Live data from Hacker News

We can confirm that there was a successful 51% attack on Ethereum Classic

twitter.com

131–140 of 289 posts

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#131

Earlier quoted context omitted.

If a 51% attack is mounted by adding hash power, wouldn’t the existing miners on the target coin also start shutting down[1] because the competition is higher, reinforcing the strength of the attackers? [1] or migrate from to another coin, such as the coin that the attackers left to fill their void?

51% attackers mine in secret. Basically, you spend your coins today, while controlling a 51% share. When everyone else's 49% hash-power creates 98 blocks, your 51% share will create 102 blocks. But secretly. That's the key. Now that your chain is +4 ahead (or wait even longer and become +10 ahead), you can spend your coins on the public chain. Then, you publish your 102 alternative blocks (which barely adds any hash…

Or wait for many more confirms that the attack is impractical.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#132

Earlier quoted context omitted.

That's what it was like in 2016. I remember seeing the headline for the DAO hack on HN back then and thinking "Wow, good thing I didn't invest in this Ethereum thing". Someone had told me about it in 2015, I took a quick glance and passed thinking "Looks like a scam." Then 2017 happened and the joke was on me. Then 2018 happened and the joke was on them again. New technologies are always shitshows when they get start…

"New technologies are always shitshows when they get started. " A key difference is most of the new techs like Internet, email, Paypal, and so on improved on what people already had in a way that delivered obvious value. They also came with problems. Whereas, nobody I know in real life wants the drawbacks of these cryptocurrencies that come with giving up the benefits of their current, centralized offerings. The only…

> A key difference is most of the new techs like Internet, email, Paypal, and so on improved on what people already had in a way that delivered obvious value.

I'd argue that for most people the value was only obvious afterwards.

To put email in perspective, early adopters had to choose between what they already knew and all the hurdles involved in connecting to the internet and using the new technology. There was also a good chance the people they were trying to communicate with didn't even have email. Outside of a few niche areas, email provided no obvious value to the vast majority of people for decades.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#133

Earlier quoted context omitted.

If a 51% attack is mounted by adding hash power, wouldn’t the existing miners on the target coin also start shutting down[1] because the competition is higher, reinforcing the strength of the attackers? [1] or migrate from to another coin, such as the coin that the attackers left to fill their void?

With a 51% attack the additional hash power is not visible on the chain until the attack is triggered to perform a rollback.

Sorry for being that guy, but it is usually called a re-org not a rollback

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#134
post #65

This is inevitable. Ethereum Classic (ETC) isn't the only currency such attacks have been successful on. The site https://www.crypto51.app/ puts the cost of running a 51% attack on ETC at ~$5k per hour. The incentive for running these attacks for profit becomes higher as the market cap of these coins increases, making long-term 'investment' in these coins nonsensical.

Really surprised by the relatively low cost of attacking Bitcoin with 51% for one hour - claimed to be about $300k. Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.

It's worth pointing out that just getting 51% hash rate isn't enough to steal money. It's really just the entry point at which you _might_ be able to steal money.

To actually steal money you need to falsify at least six blocks, which in turn means you need to mine six blocks in a row (roughly speaking). The probability of this being successful is (1.0-0.51)^6 - ie. about 1.5% chance of being successful. You can increase your chances by increasing your mining percentage. Make it a 75% attack and you have an 18% chance of success. To have a 50/50 chance of success you really need to mount about a 90% attack which is pretty ambitious.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#136
post #55

Earlier quoted context omitted.

Other people have answered this from a more technical perspective. Philosophically, what the distributed blockchain is , is an agreement for adjudicating whose record (eg list of transactions) should be agreed on as "the valid one". If you already have a different, reliable external way of deciding this question, that is (arguably) conceding that you didn't need a distributed blockchain in the first place. EDIT: I've…

What I described would be part of the rules of system (or at least certain players). It just says "no changing history after X point". If anything, relying on an outside source is what we're doing now. Coinbase and others are telling us that they detected something and I haven't heard anybody question them. (And I'm assuming they're not lying). Though that's not to say the blockchain will be changed by this informati…

> If anything, relying on an outside source is what we're doing now.

You are correct of course. To me, problems like this recent attack highlight an inherent contradiction in the blockchain idea

- that the "51%+ of hashing power determines the truth" rule is really either lip-service; techno-marketing vanity that doesn't actually translate to practice (if corrective action ensues), and in which case the adjudicator is clearly not the blockchain tech we were told, but instead a nebulous collection of companies and stakeholders OR

- that "51% determines the truth" is indeed a strictly-held principle even though we have already demonstrated that there exist actors with enough resources and motivation to make attacks of this nature on some of the most prominent blockchain projects already - and we haven't even yet witnessed what a 51% attempt by an actor with the resources of a state would look like.

This is one of the reasons I have become skeptical of blockchain projects.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#137
post #132

Earlier quoted context omitted.

"New technologies are always shitshows when they get started. " A key difference is most of the new techs like Internet, email, Paypal, and so on improved on what people already had in a way that delivered obvious value. They also came with problems. Whereas, nobody I know in real life wants the drawbacks of these cryptocurrencies that come with giving up the benefits of their current, centralized offerings. The only…

> A key difference is most of the new techs like Internet, email, Paypal, and so on improved on what people already had in a way that delivered obvious value. I'd argue that for most people the value was only obvious afterwards. To put email in perspective, early adopters had to choose between what they already knew and all the hurdles involved in connecting to the internet and using the new technology. There was als…

The thing I was getting at is, if you had a computer and Internet, then email would be a free, fast alternative to traditional mail. That has obvious benefit. Whereas, these currencies are volatile, slower, often dont allow charge backs, use more energy, and accepted at fewer places. Worse in every way to checking accounts and credit cards. Esp if we have multiple cards or accounts to reduce risk of single institution.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#138
post #131

Earlier quoted context omitted.

51% attackers mine in secret. Basically, you spend your coins today, while controlling a 51% share. When everyone else's 49% hash-power creates 98 blocks, your 51% share will create 102 blocks. But secretly. That's the key. Now that your chain is +4 ahead (or wait even longer and become +10 ahead), you can spend your coins on the public chain. Then, you publish your 102 alternative blocks (which barely adds any hash…

Or wait for many more confirms that the attack is impractical.

I'm not sure that is possible. If a 51% attack for 1-week costs $1-million USD to pull off (hypothetical round numbers against a hypothetical coin)... then how many confirms do you wait for?

If you wait for 1008 confirms (for a transaction of $1 Million USD), then that doesn't stop the attack at all. After all, the attacker simply has to perform $2 Million USD worth of double-spends during that timeframe to make a profit. (Not necessarily with you, but across the entire blockchain).

After waiting 1008 confirms (1-week for a 10 minute/block coin), the attacker simply replaces those 1008 blocks with his 1049 secret-blocks and makes his chain the longest. That means that ALL spends for the past week are nullified, allowing the attacker to double-spend his coins on the new blockchain.

----------

In effect, waiting for 1000-confirms (or whatever) is closing the barn door after the horse has bolted. It doesn't protect your transaction... it protects the NEXT GUY's transaction.

In any case, the attacker gets to double-spend his money, which probably includes a large exchange (where you can turn coins into US Dollars easily).

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#139
post #134
post #65

Earlier quoted context omitted.

Really surprised by the relatively low cost of attacking Bitcoin with 51% for one hour - claimed to be about $300k. Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.

It's worth pointing out that just getting 51% hash rate isn't enough to steal money. It's really just the entry point at which you _might_ be able to steal money. To actually steal money you need to falsify at least six blocks, which in turn means you need to mine six blocks in a row (roughly speaking). The probability of this being successful is (1.0-0.51)^6 - ie. about 1.5% chance of being successful. You can incre…

> You can increase your chances by increasing your mining percentage. Make it a 75% attack and you have an 18% chance of success. To have a 50/50 chance of success you really need to mount about a 90% attack which is pretty ambitious.

I'm not sure this is accurate. You don't need to mine 6 blocks in a row on the existing chain. Clients are programmed to recognize the longest chain, so you just need to silently mine new blocks (and not share them with anyone) until you have more blocks than the main chain. Then publish these new blocks, and existing clients will recognize your chain of blocks as being the correct ones.

You can double spend by making a transaction on the public chain while you quietly mine your own blocks on your private chain. Send the coins to an exchange on the public chain, but send them to your own address on your unpublished chain. After you steal funds from the exchange, publish your privately mined blocks.

Post reply on HN