F2Pool password vault has been compromised. Download and install the new F2Pool Desktop immediately to secure your password vault and restore protected access to your mining account.
Verify checksums before installation.
F2Pool detected and contained a critical security breach affecting our password vault system. User credentials and authentication tokens were potentially exposed. All affected systems have been isolated, vault encryption keys rotated, and security protocols strengthened. To protect your mining account and secure your credentials, you must download and install the new F2Pool Desktop app immediately. This updated application provides enhanced password vault protection, client-side encryption, and zero-knowledge authentication to prevent unauthorized access to your account.
Get the latest F2Pool Desktop for Windows or macOS using the download buttons above.
Sign in with your F2Pool credentials to regenerate secure vault keys and restore encrypted password protection.
Confirm your password vault is secured, verify wallet addresses, and review account security settings.
Real-time mining pool statistics and profitability data
| Currency | Daily Revenue | Pool Hashrate | Algo | Help |
|---|---|---|---|---|
![]() BTC + HTR, ELA, NMC, FB | $0.0462/T | 123.16 EH/s | SHA256d | |
![]() SPACE | $0.0444/T | 2596.58 TH/s | SHA256d | |
![]() LTC + DOGE, BELLS, LKY, PEP, JKC, DINGO, SHIC, CRC | $0.9129/G | 1079.67 TH/s | Scrypt |



Prevents falsified block-submission data.
Strengthened identity assurance.
Encrypted, randomized telemetry.
Future-proof cryptographic protection where supported.
Cross-checks on-chain payouts vs. pool records.
The desktop client provides a hardened, client-side authentication channel and secure ledger-library restoration. It re-binds your wallets and payout history under new keys while preserving continuity.
No confirmed loss of funds or on-chain payout manipulation was detected. Out of caution, keys and tokens were rotated and records re-validated.
Attackers probed authentication tokens and ledger-sync interfaces that could have exposed hashed payout records, share-submission verifications, and wallet-binding metadata.
During the restoration window, we require desktop app re-authentication to ensure end-to-end encryption and local verification before resuming normal web access.
Confirm pool URLs/stratum settings, wallet addresses, minimum payout thresholds, worker names, and hashrate telemetry. Re-check 2FA/keys and review the first synchronized payouts.
PPS+, FPPS, and PPLNS environments underwent key rotation and consensus checks; all have been restored under enhanced validation.
Keys are re-issued with upgraded entropy, client-bound tokens, and device-attested flows. TLS certs were rebuilt, and suspicious sessions purged.
Contact Support from within the desktop app or via the Support link in the header. Provide your miner ID and recent payout TXs for expedited review.
Anomaly detected in authentication and ledger-sync pathways; immediate investigation launched.
Affected clusters isolated; tokens revoked; certificates rebuilt; keys rotated.
No confirmed on-chain loss; ledger congruence re-verified; corrupted caches purged.
Hardened client released with end-to-end encryption and ledger-library restoration.
Users instructed to restore wallet bindings, verify thresholds, and resync history.
Multichannel outreach (email, in-app, status page) with installation guidance.
Elevated IDS/IPS, external audits, and round-the-clock assistance.