Do you have an example?
Do you have an example?
1. https://eprint.iacr.org/2019/748.pdf 2. https://arxiv.org/pdf/1810.11605.pdf 3. https://eprint.iacr.org/2019/775.pdf 4. https://users.encs.concordia.ca/~clark/papers/2019_wtsc_fron... 5. http://homepages.cs.ncl.ac.uk/patrick.mccorry/minerbribery.p...
This one isn't an attack per se, it is mostly an exploration of arbitrage bots in decentralized exchanges running on Ethereum smart contracts. However, they point out that miners can trivially capture the value of the arbitrage transactions by front-running, and that this "free money" is like a bonus block subsidy that falls outside of the PoW consensus models:
6. https://arxiv.org/pdf/1904.05234.pdf
This one actually operates through transaction fees only, so it doesn't depend on smart contract functionality. However, it is waaaaay more expensive (for the attacker) than the others:
But more to the point: allowing smart contracts in a blockchain introduces all of the complexity of trying to make any other piece of software secure. Except... now it’s on a blockchain where the code is open source and mistakes can allow adversaries to steal money, not just data. How is this an improvement?
I think it’s great that more and more people are jumping in and learning what it’s like to develop in such an unforgiving domain (no point here, I just think it’s great!)
One of the ideas of PoW is that if you have enough money to bribe the miners, it's better for you to be a miner yourself. Is this the principle your examples weakens? I may have misinterpreted them.
It’s like... the people most interested in trustless collaboration are people who are untrustworthy. A trustless settlement layer seems fine, but any real human application is going to have an element of trust and doesn’t belong alongside settlement.