Live data from Hacker News

Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

ccn.com

471–480 of 555 posts

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#471
post #266

Earlier quoted context omitted.

That's not buying anything with Bitcoin. You are converting your Bitcoin to USD and then purchasing using the traditional, centrally controlled financial system. And that's not even considering the transactions fees it costs to get the Bitcoin to your account. Then there are the transaction fees for using the card, which coinbase says is free "for now".

That's like saying you can't buy anything with a VISA. Sure, transactions are intermediated through some consensus denomination for exchange. So? He still lost bitcoin and gained tacos. Just as someone else might lose a portion of a credit balance and gain tacos. You get just as full either way.

Whatever the receipt says is what you paid with; those receipts are definitely in USD.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#472

When Bitcoin was running up to $20,000, I tried to analyze the system and come to a personal conclusion about its equilibrium value, because I didn't want to miss out if it really was the currency of the future. I ended up not investing, because of the possibility of a double-spend attack. I think that cryptocurrency enthusiasts are seriously underestimating the importance of double-spending attacks to the economics…

It is often asserted (for example, in the Bitcoin white paper [22]) that a cartel can double-spend Bitcoins. In a strict sense, this is true: a cartel can spend a Bitcoin by paying it to a player Alice, receiving goods or services, and then shifting the consensus choice of history to a branch where that coin is instead paid to a different player Bob. However, we argue that double-spending by a cartel has a limited payoff. Bitcoins have value because people are willing to trade them for goods and services. If players were unwilling to accept Bitcoins for trade or unwilling to spend Bitcoins for fear of having their payments nullified, the value of Bitcoins would diminish significantly as players lost confidence in the system. Worse, because players are encouraged to generate a new identity for each transaction and because identities are not linked to any side information, players cannot easily determine whether a proffered payment is coming from the double-spending cartel or an honest user. Thus, a rational player should refuse to accept any payments when there is a significant threat of double-spending.

As a cartel must outmine the entire Bitcoin network and thus outspend the entire Bitcoin network for as long as it would remain a cartel, we believe it is very unlikely that a cartel could double-spend enough to recover the cost of the attack...

As described above, a 51% cartel attack is unlikely to generate enough reward within the Bitcoin economy to be worthwhile to the attacker. However, this does not rule out the possibility of a 51% attack that aims to destroy the Bitcoin economy in order to achieve utility outside the Bitcoin economy. We call this the Goldfinger attack after the character in film who tries to undermine U.S. currency by ruining its gold backing [15]...

In all of these cases, the attacker must achieve enough utility to justify the substantial cost of an attack. We agree with Becker et al. that it is unlikely that a protest movement could muster the resources to launch a successful attack. And at present it does not appear possible to acquire a short position on Bitcoins that is large enough to justify an attack. (2013)

The Economics of Bitcoin Mining, or Bitcoin in the Presence of Adversaries

Joshua A. Kroll, Ian C. Davey, and Edward W. Felten, Princeton University

https://www.econinfosec.org/archive/weis2013/papers/KrollDav...

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#473

When Bitcoin was running up to $20,000, I tried to analyze the system and come to a personal conclusion about its equilibrium value, because I didn't want to miss out if it really was the currency of the future. I ended up not investing, because of the possibility of a double-spend attack. I think that cryptocurrency enthusiasts are seriously underestimating the importance of double-spending attacks to the economics…

It is often asserted (for example, in the Bitcoin white paper [22]) that a cartel can double-spend Bitcoins. In a strict sense, this is true: a cartel can spend a Bitcoin by paying it to a player Alice, receiving goods or services, and then shifting the consensus choice of history to a branch where that coin is instead paid to a different player Bob. However, we argue that double-spending by a cartel has a limited pa…

This seems to miss the point that the mining pays for itself in collected transaction fees. Double spend is just icing on the cake.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#474

When Bitcoin was running up to $20,000, I tried to analyze the system and come to a personal conclusion about its equilibrium value, because I didn't want to miss out if it really was the currency of the future. I ended up not investing, because of the possibility of a double-spend attack. I think that cryptocurrency enthusiasts are seriously underestimating the importance of double-spending attacks to the economics…

blockchains are not immutable, the software that blockchain servers run can be updated to any chain with the most social consensus, if an attack was that bad it can be fixed with a few git pushes and pulls, the price might suffer but even that is not a guarantee, price movements have a greater influence than fundamental value in crypto

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#476
post #167
post #161

Earlier quoted context omitted.

So it's ok if your currency becomes unreliable for many hours? It would immediately negate the trust of what happened during that period of time, affecting the trust of any balance in participating addresses.

If Visa or SEPA got hacked over 12 hours and then fixed the root cause, would you stop using credit cards or bank transfers altogether? I would not.

My credit card gets stolen yearly. Sure, they can reverse the charges but changing the number everywhere is annoying..

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#477
post #148

So this would require an attacker to pay into the exchange with BTCg, have the deposit clear and approve for trading, trade it for another currency, and have that trade settle and be clear for withdrawal, and then process the withdrawal, all in under 4 hours. After which point the attacking miner surfaces a longer chain they had been keeping which doesn’t include the original BTCg deposit. Alternatively, if the excha…

Exchanges need to be built with the fluid nature of blockchain conflict resolution in mind.

You can estimate the cost of double-spend attacks on each chain at any time, calculate your potential exposure, track where the related funds are now in your system, and mitigate your exposure by delaying the outflow of funds that have outsize exposure to double-spend attack potential.

In the simple case, you might allow withdrawal of a single $10 deposit after 2 confirmations but enforce a long 1000-confirmation waiting period on a million-dollar deposit, in order to increase the cost of executing a double-spend against your exchange beyond the point which you estimate it becomes infeasible.

It's a little trickier in practice because someone could split their million-dollar deposit into 1000 thousand-dollar deposits from separate addresses into separate accounts. But you can still track your exposure in aggregate, and you should design a system to hold all impacted funds as long as is necessary to make a double-spend attack infeasible.

You can be upfront with your clients about what's happening and why their withdrawals are sometimes delayed: it would increase confidence in the safety of honest customers' deposits while discouraging thieves from targeting you.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#478
post #52

Earlier quoted context omitted.

How much energy is spent securing conventional financial systems? You have to include everything: banks, minting, enforcement, physical security, even military and intelligence action.

Why is this argument repeated so often? How is that comparison not clearly absurd to you? The conventional financial system is very obviously many orders of magnitude more efficient than bitcoin.

How is it obvious that conventional financial transactions are orders of magnitude more efficient than bitcoin? You can't use transaction price as a metric because it reflects a lot more than just the energy consumption of the system and even if you did, conventional transactions are not orders of magnitude cheaper than bitcoin transactions.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#479
post #385

Earlier quoted context omitted.

All of the major Bitcoin miners are very pro Bitcoin cash. They basically created Bitcoin cash. They would be more likely to attack Bitcoin Core, if anything. I would also point out that Bitcoin cash is the 4th largest crypto currency in the world, by market cap. If IT is in danger.... Well I fear for everyone else even more.

Bitcoin Cash is only protected by the benevolence of the large miners. It is otherwise wide open to a 51% attack.

So... Then I guess that means it is safe then right?

The whole point of crypto is that you are relying on the fact that 50% of the network is honest.

So yes, you are correct that it relies on half the network being "benevolent". That's how ALL cryptos work.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#480
post #285

Earlier quoted context omitted.

Interesting points. A defense against this type of attack is to use at least the hybrid proof-of-stake design that Ethereum is rolling out in about three months; blocks are proposed by proof of work, but proof of stake periodically adds a layer of "economic finality." Here's a paper: https://arxiv.org/abs/1710.09437

Just a cautionary note - you are describing the future in the present tense.

"In three months"...there's a chance that a problem will be found by the people doing formal verification, but otherwise there don't seem to be any potential roadblocks. Client implementation is very simple, partly because most of the protocol is implemented by a smart contract, which is already done. Ethereum does a hard-fork upgrade a couple times a year.
Post reply on HN