Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions
ccn.com
ccn.com
I ended up not investing, because of the possibility of a double-spend attack. I think that cryptocurrency enthusiasts are seriously underestimating the importance of double-spending attacks to the economics of bitcoin and other cryptocurrencies.
A few points that convinced me not to put my money into this system:
If hash capacity were traded on a perfectly competitive market, then it would always make sense to rent 51% of the capacity at market rates, earn the transaction fees, and also perform a double-spending attack. There is no equilibrium point for transaction fees where this attack becomes uneconomical. The only defense is that the market for hash capacity is imperfect.
The market for hash capacity is going to become more efficient over time. ASIC miners will be commoditized, so that hardware investment becomes a much smaller factor in hash cost versus energy. This might be even worse during a bitcoin downturn, because there could be a glut of ASIC miners.
Miners will coordinate with market prices, turning off capacity when the price dips (for example, because someone is underbidding to create a 51% attack). If mining becomes more decentralized, it will be harder for miners to act in their common interest (fending off 51% attacks) and against their immediate interest (selling their hashrate to the highest bidder, or taking it off the market during an underbidding attack).
High transaction volume is not necessarily any help - the more transaction volume, the higher the cost of the attack, but the greater the rewards. The semi-anonymous nature of bitcoin means that one could easily flood the network with double-spend transactions. Attacking a huge network like bitcoin would be an audacious and expensive act, but there are certainly organizations with the resources to do it, e.g. intelligence agencies, organized crime. The massive rewards to such an attack also offset fixed costs such as writing and testing the software to carry out the attack.
Hostility toward a community in which the target currency is particularly popular.
“Some men just want to watch the world burn.”
Mind you, I say this as a crypto currency outsider.
That's true as long as cryptocurrency itself is seen as fringe; it's less true if cryptocurrency becomes generally accepted.
Of course, a nation-state or other actor interested in preserving the role of fiat and keeping cryptocurrency on the fringes is also a possibility.
If a bank is critically hit so bad funds become impossible to correctly attribute to people (Fight Club type unrealistic scenario), at least in the US FDIC would probably come in to play. The bank might even have to be treated as a failed bank.
People wouldn't stop using banks, but they would stop using that bank.
I'd really like to live in a world where that's true, but I don't see Equifax going anywhere. PayPal does a form of this as well, except it's the central system and not a rogue actor that locks your money away. Well informed users avoid PayPal, but there appear to be many more uninformed users.
A major hack against Visa would absolutely tank the value of Visa the company however, and if people who believed they were paid weren't made whole somehow then it would also tank the acceptance of Visa.
And it would be an ongoing devaluation without Visa being able to show they'd fixed the underlying flaw - which you can't with a 51% attack.
I have a shift card, bought tacobell with bitcoin.
And that's not even considering the transactions fees it costs to get the Bitcoin to your account.
Then there are the transaction fees for using the card, which coinbase says is free "for now".
Sure, transactions are intermediated through some consensus denomination for exchange. So?
He still lost bitcoin and gained tacos. Just as someone else might lose a portion of a credit balance and gain tacos. You get just as full either way.
Credit and debit cards are just a way of shifting dollars around. Bitcoin is more a commodity than a currency. Yes, you can convert gold or oil to dollars and buy things, but you can't walk into a store and give them some gold flake or a quart of Texas crude in exchange for a candy bar.
A credit card is shifting a line of credit, an intangible promise to pay, a form of trust, that happens to be denominated in dollars.
We can pretend it's just a balance of dollars, even though it technically isn't, because it makes conversations easier, and in practical fact that's how it appears to work. But that's just a shorthand.
We can use the same shorthand to say someone bought something with bitcoin.
There's no reason to demand perfect technical precision with bitcoin and no similar pedantic precision with lines of credit.
> you can't walk into a store and give them some gold flake or a quart of Texas crude in exchange for a candy bar
I think this is the best test. Here the guy has done that. He walked in with bitcoin and walked out with tacos. When you say that's not really what happened, it feels like a no true scotsman response.
Bitcoin is not a currency. Plenty of other things are true currencies, so there's no fallacy here.
If you insist that the guy paid his beer with USD, it is going to be very difficult to discuss about anything as the meanings of the concepts are so twisted.
It is quite obvious that using a credit card that then accepts BTCfrom you does not mean that you use BTC to pay for anything but your credit card bill.
It's a useful currency.
Amazon alone probably handles more transactions over the course of a couple of weeks.
[1] https://www.quora.com/How-many-credit-and-debit-card-transac...
Even prominent Bitcoin advocates agree it's not effective as a currency: http://avc.com/2017/08/store-of-value-vs-payment-system/
Also, all systems that pay taxes are negative sum as well! Utility is not measured in money.
You're also wrong about taxes. Consider my local taqueria. They buy raw materials and create value by making ready-to-eat food just when people are hungry. They receive cash in exchange, a portion of which they pay in taxes to fund the infrastructure their business depends upon.
That is positive sum for all participants. It has to be. If taxes tipped it into the negative sum category, they'd eventually close down.
If you buy 50 dollars of taco materials, then taco materials seller makes likes than 50 dollars ,because the state will charge a tax on him. If he didnt sell 50 dollars worth of raw materials, he would have 50 dollars of raw materials to consume, instead of less than 50 dollars.
On the other side, making the taco, you have the same issue: if you sell 100 dollars of tacos, and someone pays you 100 dollars for them, you then pay taxes.
You earn less than 100 dollars, and someone else lost 100 dollars. Repeat the proces ad-infinitum and your holdings go to 0.
If you buy 50 dollars of taco materials, then taco materials seller makes likes than 50 dollars ,because the state will charge a tax on him. If he didnt sell 50 dollars worth of raw materials, he would have 50 dollars of raw materials to consume, instead of less than 50 dollars.
On the other side, making the taco, you have the same issue: if you sell 100 dollars of tacos, and someone pays you 100 dollars for them, you then pay taxes.
You earn less than 100 dollars, and someone else lost 100 dollars. Repeat the proces ad-infinitum and your holdings go to 0. (assuming for simplification, any rate of positive taxation on income).
Most economic activity is positive sum. When I'm hungry and on the go, a taco is more valuable to me than raw taco materials, so I pay more for it. Value has been created. The taqueria owner takes money in, pays their expenses, and is left with a profit. Taxes are paid out of that profit, and you could just as well model it as another kind of expense, a societal infrastructure fee.
Many countries use value creation as an explicit taxation model: https://en.wikipedia.org/wiki/Value-added_tax
Those are still positive-sum interactions in the economic sense: https://www.tutor2u.net/economics/blog/qa-what-is-a-positive...
But not dollars, which is what you are using to classify gambling as negative-sum.
> Many countries use value creation as an explicit taxation model: https://en.wikipedia.org/wiki/Value-added_tax
If the gobernment collected that tax but didnt spend or issued money, even VAT ends up capturing all the money supply.
This is an unnecessary long argumentation. Gambling is not negative sum because they provider entertainment that has utility.
I understand you are claiming the entertainment value outweighs the harm of exploitation and addiction. I strongly disagree.
Expected value is not the only thing to consider. Higher moments matter.
Insurance typically has negative expected value but it’s rational to buy it (in conjunction with owning the insured object) to reduce one’s variance.
Gambling will increase the variance of one’s portfolio at the cost of expected value, which can be rational depending on one’s situation.
Apart from weird edge cases where an actor needs to double their money overnight to return to solvency in order to have a chance of benefiting from an income stream in future, there aren't many cases where it makes sense from a portfolio allocation basis given the existence of non-negative expectation bets in other markets with a wide range of possible variances. The insurance and investment management industries are built on the principle that economic rationality works in exactly the opposite way to gambling: that inherent value exists in reducing risk.
Also, consider ghash.io or the odd OKPAY double spends.
They have an underlying value/utility. People have a real, tangible need _outside of the use of those products_ to get them fixed. Can you say the same for a cryptocurrency?
Zero.
Edit: any crypto-currency you can exploit gives you option to print yourself money.
First of all, the value of a currency that could be printer on any printer might not actually be even 0.
Secondly, cryptocurrencies do not operate in vacuum. Its not as simple as "printing yourself money".
Second, if I went to a store spent 199 dollars and those 199 dollars magically reappeared in my hand, didn't I create money out of nothing and reduce dollar value? Yes I did. Even if I never cloned any money I reduce the expectations of future stores that their money won't magically disappear.
And yes, I am aware banks do this, but they are regulated and when they abuse it, you get a financial crisis.
It’s more like being able to write two checks for your whole bank balance and having them both clear.
So very relevant are:
- whatever goods you bought with the checks need to be impossible to recall. So, like you need to find (two) someone’s who will effectively cash your check. You can’t buy a house because the police will come take the house back.
- you need to do it fast. The second you make are the first transaction you need fork and start mining hard. 51% gives you a speed advantage, but it’s very small. It still takes time to get the network to follow you.
Double spend is a very specific heist. Even if someone did it, it wouldn’t mean Bitcoin is valueless, it would just mean a certain class of heist is somewhat more probably and people need to adjust their security practices accordingly.
Tricks like waiting for extra confirmations, requiring identification before accepting payment, etc, are easy remediations.
https://en.wikipedia.org/wiki/The_Diamond_as_Big_as_the_Ritz
I think people need to be concerned that Governments, at any point of time, with their incomprehensibly huge computation power, can use it to crush bitcoin. Not only that but they can pass laws that allow them to forcibly seize the fattest wallets. Which ultimately ensure's that the Government can, behind the scenes, kick the scaffolding out from beneath us. All I see right now is state level actors experimenting in this regard, because seriously who single handedly has the computation power to take control of these cryptocurrency's if its not the government or a company like Google?
But fortunately, these state actors seem to have no interest in attacking crypto.
It seems like the governments that matters IE the 1st world, are perfectly happy to allow people to have access to a censorship resistant method of financial transactions.
This makes a certain amount of sense. The governments of the 1st world claim to care a lot about freedom. And it seems that they are getting us have it.
I don't see any of these privacy coins being banned yet, so.....
But anyways that is besides the point.
The argument that the OP was making was that governments are areal threat to crypto. And MY point was that these governments are NOT actually attacking cryoptocurrencies so I guess things are going to work out fine for cryptocurrencies.
To the extent there is a legitimate threat to dollar supremacy, it is in the Chinese renminbi. The U.S. dollar is ascendant because of the huge base of American consumers, who buy stuff with dollars others then need to find investment for. Plain and simple network effects.
The US dollar is useful to countries like china is because the US government acts as a debtor of last resort, allowing them to park surpluses in treasuries.
Which ultimately derives from our mammoth consumption. If Chinese consumption eclipses America's and their economy rebalances, they will have lots of Chinese consumers buying goods with renmimbi, leaving sellers offshore with boatloads of the currency to find investments for. (I consider this to be a moderate risk, and not one which would supplant the U.S. dollar but instead cause it to share the world stage.)
TL; DR Bitcoin is not a serious threat to the U.S. dollar. It promises huge profits to banks, which is why they're salivating over it.
The Chinese government is not interested in filling this same role, even if now anemic Chinese consumption somehow picks up, they will probably still want to maintain absolute control over the exchange rate.
https://datahelpdesk.worldbank.org/knowledgebase/articles/11...
If you look at the original paper, it's pretty clear that Bitcoin was meant to be peer-to-peer electronic cash: https://bitcoin.org/bitcoin.pdf
In practice, it has failed at this aim. I don't think that was necessarily so; plenty of things start out rough and become more useful over time. But the mechanics-adorers I've talked with seemed willfully blind to all the practical issues. We can't fix problems we refuse to see, so Bitcoin has preserved its machinery at the expense of fulfilling its vision.
I use technology to solve problems for people. The few niches Bitcoin has found (e.g., speculation, money laundering, ransoms, light drug crime) are not really what I would call solving problems for people.
Bitcoin has property similar to cash to many extend. It was not technically possible before its invention and as such as it is a real intrinsect value (dont ask me to quantify it)
Regardless, your point doesn't make a lot of sense, because many Germans surveyed on this say they use cash because it gives them better control over spending and more clarity as to where their money goes. Bitcoin is in no way superior to a debit card in that regard.
The value of new possibility isn't really intrinsic; you measure it through seeing if people actually use it. With Bitcoin they mostly don't, which suggests that it is at best more useful to a small slice of people.
Really, though, I think the closest financial match is a private currency: https://en.wikipedia.org/wiki/Private_currency
These are illegal in most places because they historically have caused a lot of problems without much in the way of redeeming value: https://en.wikipedia.org/wiki/Banking_in_the_United_States#1...
Digital currencies can be used via computers and networks while physical currencies such as banknotes and gold requires sneakernet.
Besides, AirBnb didnt even fail in providing accommodation for conference goers with included breakfast. It still works perfectly in its original intended use.
Bitcoin was a political experiment before it was a technological one. You don't pivot political beliefs the way you pivot a business. The technological experiment is still ongoing, but the political experiment has failed its goals.
They succeeded by expanding the mechanism to support actual discovered user needs. Which is what Bitcoin signally failed to do.
Then it hits the real world, and suddenly what people actually do with it and its valuation is dependent on how the exchanges operate (are exchanges even mentioned in the original paper?), energy prices in China, media coverage, interactions with alt-coins, etc.
I'm asking what the long game is? You haven't helped.
There would seem to be organizations (states?) that can wield tremendous resources to mine Bitcoins. I would think this would devalue the currency and, as is so often the case in life, fuck over the little people.
Never mind the insane amount of actual energy resources needed for this virtual currency. It almost seems immoral.
And with exploits like the one in this article, how can anyone continue to have confidence in it? It feels more akin to Confederate money printed during the U.S. Civil War.
In addition to this you have to do it on margin, and most exchanges have a history of dubious liquidation of margin positions.
2. Rent 51% and mine a fork in secret for a week
3. Wreak havoc
4. Collect money
So why the pow? Is this stabilizing the actors somehow? It seems like an explicitly managed network would be no less centralized, way more efficient, and way more user friendly.
> Any non-colluding ecosystem should have centralized.
Not exactly. There's real laws and borders and market realities that prevent the ultimate centralization of hashpower but what's clear is that centralization is works, centralization is extremely profitable, it's happening and it will continue [1]. Centralization, I would suggest, is the true goal of bitcoin and is the inevitable conclusion.
> So why the pow?
I see what you're getting at but it should be obvious. The miners are paid very, very handsomely not to collude. Bitcoin miners charge fees that are effectively far greater than any centralized authority. They reap billions in profit each year [2] for turning on a bunch of computers and plugging them in. A cynic might say the "proof of work" is a marketing tool to disguise what is really just the mass transfer of wealth to the miners. Certainly, bitcoin holders believe that miners have somehow "earned" these outrageous profits.
[1] https://blockchain.info/pools
[2] http://fortune.com/2018/02/24/bitcoin-mining-bitmain-profits...
Only if you make it public. A 51% attack works at a poker table too, but only if the marks don't know the game is rigged.
A successful double spend makes it public, as well as announcing your intentions to get to 51%. If you're quiet and can pull off a successful 51%, you can create the double spend before anyone knows.
If renting asic miners becomes vogue (and it might because it makes the computing market more efficient) then it might be possible just to rent asic miners for nearly free, since you'd be acquiring bitcoins while you were amassing the 51% computing power.
Security in crypto is a very slippery concept, and many conclusions are non-obvious, if not outright counter-intuitive.
Large miners don't want to see Bitcoin get attacked because it destroys their income and de-values their incredibly expensive hardware. This is also why miners won't just let you borrow their hashrate for a while - it's a big issue if you use that hashrate to undermine their cash cow.
Just wondering if there is some kind of crypto currency where the transactions had a max of some kind. Would the difficulty be able to be much smaller and blocks every minute (since there would be so many more to transact)? This isn't well formed, just off the top.....
Yes, but only if mining the coins via renting is cheaper than buying them outright.
If you're a miner, it makes sense to rent out your gear, because you get a guaranteed payment higher than you could make via mining.
For any purchase, there's a trail that leads to you through however you paid for it; for mining, the mined coins are totally disconnected from the hardware that mined the block and how you bought it.
For instance, I can decide not to finalize the transaction until I see a chain with 12 new blocks added after the transaction block. So an attacker has to control 51% for 2 hours to successfully scam me. Or I can make it 24 blocks (4 hours), or whatever.
Not sure this can mitigate the attacks and market forces you discuss, but it might. I see Bitcoin moving toward an intermediary system where you have a "Bitcoin balance" with a "Bitcoin bank" that allows you to make immediate transactions and takes on the risk and time delay of settling these transactions on the blockchain over the course of the next day or two.
How would this system differ from an ordinary bank in the system we have now?
Could you expand a bit more on this?
One of these is not like the others
How do you propose they would go about doing this? Would they jam up the whole worlds chip production to source the ASICs at above market rates? How could this be profitable?
Perhaps by taking over existing mining operations, but then you’d need to somehow perform the attack before you’re detected.
That makes no sense. If there are no confirmations, there is no cost, because nothing happened. This comment is a 0-conf transaction on BTC...
How bitcoin transacting work is not that the miners publish their price and someone accepts that price and thus sends the transaction to that miner. How it works is that you publish your transaction with the fee you're willing to pay and if your fee is high enough, it will get included in the next block.
It has nothing to do with Bitcoin.
Full Casper may have stronger liveness guarantees eventually, I'm not sure. At a minimum it's easier to manually intervene to get the network going again. (You could also do that in PoW by changing the hash algorithm, but you can probably only pull it off once, migrating from ASIC to general purpose hardware.)
Right now what would minimum amount of power would be necessary? How many homes/neighborhood worth? How many Amazon data centers?
* bitcoin is not mandated as the sole accepted currency for settling tax in any sovereign state, therefore it can go to zero
Also tell people in Venezuela how their Bolivar is not going to zero, because they have to pay their taxes with it.
Nation states. Don't forget the large number of sanctioned regimes who would (a) have the resources to execute such an attack and (b) find great profit in doing so.
These double-spend attacks are only successful if the receiving party doesn't wait long enough.
Also, could't find any sources from exchanges if they were actually successful? The article didn't mention which exchanges.
Quote:
"Blockchain data indicates that the attacker successfully reversed transactions as far back as 22 blocks, leading developers to advise raising confirmation requirements to 50 blocks."
So as long as exchanges wait 50 blocks before crediting, they should be all right.
Someone could rent the local courts for a week, pillage everyone, and leave.
Or just come with a larger army.
In 2013, the network forked unexpectedly [0] and the Bitcoin network had 2 chains for about 4 hours. During those 4 hours, it is entirely possible that people sent BTC to exchanges they knew were going to be on the chain that ended up being orphaned.
A conniving team of centralized developers can take this a step further and discover or intentionally plant a consensus bug that causes such a fork and because developers ultimately tell everyone which chain contains the "fix" (in 2013, they commanded that the minority chain was the right one), the developers know which chain will be orphaned and thus which exchange they can exploit.
[0] https://freedom-to-tinker.com/2015/07/28/analyzing-the-2013-...
At this point in time the current hashrate of the bitcoin network is 32.500 PH/s, up from 5.000 PH/s a year ago and 1.400 PH/s two years ago. If you rent 51% of the network it's going to be rather obvious that something is happening, that will however not prevent an attack. Let us assume that you can rent capacity because the miners are greedy, what price would you have to pay? Let's assume that you can buy from miners that want to exit the mining business, so they do not care about deprecating the value of their hardware nor the bitcoin value itself.
So the assumptions are that 51% of the available capacity don't care if bitcoin tank and burn as long as they profit enough, and you're able to buy that. A 0.43% difficulty increase daily (average over last 2 years), bitcoin price of 7.600$, a 4MW powerdraw, and electricity prices of $0.08/KWh
Miners controlling 51% would profit north of $1.000.000.000 yearly, and if they just want to be compensated for that one year, you have to pay $1.000.000.000 to rent 51%. That is a lot of money, and at $20.000 high it would be tripple that value.
However, why would 51% of the capacity suddenly exit? Rather they want to be compensated for multiple years of profit, lets say 5 years and it's not unreasonable to expect bitcoin to reach $70.000 in that time. So we're looking at a $50.000.000.000 cost to coordinate the attack. That's expensive, and with that kind of money there are other ways to make them multiply. Who would pay that to ensure destruction of the thing we know as Bitcoin? After all, the success means it's likely that another *coin takes over, where you cannot 51% as easily.
People like to compare bitcoin to gold, which has an estimated current market cap of $6,000,000,000,000. Will gold ever generate more value than Google or several Big Energy companies combined with more than a factor 10? Or does it hold value simply because it's rare?
Gold is also quite unique and "best" or close-to-best in its collection of properties. Bitcoin is not really rare and many other recent variants are "better" in a number of ways. Would the network effect be sufficient for its valuation to come close to physical gold? Warren Buffett, Robert Shiller, a well-known Nobel prize winner in economics, and several other respected economists say unlikely [1] [2] [3]. Basic logic says the same.
[1] ""It has no value at all unless there is some common consensus that it has value. Other things like gold would at least have some value if people didn't see it as an investment," Shiller told CNBC in an interview ahead of the World Economic Forum in Davos, Switzerland, where he will be speaking next week."
https://www.cnbc.com/2018/01/19/bitcoin-likely-to-totally-co...
[2] https://www.project-syndicate.org/commentary/cryptocurrencie...
[3] https://www.project-syndicate.org/commentary/cryptocurrencie...
I'd argue that jewelry is also a store of value. It doesn't serve a practical purpose, and was traditionally given as a gift for hard times. Industrial applications, fair enough. This also plainly written in your quote from [1]
> Bitcoin is not really rare and many other recent variants are "better" in a number of ways. Would the network effect be sufficient for its valuation to come close to physical gold? Warren Buffett, Robert Shiller, a well-known Nobel prize winner in economics, and several other respected economists say unlikely.
Bitcoin is exceedingly rare. Only 21 million will be created, and a non trivial portion of them is lost in wallets that no one controls. In [1] he states that "doesn't know what to make of bitcoin ultimately.". In [2] one of the main arguments seems to be "Practically no one, outside of computer science departments, can explain how cryptocurrencies work." which is true for the modern banking system too. Besides, it really isn't hard to explain the idea and workings, without going into the technical details.
One of the things that could super charge bitcoin is LN. The potential is enormous if adopted by companies.
The article in [3] shows a fundamental misunderstanding of bitcoin when it claims
> Bitcoin will be “mined” in diminishing quantities until it is exhausted in 2040, having delivered 21 million digital coins. In other words, there is no elasticity in the currency. This means that long before the mine is exhausted, the currency will run into the same problem as the gold standard: not providing enough money to support a growing economy and population.
Gold is limited by the smallest amount of gold you can reliably trade. Bitcoin have no such restriction. As the value of a whole bitcoin increases, you can trade a smaller and smaller fraction. At the current value 130 "Satoshi", which the name for the current smallest fraction possible to trade, is worth $0.01, so bitcoin can reach a value of $1,000,000 and still have the same monetary "resolution" as the current USD.
The last paragraph might on the face of it seems to contradict my statement about the rarity earlier. But there is a key difference. Because bitcoin is in limited supply, but possible to trade very small fractions of it, and ability to allow smaller fractions if needed, means that the currency is more likely to be deflationary, i.e. the money I save will not automatically be worth less because I do not use them.
You're killing your goose with the golden eggs. That is, if a currencies remains in use.
Examples like Delegated Proof-of-Stake or "eusocial oligarchy like consensus" systems like Byteball?
But, if we take on step further and continue our experiment, lets compare the actual facts with the assumption.
And what we see? Two cryptocurrencies (Bitcoin Gold and Verge) which were successfully attacked this week, didn't lose in market cap.
How comes? What conclusion should we take from this assumption/fact, if continue being scientific? Do we need a new assumption?
A mid-term (3-7 years) of irrational behaviour in a market in not unusual. Some will benefit from it.
How do you know the current behavior is irrational? We probably just don't know what kind of rationality is behind this.
What if it is not drive by the technical merits of blockchain, but still based on some rationality, we reject to agree with?
There are a lot of problems other than double spend with the Bitcoin. Transactions fees rise very quickly because of the block size limit of about 1MB. You can't really rely on 0-confirmation transactions. The saviour lightning network in my opinion is the wrong solution to the scaling problem. It changes fundamentally how bitcoins are exchanged and steers away from the original white paper by Satoshi. Not that this is wrong... it just becomes another project altogether.
The dominant form of mining would be utility companies and individuals redirecting excess electricity generated from their renewable electric power generators, during off-peak hours and spikes in generation, to mining, and the constituents would be both numerous and globally distributed, owing to the wide geography areas across which renewable energy resources are found.
"Renting 51%" (of any global market) and "at market rates" are mutually exclusive.
> There is no equilibrium point for transaction fees where this attack becomes uneconomical.
The counterforce against doublespending is not transaction fee but cost of ownership of mining equipment.
Some other arguments against your conclusion:
- As mentioned nearby, for big transactions you want to wait longer than 6 confirmations.
- Also, as recipient you might want to distribute huge payments into smaller ones distributed over time.
- It's in the interest of mining capacity lenders to make sure you don't get 51% because it renders their equipment worthless in case you are successful.
- As you correctly stated, low prices will lead to lower hash rates (and higher prices to higher rates). This means actually that bitcoin will be more stable (it's harder to obtain 51%) if prices rise. There's an equilibrium on that side as well! That is, if double spending is what you're worried about.
It seems you're too focused on a specific decentralized consensus solution, while there are already much better ones out there, e.g. Iota with a tangle, skycoin with a web of trust or Elastos that are immune to 51% attacks.
I plausibly could have invested a few hundred or thousand in Bitcoin was in the low hundreds, and if I hodl'd to the moon realized a hundredfold gain, which would have been nice.
But once you're at the moon, then what?
The new price predictions are things like "If Bitcoin replaces gold it could be worth $135,000/BTC.". Which is a lot, and a little far fetched, but also only 6x from the last peak.
I'm not interested in a risky investment which takes years to come to fruition and only yields 6x. It's too risk for a safe investment and too low-yield for a risky investment. Boat missed.
As a cartel must outmine the entire Bitcoin network and thus outspend the entire Bitcoin network for as long as it would remain a cartel, we believe it is very unlikely that a cartel could double-spend enough to recover the cost of the attack...
As described above, a 51% cartel attack is unlikely to generate enough reward within the Bitcoin economy to be worthwhile to the attacker. However, this does not rule out the possibility of a 51% attack that aims to destroy the Bitcoin economy in order to achieve utility outside the Bitcoin economy. We call this the Goldfinger attack after the character in film who tries to undermine U.S. currency by ruining its gold backing [15]...
In all of these cases, the attacker must achieve enough utility to justify the substantial cost of an attack. We agree with Becker et al. that it is unlikely that a protest movement could muster the resources to launch a successful attack. And at present it does not appear possible to acquire a short position on Bitcoins that is large enough to justify an attack. (2013)
The Economics of Bitcoin Mining, or Bitcoin in the Presence of Adversaries
Joshua A. Kroll, Ian C. Davey, and Edward W. Felten, Princeton University
https://www.econinfosec.org/archive/weis2013/papers/KrollDav...
Lenin was right: "When it comes time to hang the capitalists, they will vie with each other for the rope contract."[0]
The problem with mining centralization is that sufficiently powerful miners can attack the network by rewriting blocks. This opens the door to double spending.
This was exactly the attack the article described.
It appears that Bitcoin Gold's decision to use Equihash led to this mess. The algorithm is used by several other coins. Hardware optimized for this algorithm can therefore be used with equal ease to mine on a network or attack it.
Bitcoin Cash may be headed for a similar fate. It retains SHA-256, but is a minority chain in terms of hash power. A powerful Bitcoin miner deciding to perform double spends on Bitcoin Cash would have everything needed to do repeat the Bitcoin Gold attack.
BTW, a similar attack recently occured on Verge:
https://blog.theabacus.io/the-verge-hack-explained-7942f63a3...
It's possible that any altcoin that becomes sufficiently valuable will suffer similar attacks to the ones that have now taken place on Verge and Bitcoin Gold.
The trust in these systems seems to be based on proving a negative.
The lack of an attack is neither a proof of robustness nor proof that one or more zero days aren’t already known. We can only “know” it’s safe when the temptation to use an exploit is far too high to resist.
I think there are a lot of people who imagine “an attack” as a ready-aim-fire affair. There’s a juicy target, someone concocts a plan and then uses it.
But as you illustrate, maybe there is already a plan and someone is waiting for the target to get juicy enough. Aim, ready, fire.
Normally the non-51% attack argument is that anyone who invests enough in 51% of the infrastructure and has sufficient coins to profit from double-spending, is very unlikely to do so because it would render the coins and mining equipment worthless or at least worth less than the investment had cost.
That'd be true for bitcoin, but not for a GPU-mined 26th largest cryptocurrency. You can completely destroy it, cash out and use your equipment elsewhere on coins in which people still have faith.
So you can exchange it to BTC or ETH and withdraw. Or you can just deposit it and withdraw it after. Most exchanges just mix customer funds together, so as long as the exchange has enough BTG balance minus the double spent deposit, they will send you real BTG.
I would also point out that Bitcoin cash is the 4th largest crypto currency in the world, by market cap. If IT is in danger.... Well I fear for everyone else even more.
The whole point of crypto is that you are relying on the fact that 50% of the network is honest.
So yes, you are correct that it relies on half the network being "benevolent". That's how ALL cryptos work.
Specifically, the fraction is 51/100, or 51 percent of the network. This is for the main Bitcoin network.
The fraction for Bitcoin cash would be around 15%, or 15/100, expressed as a fraction.
The Bitcoin cash network would require a smaller fraction, yes. But this still isn't a huge concern.
If it is 3 times easier to attack bitcoin cash, that is still extremely difficult.
Fractional hashpower attacks, (51% attacks) are all explained quite clearly in the white paper.
Alternatively, if the exchange isn’t smart enough to pay short-term withdrawals with inputs that link back to the recent deposit, an attacker could just deposit and then withdraw with no trade and the withdraw transaction is valid even if the deposit is double-spent.
An exchange that lets a trader deposit millions in one crypto-asset, exchange it for another, and clear a withdrawl in 4 hours... got what was coming to them? Where’s the KYC process for a million-dollar deposit?
There’s a reason new deposits in a brokerage account take a few days to settle / be cleared for trading. And again after selling before funds can be withdrawn. And that’s a currency where most transactions can be reversed!
It would be one thing to allow 10 block settlement for Bitcoin main-net. It’s another to allow it with a thinly mined alt-coin.
This trade would look exactly the same as an arbitrage move.
If exchanges are enticing arbitrage through insanely quick setttlement and clearance times on the order of 2 hours after closing a position, they are just playing with fire.
If there wasn’t an actual trade, just transfering in and out, not chaining the transactions is similarly RTFM.
If the facts are as I understand them, I think the exchange bears a significant portion of the blame.
It’s like the story a couple weeks ago where Deutche Bank accidentally approved a wire transfer for $35 billion dollars.
Majority of current exchanges are playing it absolutely fast-and dangerous. It's no surprise with new exchanges popping up like mushrooms.
I'd bet that the top exchanges didn't lose anything on this. I'd actually wager this didn't happen to an exchange, but some other type of site, like a BTG Betting site or something.
You can estimate the cost of double-spend attacks on each chain at any time, calculate your potential exposure, track where the related funds are now in your system, and mitigate your exposure by delaying the outflow of funds that have outsize exposure to double-spend attack potential.
In the simple case, you might allow withdrawal of a single $10 deposit after 2 confirmations but enforce a long 1000-confirmation waiting period on a million-dollar deposit, in order to increase the cost of executing a double-spend against your exchange beyond the point which you estimate it becomes infeasible.
It's a little trickier in practice because someone could split their million-dollar deposit into 1000 thousand-dollar deposits from separate addresses into separate accounts. But you can still track your exposure in aggregate, and you should design a system to hold all impacted funds as long as is necessary to make a double-spend attack infeasible.
You can be upfront with your clients about what's happening and why their withdrawals are sometimes delayed: it would increase confidence in the safety of honest customers' deposits while discouraging thieves from targeting you.
also, you can monitor the value of transactions in the last few blocks. 500% spike in transaction value in the last 2 blocks? better add a few more blocks to the confirmation requirement, or require withholding on those deposits.
https://forum.bitcoingold.org/t/double-spend-attack-on-excha...
Bitcoin gold was a fork to try and decentralize mining. It changed to a proof of work that is supposed to be ASIC resistant. It looks like the typical situation is mining by GPU for equihash (BTG PoW).
BTG hashrate is at ~30MH/s at the moment, where Zcash's hashrate is at ~486MH/s.
I don't have the numbers off hand, but it'd be interesting to see how many GPUs you'd need to pull of a double spend against BTG and if any of the other equihash coins saw a drop off during the attack.
It'd be really interesting if it wasn't a rental attack, but an invested miner just switching over to BTG to achieve the hack.
They reversed 22 blocks, the recommendation is to increase the # of confirmations to rely upon to 50. If you are trying to react to 51% attack doubling the number of confirmations only doubles the cost of attack, and the attacker likely just doubled the number of BTG they have. If they can pay the electricity/rental cost for the attack they have enough BTG to execute the attack in a cost effective manner again.
That sounds problematic. If I deposited coins and the exchange determined I was attacking them (how does that work beforehand?) to confiscate my money I'd be pretty miffed.
A cryptocoin is worthless to miners if it cannot be exchanged, and it's worthless to exchanges if no one wants to trade it.
These are the absolute worst. All they're doing is causing the cost of graphics cards to go up.
417.5 BTC/GH/day for equihash if you're renting from nicehash [1]. Block interval 10 minutes [2]. 144 blocks per day target yields 0.0869 BTC/block, so cost of the 22 block reversal was ~1.91 BTC, or roughly $15k.
I'm curious if this was done as one large deposit, or many smaller deposits. I've imagined a system where block confirmations required are based on a computed cost of attack done like I did above, which would be pretty effective for very large single transaction double spends. A bit trickier to handle multiple deposits spread across multiple user accounts.
[1]: https://api.nicehash.com/api?method=simplemultialgo.info
For example changes could wait for 10 minutes worth of blocks then request a quote for double spend insurance. The company evaluates the probability of a double spend and maybe even has a couple standing contracts with rentable hashing power to be able to target smaller PoW chains and prevent any double spend attack.
There are lots of interesting and cool problems to be solved in evaluating the safety of a given tx. Unfortunately I don't know if the space is mature enough that exchanges would actually use the service.
Am I misunderstanding something here, or can I maintain a 51% attack right now for ~$8k an hour. This can't be right.
If 100 machines play fair, >50% requires 101 evil machines, but >60% requires 151 evil machines.
An honest network participant will accept the chain with the largest accumulated proof of work. This is necessary to resolve forks of the chain, which are a natural occurrence.
A 51% attack means that the attacker can create a chain with more work than the rest of the network.
The idea that you can say "we require 60%" makes no sense by itself - you have to say what you actually mean in the context of a competitive and adversarial distributed proof of work blockchain network...
Maybe you have some ideas how to avoid history-rewriting attacks, in which case you should write a white-paper and launch your own sh1tcoin or ICO (only half joking).
Some blockchains require a higher amount of consensus to fork (blockchain fork).
For others who might be confused, here is a good resource:
https://bitcoin.stackexchange.com/questions/26999/supermajor...
We could really do with a webpage with a list of crypto currencies, the hashing power currently behind them, and how much it would cost somebody to take over 50% of the network.
Or does that already exist?
I am emphatically not taking a stance on which I prefer here, I might add, just pointing out that there are more variables here than you're acknowledging.
With a blockchain, you still need to trust the counterparty, but now you also need to trust that the coders have properly designed and programmed the system, and that the miners either don't have the power to corrupt the system or aren't corrupt, and you need to trust whatever exchange you use to get into and out of the cryptocurrency.
Plus, you've added in a significant amount of time--at a minimum 20x the time with Bitcoin and significant transaction fees that as a practical matter have exceeded card interchange fees by 2x or more for the past 3 years straight.
Your right about their being more variables...with cryptocurrency.
One obvious tradeoff you're not considering is that of a criminal getting its assets frozen, for instance. There are less black and white situations where you might prefer bitcoin as well, if you have a little imagination. If you could address that, I'd probably appreciate your comments more.
With fiat, I at least have some idea who I am trusting, and if my trust is betrayed, I have some idea who to work with others to organize to work to inflict punishment. And, the people involved are aware of that.
With crypto, I have to trust an anonymous network of people that I have only distant and indirect indications aren't, in overwhelming majority, mutually cooperating agents of a single potentially adverse party, and no idea of who to go after if my trust is betrayed. And the people involved know that, too.
Yes, except the trust is free. Bitcoin replaces that trust with burning electricity.
It's kind of like standing on the ground. The surface of the Earth stops you from accelerating under gravity for free. But if you want to hover just above it, you have to burn ungodly amounts of energy, because you're now replacing surface with active propulsion. This is the same relationship as Bitcoin has with trust.
And yes, flying is occasionally useful. So are trustless systems. But both the ground and trust are features that cut out a lot of unnecessary energy usage from our lives.
And since we're taking into account all of the underlying systemic costs going into banks, we need to do the same for Bitcoin. That means including all of the power utilities, factories, and mining facilities that went into making the hardware, plus the cost of shipping the hardware worldwide, plus the cost of the utilities and transmission lines needed to operate the network. And that's clearly not 1/20,000th the cost or resource usage of our current financial system.
In the case of bitcoin they aren't inherently necessary to the function of the system, although with the risk of hacks you can make the case for them.
Fort Knox has basically nothing to do with the modern U.S. dollar financial system.
The U.S. dollar isn't backed by gold. The total value of the gold at Fort Knox, about $100 billion, is negligible [1] and does not appear on the Federal Reserve's balance sheet [2]. It is mostly an anachronism from the eras of the gold standard.
[1] https://en.wikipedia.org/wiki/United_States_Bullion_Deposito...
[2] https://www.federalreserve.gov/monetarypolicy/bst_fedsbalanc...
There are ~8000 banks in the US alone, around 15K around the world.
According to your made up number, it costs $6K/year to run a bank. That's not even remotely close. That would pay maybe a month of the desk clerk's salary + overhead.
All you bitcoin shysters can keep telling yourself that to sleep at night, but you are lying to yourself and you know it.
Bitcoin consumes massive amounts of energy for a pathetically small amount of transactions per second. ON a per transaction basis, Bitcoin uses several orders of magnitude more energy than anything used by modern day financial systems.
Like, embarrassingly, shamefully large amounts of electricity. Y'all should bow your heads in shame for the harm you are doing to the world.
> The service it provides is to guarantee the integrity of the blockchain without the requirement of a central authority.
The blockchain, whose only use case is to enable rampant speculation and amazingly large quantities of fraud.
The whole "space" needs to go away.
But if the new system is better than the old one, why would comparing it to the old one imply that anyone using the new one should be ashamed of doing so?
But it turns out that the new system is significantly worse than the old one, for little to no practical benefit. That's why people are comparing and complaining.
It's an open question as if it actually does serve a purpose, though.
There's not anything wrong with having a central monetary authority. There's not anything wrong with having institutional trust.
The fundamental problems of inequality don't stem from Treasury, but rather from the game theory concept of the https://en.wikipedia.org/wiki/Gambler%27s_ruin making barriers to entry for new players always higher than the incumbents. You can take this all the way down to the bottom, in the example of having no car to be a delivery driver, and to get a loan for a car is a tremendous risk.
Also they pay for all the energy they spend so what exactly is the problem? Do you see vegans complain for the resources spent to raise animals?
Yes, because the resources (Material or labour) that went into building those renewable power plants could have gone into building something else that people want or need. Houses. Retaining walls. High-speed rail tracks. Electric cars. Bicycles. Video games. Rolls of sushi.
I will keep asking that question until we are in a post-scarcity society.
Opportunity cost. All that 100% renewable energy could be used for something that actually adds value to society but isn't because it is being pissed away on the Rube Goldberg invention known as Satoshi's BlockChain.
> Also they pay for all the energy they spend so what exactly is the problem?
Give me a fucking break. These miners raise the price of electricity for everybody else and produce absolutely nothing of value to society at large.
Same thing these miners have done with graphics cards -- they've made graphics cards more expensive than most people can afford... you know, people who want to use those video cards for playing games instead of sucking down large quantities of non-renewable energy in a vain attempt to Get Rich Quick.
Bitcoin and all the others in the crypto "space" add absolutely zero value to society.
How much energy do you and everyone else waste doing things that don't add value to my life or society?
Using your own comparison, why is it a big deal if little Jimmy can't afford a graphics card to play some Counter-Strike? Is gaming a better use for energy?
Seems weird to pick on cryptocurrencies if you actually believe your premise, which I don't think you do.
Hardly. What, exactly, does bitcoin add to our world? Near as I can tell it's only use case is Making Money Fast (for the folks at the top of the pyramid, anyway) and scamming the bejesus out of all the rubes who fall for the con.
> How much energy do you and everyone else waste doing things that don't add value to my life or society?
Bitcoin is estimated to consume more than 0.5% of all the worlds energy. Many nations use less power than bitcoin consumes. Bitcoin can process a mere 4 transactions per second. Please go on and explain to me why this is even a remotely acceptable thing.
The whole space is a deplorable shame and people like you should be absolutely ashamed of yourselves. You are a drain on the planet's limited resources.
Bitcoin is relevant for the US economy and a rogue state tries to have 51% of hashing power? Military and intelligence to the rescue.
Someone is very rich in Bitcoins? Bunker services for offline storage, physical/computer security, etc.
Too many scams with altcoins? Legal enforcement, more bureaucracy, education, etc.
One could say that, somehow, the cryptocurrencies won't require as much of any of that, but I don't see this point being made as often (and not with any realistic estimations).
Protecting cryptocurrency: there are cryptographic ways to achieve very high security that are free or very inexpensive. Physical encryption keys cost under $100. Combine those with multiple signatures and offline storage in a safe deposit box and you have several physical and cryptographic layers of security for pretty cheap. Services that do those things do not need to be very expensive.
Too many scams? Point taken. We will still need police.
BTW there's a reason I said cryptocurrency and not Bitcoin. Bitcoin is one of the slower cryptocurrencies. Energy spent securing the chain is per block, and its block size limit and other aspects of its design artificially boost its energy per TX. That and in the long term I expect people to find less energy intensive ways to secure block chains.
Also Bitcoin is one of the slower block chain coins.
> How much energy is spent securing conventional financial systems? You have to include everything: banks, minting, enforcement, physical security, even military and intelligence action.
I really feel like I shouldn't have to explicitly point out why this reasoning is so flawed, but to start with, bitcoin does not IN ANY WAY obviate the need for banks, law enforcement, physical security, or "military and intelligence". There isn't some kind of "well, actually..." response to this, it's totally and obviously incorrect and we're living in two different fundamental realities if we can't agree on that base line.
Cryptocurrencies, on the other hand, have energy use as a feature, not cost. Unlike conventional financial systems, cryptocurrencies try not to minimize energy expenditure, but maximize it, as a core function ensuring their integrity.
(Also, military and intelligence action count to stability of both conventional and cryptocurrency-based systems. After all, you can't run a crypto economy without stable and secure nation states with rule of law that allow for development and availability of advanced microelectronics (for mining), electricity and the Internet. Crypto is much more dependent on that than conventional systems.)
--
A tangentially related analogy that comes to mind: cryptocurrencies are like trying to build a city on a big hovering platform, kept aloft by great fans or jets. In order to keep the whole thing airborne, you'd find yourself constantly burning fuel just to counter gravity. Now we find this idea stupid because we can just build city on the ground and not waste any fuel at all - the surface of the Earth counters gravity for free. This is cryptocurrencies' relationship with trust. Trust works 99% of the time for free. Cryptocurrencies try to replace it with burning energy.
Your reply about trust though...
Trust is massively less expensive until it's not. The trouble with trust is that when it breaks "fixing" it is immensely painful, often requiring major political upheaval or worse. In extreme cases people die when trust has to be "fixed."
I do still wonder... what happens when you amortize the cost of trust across say two hundred years time? Reminds me of the cost analysis of nuclear power. Nuclear power is cheap until Fukushima happens, and one Fukushima amortized over even 50-100 years renders nuclear power more expensive than any other energy source.
I do not think it's a coincidence that the cryptocurrency explosion happened right after the 2008 financial crisis. The level of corruption revealed by the crisis and by the nature of the state and financial sector response to the crisis (selective bailouts, bailouts only to the rich, bailouts that preserved the wealth of those responsible, etc.) showed that our trust in the financial sector and possibly in larger institutions is dangerous. People started looking for alternatives. I have doubts about whether cryptocurrency would have caught on to the level it has prior to 2008.
What cryptocurrency needs to be successful is some alternative to proof of work mining. I'm not convinced proof of stake is it since it has a lot of other problems.
What conventional economic systems need to be successful is a housecleaning and a restoration of public trust.
The average state employes about 300'000 people (324'000) to be exact (about 16 million in total, which includes teachers and similar).
So already the Ethereum network uses half of an entire average US state to just secure it's network. The US state in question does a lot more and it includes education and similar.
Bitcoin uses 68 TWh anually, about 17 times as much or about 8.5 average US states. To secure 200'000 TX per day. In contrast the US employees handle the entire state affairs, including taxes, education, etc. for 54 million people every day.
I think you may be missing my point and sarcasm.
And maybe they're worthless even then. Time will tell on that.
And then if that's true, one might dream of a power plant arms race, where two competing nations build additional power plants as fast as possible to prevent the other from gaining enough electrical capacity to attack the network...
Oh...
I'm not saying it's perfect -- there are some downsides like needing a cap on fork distance in order to prevent stake bleeding attacks [1] -- but it's certainly viable.
Why would you think an enormous amount of hashing power helps? Even with Bitcoin, the actual marginal cost of a 51% attack is quite low. The difficulty is the capital expense of actually connecting to a couple GW of power and finding enough rentable ASICs.
I think this is fundamental. In a proof-of-work scheme, if the mining rewards in whatever time frame is considered a full confirmation are less than the amount of gain available using a 51% attack, then a 51% attack is economical.
ASIC mining during boom time helps mitigate the issue a bit, since the ASICs are worth more if the currency isn’t devalued by 51% attacks, but even Bitcoin will be vulnerable of older, less efficient ASICs start flooding the market, which seems inevitable if the price of BTC stagnates enough.
- The exchange/betting website not catching onto your scheme
- The volume of the coin being enough to mass sell it and not majorly affect the price
- How fast the community can act in unison against you
Doesn't the cost depend on who you assume the attacker is? The required hashing power doesn't have the same acquisition and operating costs for all potential attackers.
Each currency would need an explanation of what resources the calculation was based on. E.g, n instances of a blah node on Google Cloud Platform running software x in config y for z hours.
Shooting from the hip:
They've go this 51% vulnerability that is well known and hypothetically cannot be truly closed. Instead, we rely on the idea that mounting such an attack would be "too expensive". But at the same time, the cost/benefit of mounting such an attack is fairly easy to estimate using public data - all you really need to know is the cost to get to 51% and stay there for a given amount of time, which you can infer by monitoring mining activity, and the current price of the currency you'd want to attack. And you have to assume that whenever the cost of mounting such an attack dips below the benefit, such a thing _will_ happen.
So then, I think that implies that the only other feature you'd need to throw into the mix to ensure a cryptocurrency is ultimately doomed is to make the rate at which new coin can be mined asymptotically approach zero. Such a feature would mean that, in the long term, miners' revenue would ultimately be dominated by transaction fees, which, this being a supremely commodity service, market forces will presumably tend to keep relatively low. That would, in turn, limit the number of miners the economy can support, which would serve to limit the cost of mounting a 51% attack.
Meanwhile, what with a money supply that can't grow being inherently deflationary, the benefit of mounting such an attack would be constantly growing, for as long as said cryptocurrency remains in use.
Or, to turn this around, if X is the amount of money needed to sustain a 51% attack for 1 block, then you have to wait for 1 confirmation for every X amount of coins received.
Luckily, there are deeper incentives protecting large asic mined chains such as bitcoin.
That's actually, if anything, underestimating the likelihood of a 51% attack. It seems that the more likely path to that situation is collusion between segments of the existing mining community. For such a cartel, the "cost" is zero, it's just a matter of trust.
One example of this sort of behavior is in mining. We tend to think of miners as being selfish to a fault, and to some degree, that's true. But sometimes miners have the opportunity to mine empty blocks (a form of attack), and refrain from doing so, because it would harm the ecosystem as a whole and jeopardize their long-term profitability.
I think this is only true if you assume that crypto-currencies must be based on proof-of-work algorithms.
What about proof of stake systems?
Not a very precise explanation, just checking, what exactly does this mean?
I always thought the way a 51% double-spend attack worked was by broadcasting a transaction for human consumption (eg, I'll give you Y coins for Z dollars), then secretly mining your own blockchain for the N successive chains following it. After the humans have completed the human-level transactions after waiting the standard N successive blocks with no transaction conflicts, you release your own secret blockchain fork back into the public with data that contradicts the current popular one and instruct your network to ignore the competing publicly-acceptable chain. The new private one wins so long as it is equally as long as the public one which it should be because you have more compute power than the rest of the public.
Is that basically what happened here?
Anyone care to weigh in on this?
Is it? Presumably you only need to maintain it for a short amount of time. Sounds like something one could smash with google cloud preemptible GPUs or similar. Especially since such an attacker is presumably not above using a stolen CC or three.
[0] https://bitinfocharts.com/comparison/bitcoin%20gold-hashrate...
The question is: are bitcoin miners subject to the usual free market assumptions? If someone offered you double the market rate to hire a bitcoin miner for an hour would you accept that offer or not?
[edit] And renting existing miners' equipment would be difficult because you would have to: figure out who they are, convince them to point their equipment to your pool, run your own dark pool servers to handle data from tons of miners, run infrastructure to make payouts to these miners, hope that exchanges don't have reorg procedures that prevent you from accomplishing your double spend, hope your chain reorg doesn't panic the market for long enough for you to double spend exchange to another coin that won't be tanking (due to the reorg).
In this case though, Bitcoin Gold shares a hashing algorithm (Equihash) with many other blockchains. It is possible that some Zcash mining farm decided to attack Bitcoin Gold because they felt the revenue from attacking Bitcoin Gold was greater than the potential damage to their income, which is primarily Zcash based.
I'm just grasping at straws here, but generally speaking it's a bad idea to share hashing algorithms with another cryptocurrency, especially if that cryptocurrency is substantially more valuable (in terms of monthly block reward) than your own.
And, all GPU-mined coins are essentially sharing one algorithm, because the hardware can jump between them easily. So all GPU based coins share this vulnerability, where the tiny GPU mined coins could easily be attacked or wiped out by a large Ethereum farm at any point.
In this case, Bitcoin Gold chose to have an "ASIC Resistant" algorithm, Equihash, and likely was only protected by GPUs mining the network. Bitmain has recently released an ASIC for Equihash that is substantially cheaper and more energy efficient than using GPUs, meaning that some pool which was able to buy a large number of the ASICs would have had a pretty easy time gaining enough hashrate to launch a 51% attack.
This is one of the big risks of attempting ASIC resistance. In the event that someone produces an ASIC, your coin is a complete sitting duck.
Also, we know that things like stuxnet exist. Imagine something even a fraction as crazy as that targeting mining nodes. It's going to happen eventually.
attacks like this is harder to pull off than you think. miners constantly submit "shares" to the pool, which are then validated to credit them a share in the block reward[1]. depending on the difficulty threshold of the shares are, these could be submitted a few times a minute to every few minutes. if you hacked and gained control of the miners, sure you can redirect all the hashing power to you, but this will be detected quite quickly. with thousands of dollars on the line per minute, you can bet that everybody has monitoring in place to detect a dip in shares submission. also keep in mind that you have to keep this going for about 1 hour (for your initial transaction to confirm) without people noticing. moreover, the core problem stealing hash power to do a 50% attack is that block times will skyrocket on the main chain, which will let everybody (and not just the pool operator) know that something's up. plus after this attack, you can bet that exchanges will start requiring additional confirmations for large deposits, and instituting withholding times for cryptocurrency withdraws.
[1] I don't know whether large mining operators do this. Strictly speaking, they don't but I'd imagine they do this because it lets them know that their rigs are up and producing valid hashes (ie. not malfunctioning). It's almost certain that small mining operators use pools.
Meh. I think I'm just gonna go ahead and add it. I haven't been paying close attention. I'm sure I've missed 1 or 2.
However since it is a 'Bitcoin cash' type coin this will ultimately hurt bitcoin and the community as a whole. I can already see the buzz "Bitcoin double spending attack!" articles
The hashrate for BTG is well below most other coins, a modest miner on another coin could easily switch and execute the attack, then switch back to their main coin and not have to pay large transaction costs for hardware acq or rental costs.
[edit] Also - bitcoin gold uses GPU mining - so one does not need to acquire specialized hardware to mine/attack it - and the hardware involved can be resold for other uses recovering a significant part of the capital cost. Or you could just rent it from the cloud.
> The incentive may help encourage nodes to stay honest. If a greedy attacker is able to assemble more CPU power than all the honest nodes, he would have to choose between using it to defraud people by stealing back his payments, or using it to generate new coins. He ought to find it more profitable to play by the rules, such rules that favour him with more new coins than everyone else combined, than to undermine the system and the validity of his own wealth.
Apparently he didn't realize that coins could quickly be transferred to other crypto and not held, so who cares about the value of the stolen goods.
Merchants are probably fine.
(Unless they are trying to vandalize the ecosystem)
If you did buy them though, you could attack cryptocurrencies one by one stealing money from a bunch of different ones.
I think both situations would be more profitable.
Executing a double spend attack on Bitcoin Cash would be a massive success for Bitcoin owners. Same goes for Bitcoin Gold.
You could even create a mining pool/network - let's call it CoinFucker - where every now and then the pool's resources were diverted to attack a rival coin. Doing so damages that coin's reputation, and in doing so reduces the competition. This would be a great way for the majority of mining/computational power to squash would-be rivals.
I personally thought that BTC would either be successful (in that it would be a useful currency) or that it would tank. I did not anticipate people dumping piles of money into it to speculate on its value. I certainly did not anticipate a bunch of wannabe coins sitting on millions and providing practically no value to anyone.
It's a testament to the number of people who are desperate to get rich. I probably should have taken a cue from the lotteries...
It's not like we don't have dollars and euros and so on, and silver and gold in the past.
> I did not anticipate people dumping piles of money into it to speculate on its value.
98% of trading in euros and dollars is pure speculation.
They're taking money from others.
Dedicated ASIC only for your chain = good. Commodity hardware = bad.
Remember when Bitcoin forked into Bitcoin Cash and somehow everyone just made up a new value for the coin?
It was like billions of dollars were created out of thin air, everyone started trading it and nobody batted an eye. Bitcoin even GAINED value.
There is no logic or sanity in the coin market.
https://firenewsfeed.com/news/635991
Good God you're not kidding.
It's like a car accident, but there's this siren song urging you to join in because some of the people are thrown free holding chunks of gold.
It reminds me of a Jim Gaffigan joke. He's talking about trying to lose weight, and how hard it is when the fast food restaurant has a $2 for 2 burgers deal... "Well... I don't want to lose money on this... I'll take eighty."
On the one hand this whole cryptocurrency thing seems to be gone off the rails. On the other hand, I do feel kinda dumb for not owning any.
Joking. Mostly.
How do you adjust the algorithm for the communication time between opposite nodes. Let's say earth distance, 16 minutes at speed of light direct.
I suppose there will be increasing incentive to do the numbers on the hash cost to take over a coin and to execute these attacks.
Neat.
The issue seems a lot more complex than either "of course this is illegal" or "of course this isn't illegal".
I'm certainly not arguing in favor of either of those positions.
Fraud and theft statutes in general don't have any specific limitations to what the stolen assets must be, it's sufficient if they have some nontrivial value. No matter if Bitcoin Gold is treated like a currency, a security, or other asset, the treatment of it regarding fraud or theft would be the same.
In general, this seems like a clear-cut case of fraud - there's a victim (the exchange) that suffered a loss (by allowing to withdraw the coins) by deception (the attacker "demonstrated" that they deposited the coins, but reversed it), and there's clear premeditated intent to arrange the scheme for the attacker's financial benefit.
The technical details of how the victim was convinced to accept the deal and how the funds were extracted, and what's the nature of the currency are not particularly relevant to whether it's fraud, they'd be used only as evidence to show what happened and to evaluate the amount of loss.
If you have 51% of the hashing power, you have control over that cryptocurrency; that's by design. Can you really steal at that point?
edit: to those replying, I'm not saying this double spend is ethically fine, or not theft in the common parlance. I'm saying it's not entirely clear to me a court would find this to be theft. Think about the Ethereum hard fork to undo the DAO hack; there, a majority of the hashing power undid a bunch of transactions. I wouldn't call that theft (because it was undoing a hack?) but it doesn't seem that different to this situation.
When you send money to an exchange, there's an understanding that the money now belongs to the exchange. The exchange waits 6 confirmations to ensure that the money is not easily stolen, but the money legally belongs to the exchange as soon as the transaction is sent.
---------------
Also, a 51% attack doesn't give you control over the cryptocurrency. You still have to follow the rules of the system, you can't print extra money from thin air, you can't spend money you don't control, the most you can do is change the ordering of the transactions that have happened on the system. And a lot of times, those transactions have block height or block id dependencies, which means you are even limited in your power to do that.
A 51% attacker is not God. They have a limited set of actions they can take, and while certain forms of stealing are included in that set of actions, it's overall a pretty limited set of things that you can do.
If however the miner maintained 51% + network share and then wrote some code to create new coins and adopted that code and mined blocks awarding himself 1000 coins for each block, he could legitimately do that and then sell those coins. Of course this could lead to the price dropping as soon as people realised what was happening and likely to happen before the attacker could send enough coins to an exchange to make the same sort of profit as in the situation in the article.
Courts generally frown on cutesy "gotcha" type defenses like that. See: Sovereign Citizens.
Code is law, bro. These fine chaps simply gathered enough resources to execute a slightly different code-path than before.
The folks whose value was stored in Bitcoin Gold should have read the source code before committing any funds to the blockchain. Had they done so, it would have been very clear that this feature was baked right into the source code.
And yes, this is sarcasm.... but only kinda sorta--bitcoiners wanna live in a Truly Free Unregulated Market, free from statist jack booted thugs stealing their wealth at gunpoint... guess what, double spend attacks where everybody loses is the end result. Sorry for their loss....
Fraud doesn't require "legally recognized money" to be involved. If you had some scam where you knowingly traded counterfeit collectable cards for real ones you'd be in trouble too.
The original claim was:
>He ought to find it more profitable to play by the rules, such rules that favour him with more new coins than everyone else combined, than to undermine the system and the validity of his own wealth
what satoshi didn't take into account, is the rise of "cloud mining" services and thousands of competing "alt-coins" using the same hashing algorithm.
- It rubs me the wrong way to call it an "exploit" when 51% attacks are a core part of the way blockchains function.
- I'm surprised that the price for bitcoin gold isn't tanking. That's a sign that the crypto marketplace really isn't healthy right now, imo
- Conversely I'm surprised that this isn't causing a spike in coins that are more robust in regards to 51% attacks, like BTC and BURST (because they're both the majority coin in the realm of the resources they require)
Bitmain could do this to Bitcoin, but everybody knows where Bitmain is.
I guess this is why one would like proofs, and proglangs that can (to some extend) incorporate the proofs/laws so your code is checked against them.
So you may reverse one token, but you won't be able to reverse the other.
i.e. suppose you have $100 and I have 100 tokens (e.g. bitcoin gold coins). You pay me $100 and I give you the coins. I now double-spend and sell the coins to someone else. You now have no coins and no money. I then double-spend that and give the coins to myself.
You could at some point fix this and get the coins back, technically. But you're not going to get your $100 back. Nor is the other person. And the other person never got his coins. So both of you are out of money, and only one has the token. Theft occurred.
Moreover, even if you somehow both had the coins, they ought to be worthless because the entire system is completely useless. If a system can be compromised like this, the tokens have no value. Just like a dollar bill has no value if it can be printed, or can magically be transferred to a thief at the click of a button.
I used dollars in this example, but the more likely avenue of attack is for the attacker to sell his bitcoin gold for other cryptocurrencies like bitcoin over and over. Like selling an expensive bicycle to a customer but keeping the key to the lock, stealing it at night and selling it to someone else, a dozen times in the span of a few hours.
All of this is a major issue without even getting into the political discussion on forming a coalition and deciding which transactions were fair, genuine, worthy to keep, and which weren't. That's virtually impossible, particularly when there's one set of double-triple-quadruple-spent coins out there to distribute with many people making equal claims that they were scammed.
Seriously, the idea of smart contracts can truly be of value if attacks like this are no longer possible.
If it weren't so difficult and risky to sell this, it would be worth almost nothing already.
Double spending is just convincing the network you've sent coins to multiple places, and then undoing all of the transactions that were 'paying' for something (in this case paying for credits at an exchange).
The actual details of what they were doing matters and I don't know them, but it's almost certainly simpler to chain double spends together, one after the other, than to try and do three or more transactions concurrently then reverse most of them.
This achieves the same thing as a triple or quadruple spend but only necessitates reversing one transaction at a time.
"but the attacker was able to reverse transactions since they had majority control of the network."
I thought these crypto currencies didn't allow for reversing a transaction? Or is this "reversing" such as just deposit and then withdraw?
The purpose of mining is to solve a puzzle. In Bitcoin one solution is expected every 10 min on average. This can then be used store transactions on the blockchain in one block. To add to that block you need to solve a new puzzle and so on.
You can reverse transactions if you recalculate the puzzle solutions. This can take time but if you have more mining power than the rest of the network you can win this race. This is called a 51% attack.
So for example you deposit to an exchange and wait for that to confirm, in maybe 6 blocks. Meanwhile you create 7 blocks in secret yourself where you did not send to the exchange and release them to the world. The blockchain works by always considering the longest chain as the correct one, therefore overwriting or reversing the old transactions.
They send the money from their address to the exchange, the exchange credits that money.
Then they release their chain (that they have been building privately). This chain is taken as the consensus and accepted.
Why? Because it is the longest chain.
Why? Because it has had more than 50% of hashpower behind it, allowing it to add blocks faster than the current network.
Now the trick here is that because a single entity controls this new chain, they can just not include the transaction which happened between them and the exchange. So it a sense, it never happened. Yet, the exchange credited the account -- Thus the exchange account now has currency, and the original account has currency as well.
When you first connect to the Bitcoin network, how do you find out what the true blockchain is? You connect to other nodes and ask them. They may tell you anything. However, it's easy to verify whether a blockchain given in a response is valid. That is, it's easy to tell if a given blockchain is following all of the rules.
But what if you receive a few valid blockchains that are different from one another? Which one is the true blockchain for the world?
You simply choose the longest blockchain that you hear about.
Why the longest? It's the one that has had the most computing power focused on it. Anyone can compute a very small, self-serving, malicious blockchain of a few blocks. But to compute the longest blockchain in the world requires vast computing resources. The longest blockchain is supposed to be uncontrollable by any single party or network of colluders because it is supposed to be too hard to acquire the majority of the computing resources in the world.
Unfortunately, it looks like someone did just this and controlled >51% of all computing resources in the world dedicated to Bitcoin Gold. If you have enough resources, you can generate the longest blockchain in the world, add a self-serving transaction, get some goods or service in return, then recompute a new longest chain in the world where that transaction is no longer there. Everyone by default accepts the longest blockchain because it's supposed to be the most safe, but they are wrong.
I'm not well versed in the block chain tech but it is surprising that there is an inherent big ass monopoly type manipulation you can run ... inherent to the system.
That seems very much not what Bitcoin would "intend" and yet there it is, very available.
EOS mainnet launch is June 2nd, 9 days away. There's lots of code: https://github.com/EOSIO/eos
Check this cool demo out: https://eosauthority.com/space/
Secondly, the theoretical expectation was always that the value should go to 0. i.e., if parties can steal money whenever they want then the system is worthless.
Obviously there are parties who together form 100% of the mining power, same with 51% of the mining power. They need only come together and decide in order to steal. The only thing preventing this was a bit of game theory about how their coins and mining equipment would become worthless the moment they do this.
The fact that hasn't at all happened means they profited hard. And it means virtually any coin that has a set of investors with similar levels of disinterest is susceptible to these attacks.
My prediction is this: the first attack has little influence, even on bitcoin. It'll be cast aside as some mysterious accident, the theft won't be large and it'll be seen as insignificant, people will remain hopeful. When these attacks happen with some frequency, like once a month and at a large scale, then we'll see trust completely plummet and prices with it.
The second and more disturbing possibility being it is still good for money laundering cycles even if the actual suckers have cashed out. If money launders say maintain storefronts that give out digital goods of some sort the costs to themselves are minimal so they don't particularly care if someone gets a few megs downloaded for now invalid bitcoin.
Then again maybe everyone is just freaking out about the tether expansion...
That's why crypto is still in its infancy.
Bitcoin base value is comedy value .. ok.