Will Ethereum miners become 'time bandits' and reorganize the blockchain?
Quick Take
- Ethereum miners have been reordering transactions within blocks to extract value for themselves.
- But now, there’s discussion around how they could start reordering blocks, too.
- Here’s how this would work and what impact it might have.
Ethereum miners are waking up to their power to effectively travel back in time to change the course of blockchain history — and the money that can be made if they use that power.
Now, many in the community are worried that the growing possibility of so-called “reorg” attacks threatens the network’s long-term stability.
In short, it’s possible for a miner who sees a lucrative transaction in a new block to go back in the chain to the point before the transaction occurred and create a new sequence — one that replaces the original transaction with one in which the miner takes the profits for themselves. It’s also called a “time bandit attack” because it’s like blockchain time travel.
This sort of opportunism isn't new. It’s already become common for miners, typically on behalf of a third party, to order transactions in a way that works to their advantage. Miners and mining-associated businesses have so far boosted their own revenues by $761 million doing this.
This practice is called miner extractable value (MEV) because miners use it to extract value from blocks. While MEV is controversial, so far it has been somewhat accepted by the community — or at the very least, tolerated.
But recently a new idea has been proposed, one that imagines miners going even further to extract this value. With this strategy, miners would be not just ordering transactions inside of blocks but reordering the sequence of blocks — a so-called “reorg” attack.
The new proposal has sparked outrage within the Ethereum community. Many see the idea as one that could undermine Ethereum’s fundamental value proposition: a permanent record of transactions that users can trust will not be manipulated.
What is miner extractable value or MEV?
You’ve probably been told that blockchains work in a relatively straightforward way. Users broadcast transactions to the network and then miners collate some of these transactions and include them in a block, which gets added to the chain. For their efforts, miners are rewarded with block rewards and transaction fees.
In reality it’s not so straightforward. Even ignoring the myriad of technical things going on under the hood, functioning blockchain systems depend heavily on incentives. They work by assuming participants are looking after their own interests, hence why miners are paid for producing legitimate blocks.
But blockchain networks are also complex systems, and it is hard to anticipate all the ways that people might exploit them.
The concept of MEV, which was first highlighted in a 2019 academic paper entitled Flash Boys 2.0, refers to certain kinds of profit-generating opportunities that are possible because miners are the ones who choose the order of transactions in a block. This opens the door for them to frontrun transactions by copying them and putting their own versions earlier in the sequence, effectively jumping the line to snatch cash that would have gone to someone else in the original timeline.
Imagine, for example, that someone has identified a bug in a smart contract and figured out how to execute a transaction that exploits it for millions of dollars worth of cryptocurrency. A miner who can see that unconfirmed transaction — when it's initially broadcast to the network — might copy all the actions and make sure their transaction is first. That’s an easy $10 million!
It’s worth noting that it’s not always miners who are instigating MEV events. Any Ethereum user can communicate with a miner to replace the original transaction with their own. The way this typically works is through a communication protocol known as Flashbots. This is a way for Ethereum users to tell miners which transactions they would like to have priority in a block, giving the miner a fee for doing so.
Whoever is behind it, miners have been extracting value from blocks at an increasing rate. According to block explorer Etherscan, the number of blocks containing bundles — the term for a specific group of transactions ordered in a way to extract MEV — increased to 13,652 in April, up from just 328 in early February.
Now, what’s all this about reorgs?
Thus far the discussion of MEV has been limited to the scenario in which the miner is mining a block and is able to identify a profitable transaction and recreate it to their benefit quickly enough.
Now the Ethereum community is wrestling with a new and more complicated approach to MEV: reorganizing the most recent blocks in the blockchain to the miner’s advantage.
In fact, the reorg-for-MEV concept isn’t new. One developer even coded such a protocol two years ago before deciding it was unethical to release it. But until recently, the community has deemed it unlikely to occur since it’s so antithetical to the core tenets of blockchain technology. If blockchains lose their reputation for immutability, they will struggle to stay valuable.
Yet on July 9, a developer named Edgar Arout forked Flashbots with the intention to make it suitable for supporting reorgs. He then started work coding it. On July 10, another developer created a similar mechanism for letting users pay miners to reorganize the blockchain.
So, although miners haven’t necessarily started using the protocols — and may not wish to — the technology now exists for them to do so.
How would this work?
Imagine a miner sees an extremely profitable transaction (say a DeFi exploit) in the latest block, which was created by another miner. The miner would copy this transaction for themselves, put it in a replacement block at the same block height, and then try to mine a new block or two before other miners do.
If they are successful at mining the new blocks quickly enough, their version of the chain will become the longest version and would thus be accepted by the rest of the network as the true blockchain. This means the original transaction would cease to exist, and would be replaced by the newer block with the transaction benefitting the miner (and its counterparties) instead.
It’s not a sure thing though. Unless the miner has more than 51% of the Ethereum hash rate — which is very unlikely and dangerous for the network if it were achieved — it comes down to how much money is available for the taking and the probability that the miner can achieve the intended reorg.
If the miner has a decent amount of the hash rate, then there might be a 10% chance, say, that this might work. But if the amount that could be gained is more than 10 times greater than the current block reward, then the risk might be worth taking.
Another option is that a miner could temporarily rent hashing power in order to increase their chances. This way, the miner boosts their chances of success without having to invest in equipment for the long term. Companies like Nicehash offer a marketplace where you can purchase hash power from other miners.
What impact would this have on the network?
If miners started regularly using reorgs to extract MEV, it would likely be disruptive to the way that the blockchain grows.
Exactly how disruptive would depend on how far back the reorgs go. If the reorgs went back quite a few blocks — more than seven for example — then it would have a big impact on people using the network, since it would provide much greater uncertainty over whether a transaction has happened and will not be reversed.
It’s likely, however, that reorgs will be much shorter, likely only one block or two. This is because the further back you go, the less likely you are to mine enough blocks in time to overtake the growing blockchain. Bear in mind that this is one miner trying to fight the rest of the network, so they’re at a disadvantage anyway — unless they did somehow amass more than 50% of the network’s hash rate.
If reorgs involve only going one or two blocks back in time, then this is likely to have much less impact on most users of the Ethereum blockchain. This is because the growing end of the blockchain is constantly in flux, and small reorgs are happening on a constant basis anyway. Blockchain transactions aren’t typically deemed to be confirmed until they have been included in a number of blocks (seven is often the magic number).
It may, however, have an impact on some users or blockchain services. For example, there are arbitrage bots that sniff out when a decentralized finance loan has become undercollateralized and seek to liquidate it, making a strong profit margin. These bots rely on speed. If miners started using reorgs to front run these transactions, it could make the bots less effective because the highly profitable transactions they create could be stolen by miners — and the bots would still have to stump up the expensive transaction fees.
It’s also possible that miners may choose not to use reorgs in this way. They’re invested in the health of the network and tend to hold stacks of ether, whose price could be negatively affected if the network becomes less reliable to use in general.
Is this a good or bad development?
Ethereum advocates are split on whether reorg attacks for the purpose of collecting MEV are good or bad.
“Builders should not publish code whose primary use is harming the public. It really is that simple,” said DeFi Pulse founder Scott Lewis.
But Flashbots co-founder Philip Daian, who co-authored the Flash Boys paper, argues that MEV is not necessarily a bad thing.
In fact, Flashbots is a messaging protocol that is designed to enable miners to capitalize on MEV. The idea is to encourage this activity to be out in the open rather than let miners become secretive gatekeepers. The argument is that if the incentives exist, someone is going to take advantage of them, so it’s better to acknowledge MEV and provide equal access.
Daian says that protocols and decentralized apps (dApps) should be built with MEV in mind, and should be designed to protect their users against any associated risks. Rather than deny that the incentives to extract value exist, communities around blockchain networks should encourage the ecosystem to become more resilient by accounting for these incentives, he says.
“One of the things that Flashbots is pretty strongly founded around is the idea that cryptocurrencies have to be pretty resilient to adversaries and have to be hardened to work in almost all environments,” Daian says.
“So, we can’t just leave massive incentive flaws on the table and say we’re just going to choose not to exploit these socially because if that’s what we do and we’re all sharing this delusion,” he says. “An attacker may not actually share that delusion.”
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.