Live data from Hacker News

Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

ccn.com

221–230 of 555 posts

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#221
post #163
post #148

So this would require an attacker to pay into the exchange with BTCg, have the deposit clear and approve for trading, trade it for another currency, and have that trade settle and be clear for withdrawal, and then process the withdrawal, all in under 4 hours. After which point the attacking miner surfaces a longer chain they had been keeping which doesn’t include the original BTCg deposit. Alternatively, if the excha…

Many people use exchanges for arbitrage. Exchanges benefit from arbitrage since they take a fee out of every trade and because they want their prices to be close to the international price of the asset. This trade would look exactly the same as an arbitrage move.

I still maintain that letting the assets come in and leave on a different blockchain within 24 hours is akin to a “RTFM” level mistake.

If exchanges are enticing arbitrage through insanely quick setttlement and clearance times on the order of 2 hours after closing a position, they are just playing with fire.

If there wasn’t an actual trade, just transfering in and out, not chaining the transactions is similarly RTFM.

If the facts are as I understand them, I think the exchange bears a significant portion of the blame.

It’s like the story a couple weeks ago where Deutche Bank accidentally approved a wire transfer for $35 billion dollars.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#222

Earlier quoted context omitted.

The second layer solutions such as Lightning Network don't require you letting other people hold your Bitcoin. They're still decentralized and trustless.

But they also require observation for cheating because time matters in the execution of contract settlement when you have bad actors. It is still trustless though.

You've always had to protect against cheating though; what's changed? The standard advice from as far back as I can remember is to wait six confirmations on transactions, more for big transactions, and 120 for freshly minted coins.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#223
post #196

Earlier quoted context omitted.

Assuming you want to make money directly, sure. If you want to harm a community in which the currency is widely used, the incentives are different.

What kind of incentive does the attacker have to just harm a community of a distributed system?

Just to say they did it.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#224
To me, this shows how Bitcoin type cryptocurrency mining incentives line up. For good actors, there is little to no incentive to seek 51% capacity whereas there is a lot of incentive for bad actors to seek it. As an economic activity, the logic of ruthless competition makes double spend capability the holy grail. Double spend is the sole reward for 51% capacity.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#225
post #44

Earlier quoted context omitted.

Would you ask the same question if the world run 100% on renewables? If not, it seems that your argument should be "we should accelerate our transition to renewables" instead of "bitcoin spends too much power". Also they pay for all the energy they spend so what exactly is the problem? Do you see vegans complain for the resources spent to raise animals?

This is a fairly good point. Any argument about externalities in energy usage applies to all usages of energy, and the solution is to internalize them in the price of energy.

What a great idea. All you'd need is a centralized world government to enforce it, and then you can have a responsible, decentralized currency! Wait.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#226

Earlier quoted context omitted.

It probably cost a few billion dollars to build all those banks globally. It costs a few hundred million to maintain all those banks and vaults. However, these banks and vaults can handle more than 2000x the transactions of Bitcoin in a single day (Visa on its own is 750x the capacity of Bitcoin, and Mastercard handles about twice the number of transactions as Visa), so Bitcoin would need to be at least 1/2000th the…

Fort Knox has an entire military base to secure it. That alone would use up a good chunk of your few hundred million dollar budget. I think you are vastly underestimating the cost in supporting our current financial system.

These have to do with storing something of value, they aren't inherent to gold. People are already storing Bitcoin keys in physical vaults: https://www.bloomberg.com/news/articles/2018-05-09/bunkers-f...

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#227

Earlier quoted context omitted.

It could be argued that the trust could still be misplaced, but the idea that we can't trust governments for currency is barking up the wrong tree. The fundamental problems of inequality don't stem from Treasury, but rather from the game theory concept of the https://en.wikipedia.org/wiki/Gambler%27s_ruin making barriers to entry for new players always higher than the incumbents. You can take this all the way down to…

The same people arguing for trusting the Government for currency (the people that say "wasting electricity") are the same people that are also trusting the Government to solve the climate problem. They have obviously failed at the latter - no price on carbon, which ironically would resolve their complaint about the former since "wasting electricity" is code for "contributing to climate change" which is . not priced i…

Sort of. It does create an opportunity cost, in diverting electricity away from other, arguably more useful causes. The whole matter there is complicated by economies of scale and baseload demand etc though. It could also be seen in terms of finiteness of the source of energy.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#228

When Bitcoin was running up to $20,000, I tried to analyze the system and come to a personal conclusion about its equilibrium value, because I didn't want to miss out if it really was the currency of the future. I ended up not investing, because of the possibility of a double-spend attack. I think that cryptocurrency enthusiasts are seriously underestimating the importance of double-spending attacks to the economics…

Interesting points. A defense against this type of attack is to use at least the hybrid proof-of-stake design that Ethereum is rolling out in about three months; blocks are proposed by proof of work, but proof of stake periodically adds a layer of "economic finality." Here's a paper: https://arxiv.org/abs/1710.09437

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#229
post #140

Earlier quoted context omitted.

Even finding a single double spend attack that only double-spends 1 satoshi would be enough to destroy bitcoin.

No it would not. Finding a BTC double spend attack vector would be like finding a 0-day: good and maybe even profitable up until fixed, which would take hours, days at most. Have 0-days destroyed Microsoft, Android, Firefox, Electron or Chrome?

Microsoft, Android, Firefox, Electron and Chrome aren't currencies.

They have an underlying value/utility. People have a real, tangible need _outside of the use of those products_ to get them fixed. Can you say the same for a cryptocurrency?

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#230
post #216

Oddly enough, one of the selling points of Bitcoin Gold (a hard fork of Bitcoin) was its use of Equihash instead of SHA-256. The idea was that a memory-hard proof-of-work function would inoculate Bitcoin Gold from miner centralization. The problem with mining centralization is that sufficiently powerful miners can attack the network by rewriting blocks. This opens the door to double spending. This was exactly the att…

> It's possible that any altcoin that becomes sufficiently valuable will suffer similar attacks to the ones that have now taken place on Verge and Bitcoin Gold.

The trust in these systems seems to be based on proving a negative.

The lack of an attack is neither a proof of robustness nor proof that one or more zero days aren’t already known. We can only “know” it’s safe when the temptation to use an exploit is far too high to resist.

I think there are a lot of people who imagine “an attack” as a ready-aim-fire affair. There’s a juicy target, someone concocts a plan and then uses it.

But as you illustrate, maybe there is already a plan and someone is waiting for the target to get juicy enough. Aim, ready, fire.

Post reply on HN