Cost of a 51% Attack for Different Cryptocurrencies
crypto51.app
crypto51.app
The "1h Attack Cost" is calculated from the rentable hashrate from NiceHash, but you should pay attention to the "NiceHash-able" column that says how much hash you can actually rent.
While you'd think you could attack Ethereum for only 1.5 million dollars, you can only rent 7% of that hashrate, so you can't get the required >50% you'd need to pull of the attack.
Perhaps I misunderstand the table in the article or the impact of a 51% attack however.
This is why a reasonable size of the state, to allow many many to have affordable nodes which validate and check the rules, is so important. These are not the so-called miners, yet they are critical for the integrity of these distributed systems for preventing nation-state attacks.
Is this 7% per customer or aggregate per blockchain? Ie could I set up a dozen or so companies to each have a few percent of NiceHash and obtain the 51% that way?
Vitalik Buterin just explained that a few days ago and provided that number.
So I'm very sceptical of these numbers on that website or I'm not able parse what it tries to say.
Sounds like any other IT project!
(I think there are other things that are misleading, notably that it measures what Nicehash could do, but not all of its capacity is actually for rent at any given time.)
This is the Proof of Stake Ethereum explorer. There is over 5 M ETH staked at thr moment which gives the value given above at current market prices.
In truth, that's more of a lower bound because you would have to buy that same amount of ETH in the market which would raise the price.
Additionally, Ethereum's PoS algorithm contains slashing penalties that are used to burn the ETH of an attacker. So a 51% attack may occur once, the attacker then gets slashed, loses his stake and the chain continues without the attacker's stake. Read further: https://cointelegraph.com/news/vitalik-buterin-reveals-why-a...
Just curious, do we have an idea of how much Buterin himself holds?
I wonder how he sleeps at night, given how juicy he is as a target for organized crime and North Korea. $1B + the benefit you'd get from shorting ethereum just before selling (and the collapse that would follow), sounds really appealing.
The 51% attacks only allow double spend attacks, you can't "steal" money and the attacks sooner or later will be noticed and might be reversed.
Then even if you run a 51% attack it's still a crime in more or less any country and controlling 51% of hashing power and staying truly anonymous isn't easy, given how much electricity and hardware PoW consumes. (But it's viable, through maybe only if you are state backed.)
The most feasible way to pull of a 51% attack on a larger network IMHO is by hacking multiple hashing pools.
Through like the article mentions it's a completely different thing for smaller networks. It also shows nicely why you need increasingly more hashing power the more value moves through your network (it's a counter argument to people defending PoW by saying you could just do more transactions per block).
It's also why some new chains which use PoS start out with "a farming game" where people already "stack" money before the crypto currency is worth any money (and get money based on that when "it goes live"). Because with that you can start with a already reasonable secure system.
> I'm not able parse what it tries to say.
1. Small crypto currencies are not so secure (if not build on another chain).
2. PoW is not as grate as some people make it out to be (IMHO PoW a terribly solution but it probably was the best terrible solution when Bitcoin was made).
3. And I would add: PoW based Currencies hashing cost and marked value needs to be in balance. (For PoS it's the stacked amount and marked value, which is IMHO easier to archive as it doesn't require additional factors like access to hardware and cheap electricity.)
So you'd have to buy the equipment, which is a gradual process, would be extremely expensive and would be noticed.
Indeed, back-of-the-napkin calculation with an order randomly picked from NiceHash[1] for Bitcoin mining and the same methodology gives:
Cost (PH/HR): 0.0002625 BTC
Bitcoin Network Hashrate (PH/HR): 9M
51% attack for one hour: 4.6M PH => 4.6M * 0.0002625 ~= 1200 BTC
So a one-hour long 51% on the bitcoin network would cost $43,200,000 at $36K per BTC, as per a NiceHash rate I randomly selected.
You real costs are going to be much higher, it would probably take you more than an hour to spin it all up and execute the attack. I feel realistic number is 10x to 100x higher
Out of interest why aren’t these attacks more common? (Not even for profit, even just for bragging rights)
Edit(s): need more coffee.
FWIW, I expect most exchanges to grind to a complete halt upon noticing this much chain reorganization (enough to break their finalization assumptions) and so the entire ecosystem would have to sit around and figure out what to do manually, with different participants having noticed at different moments and with different losses due to already-spent debts... it would be a complete mess to repair.
Or would you somehow rebuild those honest transactions? (I assume you can’t because of the chain). It’s pretty worrying if a 51% attack could happen, any transactions happening at the same time could be reverted, especially because there is no dispute resolution or guarantee that the person you traded with will resend the funds.
It assumes you can rent this capacity via NiceHash, but the whole point of a 51% attack is to run _different code_ on the majority of nodes.
Surely NiceHash would rent you capacity running the vanilla e.g. Ethereum code, rather than your fork?
To assume otherwise basically makes NiceHash remote code execution as a service.
Just because people try to be decoupled from the government doesn't mean laws don't apply to them.
Also as a side not operating a mixer without taking protocol about who used it when in which way is pretty clear cut money laundering. Hence why mixers are either exchanges which take your personalities or operated as much anonymous as possible and from countries in which they believe they can avoid the law. (EDIT: Yes there probably are people which operate a mixer without such precautions, and they might end up pretty bad if a country purses money laundering charges and it doesn't even need to be their country.)
Note that the attack cost does not include the block rewards that the miner will receive for mining. In some cases this can be quite significant, and reduce the attack cost by up to 80%."
And it's kinda scary that coins that claim to have millions of dollars in market cap can be attacked for a price of a sandwich.
However its is stunning: Ethereum market cap $313.09 B ( yes with a B ), and you can pull off a 51% Attack for 1.5 million dollars ?
Litecoin market cap $12.51 B and you can pull off a 51% Attack for 250 thousand dollars ?
It seems Vitalik Buterin gives frequent interviews. Anybody aware if has been asked about this ?
Can any of you with comment on the technical validity of this info. Because frankly, if this all it takes, I am tempted :-)
For example with most cryptocurrencies even with an 51% attack you can't change "from who", "to who" (destination) and also not the "sending amount".
Requirement:
- most (or enough) people do run a validating node (and not just a SPV wallet)
=> That is why Bitcoin proponents to insist so much on keeping the main blockchain small and therefore secure (other solutions like lightning, ... can then be level 2 built on the secure layer. But without secure layer 1, you have nothing secure to begin with / built less upon... like less decentralised but more scalable solutions)
You could 51% for an hour (maybe, if you can get that hash rate from nicehash for that long, but I doubt you actually can), but what happens at the end of that hour? Would everyone simply throw their hands up, allow your double spend, and keep mining your chain? Likely not.
Andreas Antonopoulos has a good take on this for Bitcoin: https://youtu.be/ncPyMUfNyVM
In the same time preiod we have seen mutiple hacks again banks, governments and the military.
The proof is in the pudding