attacker also exploits the pool’s share-reward mechanism to subsidize the disruptive activity. The model therefore links protocol-level liveness with pool-level accounting. This explanation is deliberately high level: it communicates the security finding without presenting an operational recipe for attacking a real pool.

The economic threshold is the central claim

In the paper’s model, revenue taken through the victim pool lowers the adversarial hash-power threshold required to make economically rational miners shut down. The authors say the combination can move the attack toward self-sustaining and even profitable conditions. “Profitable” is conditional on the parameters and assumptions evaluated in the study; it is not a universal statement that any miner can profitably stop any PoW chain. Hash distribution, payout design, fees, detection, coordination and participants’ response can all change the outcome. Readers should examine the equations and threat model before transferring a result to a live network.

Why fees and MEV create a counterintuitive result

The preprint argues that in environments with high transaction fees or high maximal extractable value, a larger block value can increase the attacker’s parasitic revenue. Under the modeled conditions, that extra revenue may push the operation across its break-even point. This is counterintuitive because a more valuable block usually appears to strengthen honest mining incentives. The paper’s claim is narrower: if the attack can capture part of the reward mechanism while deterring others, the same value can improve the attacker’s economics. It does not show that higher fees always reduce Bitcoin security or that a threshold has already been crossed.

What pool operators can review now

Editorially, pool operators can use the paper as a reason to map how submitted shares are paid, how unusual block-header signals are handled and how withholding or infiltration patterns are detected. Useful controls include clear incident escalation, independent node visibility, payout-accounting review and tests of how miners behave when expected value changes abruptly. These are general defensive review areas, not a claim that the paper proves one product or payout scheme is vulnerable. Any mitigation should be tested against false positives and normal variance so that monitoring does not itself interrupt legitimate mining.

Limits before operational conclusions

The next step is scrutiny of the full model, assumptions, simulations and proposed countermeasures by protocol researchers and pool engineers. Independent reproduction would clarify which parameter ranges are realistic and whether alternative payout rules change the result. Evidence of an observed attack would require logs, block and share data, timelines and attribution beyond this manuscript. ASIC operators should not change firmware, credentials or pool endpoints solely because a preprint exists. A research result can improve preparedness while remaining unconfirmed as a practical event at the scale of a major network.

Evidence boundary and source

The primary source is arXiv record 2609.12450 and the linked manuscript submitted on September 11. The abstract supports the description of the hybrid mechanism, lower hash-power threshold and possible self-sustaining economics in high-fee or high-MEV settings. ASIC.Tools has not independently reproduced the mathematics and does not claim a disclosed vulnerability in a specific miner, pool or cryptocurrency. Our operational checklist is editorial context. This article distinguishes chain liveness from ordinary hashrate fluctuation and keeps the authors’ theoretical claim separate from evidence of exploitation.

Source: Hu, Han and Ruan / arXiv ↗

Mining calculator ↗

More in this section