So, your transaction will be confirmed in the next block mined by one of the other 49% of miners. Big whoop.
So, your transaction will be confirmed in the next block mined by one of the other 49% of miners. Big whoop.
At any point there is still a 49% chance the next block will be mined by a good guy.
If the bad guys decide not to accept the good guys' blocks, then they are hard forking Bitcoin and will end up just like Bitcoin Cash: irrelevant.
This is the exact problem PoW was designed to solve, and it works very well, which is why a 51% attack has never succeeded or even been attempted against Bitcoin, and never will.
The 51% attack is not some made up thing.
The only way they can maintain that chain is by a hard fork.
So after a time, they are behind and have to jump to the other chain and ignore their own old blocks. Something like this graph:
Censored blocks: -
Uncensored Fork blocks: \
Uncensored Normal blocks: *
Censored: *--------------------------
Uncensored: \** \* \*** \** \*It doesn't matter if it's a 90% attack. The minority miners are constantly receiving and using the majority's blocks. So it is not 66% vs. 33%, or 90% vs. 10%; it is 60% vs. 100% and 90% vs. 100%.
All it takes is for the less-restrictive minority to mine two blocks in a row and they've permanently outpaced the majority's more restrictive chain.
They can use the majority blocks at the cost of discarding their earlier blocks. Every time they accept a block from the majority, they undo all the work they had done earlier.
> All it takes is for the less-restrictive minority to mine two blocks in a row and they've permanently outpaced the majority's more restrictive chain.
All it takes then is for the majority to mine three blocks in a row. The probability is always on their side.
If that's what it comes down to (and there is reason to believe it won't), I imagine sanction addresses will still transact, just with higher latency and at higher cost than others.
Assuming enough hash rate and the exchanges (and the users) agree to ignore the "sactioned" transactions, then they will never be in the main chain, not even slowly.
Also just noting that while the conversation here is about Ethereum, you are describing the fork rules of Bitcoin. Next month the concept "hash rate" won't exist on ETH mainnet (potentially depending on who you ask; looks like there might be an ETC2).
1) The hash of the old block.
2) The new transactions.
3) A number that must be bruteforced until you get a hash of all the block with a lot of zeros.
If you try to copy one block in the other chain/fork, then the hash of the previos block is invalid. If you change just that part of the block, you must bruteforce a new number until you get a new hash of all the block with a lot of zeros, that has the same cost of creating a new block from scratch.
You can copy the info of the transactions from one chain to the other, but you must create a new block to put them. You can't just copy the block.
Okay, I think I see now where I was separately wrong and partially wrong in the previous comments. When I said there's a huge monetary upside to a 51% attack, that's wrong. There's not really any upside to speak of, especially considering the huge amount of computing resources you would need to do it.
So it's not surprising it hasn't been tried yet, and that's not a proof that it's a canard as I said before (but it's not a proof of the opposite, either). Absence of evidence does not imply evidence of absence. So I'll concede and leave that point alone. I was wrong.
---
Now, when I said that the 49% can still use the 51%'s blocks, that's not entirely correct. It's correct only until the blockchain splits, then it's not correct. So my position wasn't entirely correct, but it still has value to this discussion. Let me illustrate with a randomly-generated timeline.
Let's make it easy and say 66% are censoring miners, and 33% are non-censoring miners.
We haven't discussed this yet, but let's also assume that the exchanges and non-mining users reflect this proportion. This is an unfounded assumption. But I'm steelmanning.
The 33% are in miner pool 1, and the 66% are in miner pool 2 and 3. The dots represent 5-minute intervals. Just like in Bitcoin, a block is mined roughly once every 20 minutes. Observe the moment at "X".
..3..........2...X1.3......1...1..........2......2..
At this point, the blockchain looks like this. 100% 3--2
You might ask, "Why is it not forked at this point? Miner pools 3 and 2 are the malicious actors, and they had two blocks in a row." Because 1 has no reason to fork. All previous blocks are valid according to Miner pool 1.Now, observe the point at X:
..3..........2....1X3......1...1.......X..2......2..
At this point, the blockchain has forked. It looks like this. 66% 3--2
33% 3--2--1
Notice, 33% has the longer chain, but the 66% do not accept the 33%'s block because it contains censored transactions, so a re-org does not occur. This situation will continue as long as the 33% chain is equal to or longer than the 66%, which could be a while.But how can that be possible if the 66% has more hashpower?
Observe the point at X:
..3..........2....1.3X.....1...1..........2......2..
Chains: 66% 3--2--3
33% 3--2--1
They are equal. No re-org happens.One should question at this point what's going on in the mempool here? One can assume the 66% censoring miners are not transmitting the censored transactions to the mempool. But how many censored transactions are we talking about? How much of a fee is each side collecting? Is this still in the coinbase reward era or after? Are the 33% smart enough to route around the 66%? Or punish them by kicking them off the mempool? Not sure. All of these variables can mitigate this attack. But I will not explore that now.
Although there are now two rival chains, for simplicity's sake, lets just assume the same timeline holds, and remove each of the two side's blocks from the other's chain starting from at the time of the fork.
66% ..3..........2....1.3.....................2......2..
33% ..3..........2....1........1...1....................
Now, observe the point at X: 66% ..3..........2....1.3.....................2......2.X
33% ..3..........2....1........1...1...................X
Chains: 66% 3--2--3--2--2
33% 3--2--1--1--1
3 hours later, the 66% still have not overtaken the 33%.One should wonder even more, what is going on in the mempool and ~$250B Bitcoin economy during this time?
In this example, only two blocks by the 33% are mined consecutively. What about 3 or 4? Could it be days before the 66% overtakes the 33%? I think it's possible.
On the other hand, the mining of consecutive blocks by the 66% does not create a contention between the two sides. So all miners are unified until the 33% gain an advantage. This is my point.
From the POV of the censored Bitcoin transactions, the 66% will succeed in censoring them until the issue is resolved. But I don't think you can say that the 66% have control of the network at this point. They've only succeeded in disrupting the network until more non-censoring miners come online, or something else happens.
Consider also that the attacker has to either possess 66% of all computing power devoted to Bitcoin in the known universe OR an incentive more attractive than the BTC block incentive for the operators of 66% of miners. Even for 51%, that's an impressive achievement.
It's a very interesting scenario but I still say it does not constitute a credible threat to Bitcoin. More of a thought experiment.
66% ..3..........2....1.3.....................2......2.X
33% ..3..........2....1........1...1...................X
but that's closer to a 50%-50% split of the miners, not a 66%-33%.The problem is that 2 and 3 will produce the double of blocks. For e while 1 may tie or get ahead, but after 30 blocks the the 23 fork will almost always be like 10 blocks ahead of the only 1 fork.
Ignoring most of the . to make the graph shorter
66% 3213...223.3223..23.23.323..3.2223
33% 321.11....1....11..1..1...11.1....
or looking at each chain 66% 32132233223232332332223
33% 3211111111111
After a while, 1 canA) Give up and start mining censored blocks
B) Start a new fork, from the current 2-3 chain with many censored blocks
C) Declare that they are a fork and convince the exchanges to give them a new moniker, like ETC of BXC
D) Convince the exchanges that they are the real chain in spite they are shorter, and convince the exchanges to give the other chain a new moniker.
Let's say that MiningPoolA controls 51% of hashpower, and MiningPoolB controls 49%. MiningPoolA is refusing to mine transactions from/to some wallet W.
Time T1:
MiningPoolA: OldChain -- Block1(no W)
MiningPoolB: OldChain -- Block1'(W receives 1BTC) still in progress
Any client will accept the chain with Block1 (no transactions from/to W)
Time T2 - if MiningPoolB tries to compete
MiningPoolA: OldChain -- Block1(no W) -- Block2 (no W)
MiningPoolB: OldChain -- Block1'(W receives 1BTC) -- Block2' (parent=Block1') still in progress
Any client will accept the chain with Block1 (no transactions from/to W), and MiningPoolB will never be able to catch up
Time T2 - if MiningPoolB decides to accept MiningPoolA's chain, but add the transaction in the second block:
MiningPoolA: OldChain -- Block1(no W) -- Block2 (no W)
MiningPoolB: OldChain -- Block1(no W) -- Block2' (parent=Block1, adds transaction W receives 1BTC) still in progress
Any client will accept the chain with Block1 (no transactions from/to W), and MiningPoolB will never be able to catch up
If a mining pool had 51+% of hashpower, they would always be mining the longest chain, no one would be able to compete with them and publish another block (in principle, at least; in practice, since mining is not entirely deterministic, someone else will occasionally win the lottery and propose a new block faster).The 51% chain is mined with 51% of the total mining power, while the 49% chain will contain 100% of the mining power (as the 49% miners are more than happy to build off the 51% chain, while the 51% miners will only building off the chain without the censored transactions).
They are correct in asserting that a 51% attack to censor transaction is largely just a nuisance to the users and that all transactions should eventually end up on the longest chain (the 49%).
Each miner takes a bunch of transactions and chooses a previous block B1 to build on, then starts hashing. If some other minerB advertises a new block B2 based on B1 that includes different transactions before minerA, then minerA can throw away all the work it did, and start from scratch on B3 based on B2. But minerB will probably already be working on its own B3 - and has every chance to win again.
I will not go into depth here but it's a commonly held view that this changes under PoS. Just flying by so hopefully sources are easily located
The only way 51% of miners can fork the blockchain and actually overtake the other 49% with more restrictive rules is if they have a hidden nuclear reactor dedicated to mining Bitcoin that produces hashpower equal or more than 49% of the network and they flip it on at the moment they fork.
Again, it doesn't matter how many people are convinced a 51% attack is possible on Bitcoin. It's never even been tried once. So the burden of proof is on you all. I'm just trying to help explain why this concept has never been proven.
If the 51% can ignore the blocks from the 49%, then why does it matter what the 49% is doing?
Occasionally the 49% will be able to mine a block and temporarily create the longest chain, but the 51% can always just ignore that block and continue mining off of the one before it - eventually their chain will be the longest and the block(s) from the 49% will be lost.
Really this isn't theoretical, it happens all the time by accident when two blocks get mined off of the same previous block. When that happens one of the two blocks gets lost, and the only difference with this scenario is that the 51% have enough hash power to ensure that their blocks are the ones that always (eventually) win and the 49% blocks are always lost.
The other 49% are still incorporating the 51%'s blocks in their work. There is no way 51% of miners can stay ahead of the combined hashpower of the entire Bitcoin mining population.
It's not that simple. That block from the 49% will be ignored by the 51% (since it contains "banned" transactions), which will continue the chain on the previous block (the "51% chain". Now the 49% has two options. If they continue to build the chain on top of that 49% block (the "49% chain"), after a while the 51% chain will be longer (because that side has the most hash power). The other option is to build again on top of the 51% chain, as you suggested (and AFAIK that's what unmodified Bitcoin software will do after a while); but to do that, they have to discard that block they had included earlier (since it's not in the 51% chain).
That is: yes, the 49% can include "banned" transactions, but that inclusion will be undone later. They can include these transactions again, but that inclusion will be undone again. They can never get far enough for these blocks with the "banned" transactions to be permanent.
> Again, a 51% attack has never even been attempted on the Bitcoin network despite huge potential monetary upside if it succeeds.
First, this is not the "traditional" 51% attack, which involves mining an alternative longer chain in secret. Second, the most a 51% attack can do is double spend coins (or prevent them from being spent); converting that into real money requires spending the coin twice (for instance, sending coins to an exchange, withdrawing the resulting money, and then undoing the sending to the exchange so the attacker keeps the coins), and the monetary upside isn't that big in most scenarios. Third, the cost for doing that is not as small as you're thinking (start with the cost to obtain enough miners to have 51% of the hash power), which is why it hasn't AFAIK been attempted on Bitcoin (but AFAIK, it has been attempted on less popular networks which have small total hash power). And if you fail the attack, you have wasted all that cost.
As soon as the chain diverges, they are seperate chains.
Yes, if you have a minority of the hashpower, you can hardfork yourself off the main chain, and continue to follow your smaller chain, regardless.
But you don't get a longer chain than the main one. So you'd continuously be behind, and would not get the work of the main chain, and likely most exchanges would not accept your smaller fork coin, and you would end up like bitcoin cash.
They can also prevent you from getting your transaction in ever. The 49% cannot prevent this because they cannot make a longer chain, that is the entire point of proof-of-work.
What you do is this:
- spend btc with a transaction and get it included in the chain.
- start mining blocks starting from before your transaction in secret
- include a trnasaction to a different address in the secret chain
- broadcast the secret chain once it's longer than the "official" one
- since your chain is longer, your chain is now the official one. All the transactions in the other chain are now discarded
Here an attacker controlling 51% of mining power decides to not play by the rules; we are considering what that means for everybody else. For Bitcoin it means they can block transactions forever, and they can double-spend.
Obviously if the attacker plays by the rules there is no attack.
The Bitcoin blockchain constantly "forks" for the latest 1-2 blocks. If you sell your car for BTC and hand over the car the moment you see the latest block contains the transaction where the BTC enters your wallet, you may see 1h later that the longest chain does NOT contain your transaction, and in fact your transaction is now invalid, because the buyer wallet has sent all the money somewhere else.