Inscription in limbo: BRC20 pinning attack
File(s) ndss27-summer-paper47.pdf (4.18 MB)
Accepted version
Author(s)
Type
Conference Paper
Abstract
BRC20 is an inscription-based fungible token standard on the Bitcoin network. It allows users to encode token operations within Bitcoin satoshis via Ordinal inscriptions. The token frenzy reached billion-dollar-scale market size during the 2023–2024 Ordinals boom and remained active into 2026. Yet, this intuitive design has not undergone security scrutiny.
We present the first analysis of BRC20’s transfer mechanism and identify a new attack vector. A typical BRC20 transfer involves two “bundled” on-chain transactions with different fee levels: the first (i.e., Tx1) with a lower fee inscribes the transfer request, while the second (i.e., Tx2) with a higher fee finalizes the actual transfer. An adversary can send a manipulated fee
transaction (falling between the two fee levels), which makes Tx1 processed while Tx2 pinned in the mempool. This locks the BRC20 liquidity and disrupts normal withdraw requests from users. We term this the BRC20 pinning attack.
We validated the attack in real-world settings in collaboration with Binance researchers. With their knowledge and permission, we conducted a controlled test against Binance’s ORDI hot wallet, resulting in a temporary suspension of ORDI withdrawals for 3.5 hours. An attack outlay below $150 immobilized over $9M of ORDI liquidity and blocked an estimated $26M of settlement flow during the outage window. Recovery was promptly performed. Further analysis confirms that the attack can be applied to over 90% of inscription-based tokens within the Bitcoin ecosystem.
We present the first analysis of BRC20’s transfer mechanism and identify a new attack vector. A typical BRC20 transfer involves two “bundled” on-chain transactions with different fee levels: the first (i.e., Tx1) with a lower fee inscribes the transfer request, while the second (i.e., Tx2) with a higher fee finalizes the actual transfer. An adversary can send a manipulated fee
transaction (falling between the two fee levels), which makes Tx1 processed while Tx2 pinned in the mempool. This locks the BRC20 liquidity and disrupts normal withdraw requests from users. We term this the BRC20 pinning attack.
We validated the attack in real-world settings in collaboration with Binance researchers. With their knowledge and permission, we conducted a controlled test against Binance’s ORDI hot wallet, resulting in a temporary suspension of ORDI withdrawals for 3.5 hours. An attack outlay below $150 immobilized over $9M of ORDI liquidity and blocked an estimated $26M of settlement flow during the outage window. Recovery was promptly performed. Further analysis confirms that the attack can be applied to over 90% of inscription-based tokens within the Bitcoin ecosystem.
Date Acceptance
2026-08-31
Citation
Proc. Network and Distributed System Security Symposium 2027 (NDSS 2027)
Publisher
Internet Society
Journal / Book Title
Proc. Network and Distributed System Security Symposium 2027 (NDSS 2027)
Copyright Statement
This paper is embargoed until publication.
Source
Network and Distributed System Security Symposium 2027 (NDSS 2027)
Publication Status
Accepted
Start Date
2026-03-22
Finish Date
2026-03-26
Coverage Spatial
Seoul, Republic of Korea
