Pools 18
Miners N/A
Workers N/A
Pool policies

Block withholding: the attack a pool cannot see in a single share

Last updated: August 15, 2026

A miner sends real shares and hides the one that would have been a block. Here is what it costs, who pays, and how it is caught.

What the attack is

Every share you send a pool is a real solution that missed the block target. Once in a while a solution comes in under the block target too, and that share is a whole block. It looks the same as every other share right up until the pool checks it.

A block withholding attack is a miner that does the work honestly, sends every ordinary share, and quietly throws away the one that would have been a block. The pool counts the shares and pays for them. The block it should have received never arrives.

Why one share never gives it away

This is what makes the attack interesting rather than merely rude. Nothing about the attacker looks wrong on any individual share. The hardware is real, the hashrate is real, the shares are valid and arrive at the right rate. The pool cannot examine one share and see anything at all.

What is missing is an absence, and an absence only becomes visible over time. A miner with a given share of the pool's hashrate should find roughly that share of its blocks. Over an hour, that says nothing, because block finding is a random process and quiet stretches are ordinary. Over a long enough window, it says a great deal.

An attacking miner sends a steady stream of ordinary shares to a pool, while the one solution that meets the block target is stopped before it reaches the pool and discarded
The shares flow normally. The one submission that mattered is dropped, and nothing about a single share reveals it.

What it costs, and who actually pays

The pool loses the block reward it should have had. But the pool is not really where the loss lands, and this is the part worth understanding if you mine on any pool.

Under a proportional scheme, the round simply carries on until somebody else finds a block. Everyone in the round contributed work to a round that took longer than it should have, so everyone earns slightly less per unit of work. The cost is spread across the honest miners.

Under a pay per share scheme it is worse for the operator, because the pool has already paid for every share out of its own pocket and is relying on the blocks to arrive. A sustained attack against a pay per share pool is a direct drain on the operator, and historically that is the case people worried about most.

Why anyone would do this

The attacker throws away the block reward too, so at first glance it is pure self harm. It only makes sense if the attacker gains somewhere the pool cannot see.

The usual motive is competitive. An operator running their own pool can rent or point hashrate at a rival, suppress its results, and make their own pool look luckier by comparison. The attacker pays for the sabotage out of the shares it still collects.

There is a subtler variant where the attacker holds the block rather than discarding it, keeps mining on top of it privately, and submits later at a moment that suits them. It is harder to pull off and needs a large share of the hashrate to be worth trying.

How it is actually detected

Detection is statistical, and it has to be, because there is no other signal available. The measurement is simple to state: compare the blocks a given contributor has found against the blocks its share count says it should have found, over a window long enough for luck to average out.

The window is the hard part. Make it short and ordinary bad luck looks like an attack, which would mean accusing honest miners constantly. Make it long and a real attacker operates for a while before the numbers speak. There is no clever way around this trade off; it is a property of the randomness, not of the software.

This is why a serious detector raises the question for a human rather than acting on its own. An automatic ban driven by a statistic will eventually ban somebody who was merely unlucky, and taking a legitimate miner offline is a worse outcome than the attack itself.

What it means if you are an honest miner

Almost nothing, and that is the point of saying it plainly.

Your shares are counted and paid the same either way. Being unlucky is not an offence and cannot be, because over any short window most miners are unlucky. A run of rounds where you contributed a lot and the pool found nothing is normal variance, and the luck figure on the pool statistics exists precisely so you can see how normal it is.

The one thing worth knowing is that this is a reason pools care about who is pointing hashrate at them, and a reason a pool that publishes its blocks and its luck honestly is easier to trust than one that does not. Everything needed to check the pool is on the blocks page.

Ready to put this into practice?
Pick a coin on the pools overview and open its How to Mine guide for a ready-to-run command.
Choose a pool