Live data from Hacker News

Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

ccn.com

301–310 of 555 posts

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#301

Earlier quoted context omitted.

I think the argument is that by doing a 51% attack you undermine the market value so you never get the rewards. This makes sense, but only for the leading crypto coin. As we see here today, you can 51% attack smaller coins, which should imply an increase in the value of Bitcoin from consolidation.

The spooky thing that this made me realize, is that if anyone did find a vulnerability in bitcoin (or any cryptocurrency) is that they would have a greater incentive to only slowly leech off the system, because they will be able to siphon out much more over time than if everyone panics over security. The weapon is no good unless it's secret.

My assessment is that the greatest vulnerability in Bitcoin is its breathless supporters, who will look past the dynamics of Bitcoin in adoration of the mechanics of Bitcoin. To that end, larger, more sophisticated enterprises (banks, hedge funds, etc) are likely leeching slowly off the system, propping the price up and inflating it when they can, so they can extract as much value as possible out of its correction to a value commensurate to its utility. Every other technical vulnerability, notional or demonstrated, is at least an order of magnitude harder to exploit.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#302
post #279

Is there a laymans explination for this attack? "but the attacker was able to reverse transactions since they had majority control of the network." I thought these crypto currencies didn't allow for reversing a transaction? Or is this "reversing" such as just deposit and then withdraw?

Someone please correct me, but here's my best explanation.

When you first connect to the Bitcoin network, how do you find out what the true blockchain is? You connect to other nodes and ask them. They may tell you anything. However, it's easy to verify whether a blockchain given in a response is valid. That is, it's easy to tell if a given blockchain is following all of the rules.

But what if you receive a few valid blockchains that are different from one another? Which one is the true blockchain for the world?

You simply choose the longest blockchain that you hear about.

Why the longest? It's the one that has had the most computing power focused on it. Anyone can compute a very small, self-serving, malicious blockchain of a few blocks. But to compute the longest blockchain in the world requires vast computing resources. The longest blockchain is supposed to be uncontrollable by any single party or network of colluders because it is supposed to be too hard to acquire the majority of the computing resources in the world.

Unfortunately, it looks like someone did just this and controlled >51% of all computing resources in the world dedicated to Bitcoin Gold. If you have enough resources, you can generate the longest blockchain in the world, add a self-serving transaction, get some goods or service in return, then recompute a new longest chain in the world where that transaction is no longer there. Everyone by default accepts the longest blockchain because it's supposed to be the most safe, but they are wrong.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#303
post #216

Oddly enough, one of the selling points of Bitcoin Gold (a hard fork of Bitcoin) was its use of Equihash instead of SHA-256. The idea was that a memory-hard proof-of-work function would inoculate Bitcoin Gold from miner centralization. The problem with mining centralization is that sufficiently powerful miners can attack the network by rewriting blocks. This opens the door to double spending. This was exactly the att…

The problem I think is that there are 25 cryptocurrencies bigger than it. Particularly with its form of mining, it's trivially easy for say a big player in the 10th largest currency to shift their mining power to a smaller one like Bitcoin Gold, overpowering everything else. Normally the non-51% attack argument is that anyone who invests enough in 51% of the infrastructure and has sufficient coins to profit from doub…

You're forgetting that the lower you go with a cryptocurrency the less volume it has. This will have a major effect on your profits.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#304

When Bitcoin was running up to $20,000, I tried to analyze the system and come to a personal conclusion about its equilibrium value, because I didn't want to miss out if it really was the currency of the future. I ended up not investing, because of the possibility of a double-spend attack. I think that cryptocurrency enthusiasts are seriously underestimating the importance of double-spending attacks to the economics…

By the way doesn’t your argument also destroy anarcho capitalist utopia scenarios?

Someone could rent the local courts for a week, pillage everyone, and leave.

Or just come with a larger army.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#306
post #55

Crypto currencies are worthless unless they have an enormous amount of hashing power behind them. We could really do with a webpage with a list of crypto currencies, the hashing power currently behind them, and how much it would cost somebody to take over 50% of the network. Or does that already exist?

> Crypto currencies are worthless unless they have an enormous amount of hashing power behind them. Why would you think an enormous amount of hashing power helps? Even with Bitcoin, the actual marginal cost of a 51% attack is quite low. The difficulty is the capital expense of actually connecting to a couple GW of power and finding enough rentable ASICs. I think this is fundamental. In a proof-of-work scheme, if the…

You're looking at this as a static _binary_ model, while actually, the 51% attack is heavily dynamic. The profitability of the attack heavily depends on factors that are absolutely dynamic and not publicly available:

- The exchange/betting website not catching onto your scheme

- The volume of the coin being enough to mass sell it and not majorly affect the price

- How fast the community can act in unison against you

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#307
post #72

Earlier quoted context omitted.

So, that's an interesting pair of ideas, in that it gets me thinking that any Bitcoin-style cryptocurrency might ultimately be doomed by its own design. Shooting from the hip: They've go this 51% vulnerability that is well known and hypothetically cannot be truly closed. Instead, we rely on the idea that mounting such an attack would be "too expensive". But at the same time, the cost/benefit of mounting such an attac…

> all you really need to know is the cost to get to 51% and stay there for a given amount of time That's actually, if anything, underestimating the likelihood of a 51% attack. It seems that the more likely path to that situation is collusion between segments of the existing mining community. For such a cartel, the "cost" is zero, it's just a matter of trust.

The cost of creating and upholding a cartel is not zero at all. It can actually be quite high.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#308
post #175

Earlier quoted context omitted.

> If the exchange is aware of the attack, they may also freeze his account, so that all the funds will be locked inside the Exchange. A failed 21 block attack performed with a 10,000 BTG deposit where the Exchange freezes the account in time will result in a 10,262.5 BTG loss for the attacker. (From link.) That sounds problematic. If I deposited coins and the exchange determined I was attacking them (how does that wo…

Not only that, but also an attacker can wait until the money is "safe" outside the exchange before revealing the attack. If the attacker really has more than half of the hash rate, there's no time limit; the malicious chain will always be longer than the innocent one.

This introduces the "time" component of the attack increasing its riskiness. The longer you wait until releasing the chain, the more time there is for events to happen that might completely thwart your attack.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#309
post #286

Earlier quoted context omitted.

Microsoft, Android, Firefox, Electron and Chrome aren't currencies. They have an underlying value/utility. People have a real, tangible need _outside of the use of those products_ to get them fixed. Can you say the same for a cryptocurrency?

yes?

What is the value of currency you can legally print on any printer?

Zero.

Edit: any crypto-currency you can exploit gives you option to print yourself money.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#310
post #167
post #161

Earlier quoted context omitted.

So it's ok if your currency becomes unreliable for many hours? It would immediately negate the trust of what happened during that period of time, affecting the trust of any balance in participating addresses.

If Visa or SEPA got hacked over 12 hours and then fixed the root cause, would you stop using credit cards or bank transfers altogether? I would not.

Credit Card companies and banks can reverse the transactions, so long as they keep track of things in batches, have strong backup system for their ledgers. So long as they're not SWIFT transactions that leave the country, and the country that's attacked as a strong/regulated inter-bank transfer system.

If a bank is critically hit so bad funds become impossible to correctly attribute to people (Fight Club type unrealistic scenario), at least in the US FDIC would probably come in to play. The bank might even have to be treated as a failed bank.

People wouldn't stop using banks, but they would stop using that bank.

Post reply on HN