My intuition is that this is a risky proposition. If an entity can benefit themselves $x by making a bad-faith transaction, but it only costs them $y such that $y < $x, it’s rational to do it even if the costs to others are orders of magnitude greater. As a concrete example, if Coinbase double-spent a transaction for $10m and had enough stake to make the network accept this, would it necessarily devalue the currency through loss of trust by enough to make this unprofitable? Is this true for all possible actions by a 51% stakeholder?
This logic is, as you say, simplistic. Anyone with such a large stake can cash out, and then use their former large stake to fabricate an alternative chain in which they did not cash out, forking the blockchain at the block just before they cashed out. Commonly proposed defenses against this (checkpointing) are limited because when new nodes enter the network, they are in a naive state where they do not know who to trust.
In a proof of work system, the entire blockchain can be validated by a naive node. Fraudulent blockchains could be constructed and fed to naive nodes, but they would be obvious forgeries because they would have to be constructed at lower network difficulties in order to generate blocks faster than the real network and become the longest chain.
In a proof of stake system, people who formerly had stake in the system can simulate fraudulent alternative histories forked at the point before they cashed out, and feed those histories to naive nodes. If enough naive nodes accept the alternative history, it becomes the accepted chain. The possibility exists that these former stakeholders might use some of their cashed out money to start up many nodes in the cloud and feed their alternative chains to those nodes.
The only real way to defend against this is to have trusted nodes coded into the protocol provide bootstrapping data to naive nodes. Once you do that, your network is no longer trustless.
Read more here: http://www.cs.cornell.edu/~iddo/CoAslides.pdf
A trade this large is likely to crater the currency before it can be filled in the absence of trade volume so large its practically impossible for one stakeholder to act in the manner you describe.
The difference between a system that is provably secure and a system that is theoretically insecure but with no known practical attack is a pretty big difference. In the former case, your proof has to be wrong before you lose, in the latter, someone just has to think of something you didn't.
They don't have to actually sell the currency; they can simply transfer it to another wallet they control, use their huge stake to manipulate the blockchain saying they now have original wallet + new wallet, effectively doubling their currency. Then, they can cash out slowly, over time, without cratering the currency.
Basically, this is like a secret money printing (double-spending) machine, although I would like to think that smart people would be able to detect the manipulation in some way or another.
1. Cashout - for example send coins to an exchange, sell them for other crypto, withdraw everything
2. Flood the network with transaction where your coin was transferred to your other wallet instead of exchange
3. There are two conflicting transactions, you want the network to select the one where coins stay in your hands. For PoW that requires 50%+ of CPU power, for PoS it requires to have significant % of all coins.
It is like brute forcing card chargeback - merchant had your money and they are gone and he can't do much about it. It makes exchanges more likely a target of double spending attack than the source. I guess higher deposit/withdraw delays&fees would make PoS attacks unprofitable.
No because atleast for Ethereum there will be a "point of no return", a number of blocks after which the blockchain history can no longer be altered except by the user manually switching chains.
Additionally, the system will encourage users to swap and share which chain they are on so that fraudulent chains can be detected easily.
The problem is this: the large entity (e.g. exchange), who just cashed out, will spend the proceeds on thousands of VMs, all sending its fraudulent chain to new peers connecting to the network. In this case it will be the “good” nodes’ word against a majority of fraudulent “exchange”-nodes.
> Additionally, the system will encourage users to swap and share which chain they are on so that fraudulent chains can be detected easily.
How is this supposed to work when the fraudulent entity has more funds than the honest nodes, with which it can purchase nodes who vote for its fraudulent history?
The answer is also for the previous part, ie, the "spend the proceeds on thousands of VMs.
The plan, AFAIK, is that users must pick a chain. The process is entirely in meatspace and subjective. So even if someone purchases a million dishonest nodes which have a wrong history, that doesn't mean shit if not enough people, real meatspace people, agree that it's the correct chain.
In case of a hostile takeover, this means starting a new chain is also super easy and can be done in a single day without any additional loss.
The above blogpost should explain this sufficiently.
>And how do you determine how many meatspace people are voting for something? This problem was confronted by Satoshi and his answer was proof of work.
This is quite simple, people can agree on a representative in a democracy, hence it must be possible people will be able to agree on a blockchain to use.
As state previously in the thread, long range forks are not a concern as any state S with atleast N ancestor states will not allow any state S' to become valid if it is not a descendant of S. Therefore it can be concluded that after N blocks, a fork becomes impossible.
The remaining problem is therefore short-range forks caused by someone burning a lot of stake. Forking will inherently burn all your stake in the other chain while you burn everyone elses stake in yours. Any such fork attack then must last for more than N blocks to become permanent.
The blogpost dives a bit deeper into the fork prevention mechanisms but the TL;DR is that nodes will prefer keeping a chain over switching to a new chain significantly, going up exponentially as the new fork becomes older. In essence, a fork must take over the network almost immediately or the new fork will wither and eventually die out in favor of the original chain. (The speed of a fork is roughly a function of the time delay between the first and last node receiving a block in percent with respect to X, the amount of permanent control an attacker has)
The later part of the blogpost also explains that the weak subjectivity only poses a problem for nodes that have been offline for more than N blocks and in case an attacker can control large portions of the network for extend amount of time. It does not matter if a node sees 100000 other nodes with another chain until N blocks have passed or in the other prevention mechanism, the gravity of the new chain becomes greater than that of the current chain, which can take a while.
As suggested in the end of the blogpost, if a node stays offline for extended amounts of time, there is no safe way of knowing the state of the network, thusly the best option is to obtain a recent blockhash from a friend, a block explorer or their software provider. Human social interactions would be the prefered option, the trust on the network being in the right stake would thusly be equivalent to the trust you place in said friend. Or your software provider or blockchain explorer.
It can be argued that any entity which is sufficiently powerful to cause disruption over the chain consensus for longer than a year (the proposed value of N) then they will also be able to overpower any other proof of work algorithm or pursue alternative methods to disrupt the network.
They could probably stake some of it though, as long as there's no bank run situation.
If there was even a hint that Coinbase was pulling any "fractional reserve" stunts, they'd lose the massive amount of credibility they have over less reputable exchanges. Reputation is the primary advantage Coinbase has.
That doesn't mean that they're perfect, or that nothing ever goes wrong; it means that they're the highest-reputation exchange available, and that their primary selling point is that reputation.
Also, people happy with something post about being happy far less often than people angry with something post about being angry, because the latter have a problem/grievance to solve.
What trust can you have in an exchange in which you cannot withdraw your money. Also I dare you to try and get a hold of support at Coinbase. Hint hint you can't.
Fingers crossed, in my case I first verified everything, and both deposited and withdrew cash in the last couple of months. It wasn't quick, but it wasn't as long as 13 business days. More like 6-8.
Only Coinbase seems to have this issue. And at least the other exchanges have working support.
Works fine here. As mentioned elsewhere in the thread, happy people don't typically post about everything working as expected.
There's plenty of people online complaining that wires in and out of Coinbase from December 12-18th have yet to process. There's even a class action lawsuit being formed about it.
My worst fear is that Coinbase is insolvent.
Surely they would have to be thoroughly pwned for that to be true? They claim that 98% of customer funds are in cold storage, and they ought to be raking it in on transaction fees and with BTC being up 1372% this year. They also raised a $100M Series D round in August. It's not impossible, but highly unlikely.
This isn't acceptable for what is essentially a bank that just raised $100M at a $1.6B valuation.
Additionally, Coinbase would be able to sell its future profits (from staking) in the futures market, and use the proceeds to honor an unexpectedly high demand for withdrawal.
But why would users want to withdraw? They’re making more money by having their funds deposited with Coinbase than if they stored it themselves.
How the network will reach consensus on then following this new chain is not clear to me.