Leaf-Node Weakness in Bitcoin Merkle Tree Design
bitslog.wordpress.com
bitslog.wordpress.com
Anyway, not many SPV clients actually exist these days - instead it's much more common for "lite" wallets to actually use trusted servers.
Does this mean that this exploit only has value to an attacker who is already capable of sustaining a 51% attack?
Disclaimer: he co-founded one of my companies.