Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.
Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.
Sorry if this is confusing - the attack cost is calculated based on the cost of hashing power from NiceHash * the global hash rate. If the 'NiceHash-able' column is <100%, NiceHash doesn't have enough hashing power to complete an attack (and thus the price is greyed out).
This page [0] has more details.
> Using the prices NiceHash lists for different algorithms we are able to calculate how much it would cost to rent enough hashing power to match the current network hashing power for an hour. Nicehash does not have enough hashing power for most larger coins, so we also calculated what percentage of the needed hashing power is available from Nicehash.
Note that this ignores the fact that large mining operations could easily switch coins to carry out attacks.
50% chance spend 1.1 million get 1.1 million back minus substantial overhead. Say 10% overhead although I have no idea what the actual overhead would be. So negative 100k.
50% chance spend 1.1 million + 100k overhead get 1.6 million back. Net gain of 400k
So average gain of 200k assuming you can find a market to move that much bitcoin that quickly and always assuming your creativity isn't rewarded with jail time.
People with substantial resources can find way to make money that are repeatable and don't involve finding new and exciting ways to go to jail.
To actually steal money you need to falsify at least six blocks, which in turn means you need to mine six blocks in a row (roughly speaking). The probability of this being successful is (1.0-0.51)^6 - ie. about 1.5% chance of being successful. You can increase your chances by increasing your mining percentage. Make it a 75% attack and you have an 18% chance of success. To have a 50/50 chance of success you really need to mount about a 90% attack which is pretty ambitious.
I'm not sure this is accurate. You don't need to mine 6 blocks in a row on the existing chain. Clients are programmed to recognize the longest chain, so you just need to silently mine new blocks (and not share them with anyone) until you have more blocks than the main chain. Then publish these new blocks, and existing clients will recognize your chain of blocks as being the correct ones.
You can double spend by making a transaction on the public chain while you quietly mine your own blocks on your private chain. Send the coins to an exchange on the public chain, but send them to your own address on your unpublished chain. After you steal funds from the exchange, publish your privately mined blocks.
Therefore, if our malicious miner identifies that they have had poor luck and begun to fall behind the "legitimate" chain by a block or two they can start the make-a-longer-competing-chain process over again from the legitimate head with -as far as I can see- no downsides except for some lost time/resources; the main risk to them isn't really there until they commit by initiating their double-spend, something they would almost surely not do until they're confident they've acquired their own, longer competitor to the "legitimate" chain.
This drops to zero every time they start over, so it doesn't change the basic calculus.
The chain starts at block 1000, and you make a spend that will be included at block 1001 on the public chain. At the same time, you start mining your private chain from block 1000 (and you don't include that transaction in it). Now, the exchange you're using requires 6 blocks of confirmation, so you need to wait until block 1006 on the public chain before you can actually take delivery. Now that you've done that, you can publish your private chain at block 1007 (or 1008, etc) and since it's the longest chain, it'll be accepted by the public.
You didn't have to get 6 blocks before the public chain got 1 - you only needed to get 1 more block than the public chain, at some point after the public chain has mined 6 more blocks.
1000 - 1001 - 1002 - 1003 - 1004 - 1005 - 1006 1008 Public Chain
\ 1001 - 1002 - 1003 - 1004 - 1005 - 1006 - 1007 / Private ChainWe're saying the same thing, but I see now that this was unclear.
The point of this sub-thread is that 51% doesn't give you a guarantee you'll mine faster than the 49%, just an edge, and that edge narrows as more blocks are required.
A casino with a 1% house advantage would have days when it was in the red, around 178 of them in fact. By analogy, you need to line up six days in the black, in a row.
The chance of doing that is lower than 51%.
You're focused on the chance of getting 6 in a row. But what you should be looking at is the chance of getting at least 7 in 13, which is given by this equation:
P(K>=N) = sum(nCr(M, k) * p^k * (1-p)^(M-k)) from k=N to M
With M=13, N=7 and p=.51 - which works out to about 53%. But 8 in 15 also works, 9 in 17, etc. The limit of that probability (n+1 in 2n+1 as n -> inf) is 1.
Also, a casino is not likely to have many days in the red, just like it won't have many years in the red. (for bets only, ignoring everything else) This is because while the chance on any one bet may only be 51%, the chance of 10,000 bets, or 1,000,000 bets having a majority go south starts to get very, very small. (~27.5% for 1000 bets, ~2.5% for 10,000 bets at 51%, etc)
However, after the attack wouldn't it be easy to compare both chains and see which coins were double spent? Wouldn't you obviously be the perpetrator, having both double spent, as well as having cashed out a large amount of money? Or is the idea that you'd be able to cash out to a bank account not tied to your real identity?
Then spend and/or clean your ill-gotten gains.
* Swap coin for Zcash and start mining with 51%. * Wait until your chain is longer than the main chain, and you actually hold the Zcash. * Publish the longer chain, and immediately swap your spent coin for Zcash again. (At a different exchange just to be sure).
Now, you got twice the value of Zcash you needed, and due to Zcash shielded transactions can't be traced. You just have to hope that your shenanigans won't tank the value of Zcash.
Similar things could be done with Monero.