I want to thank everyone who engaged with me instead of downvoting me.
Okay, I think I see now where I was separately wrong and partially wrong in the previous comments. When I said there's a huge monetary upside to a 51% attack, that's wrong. There's not really any upside to speak of, especially considering the huge amount of computing resources you would need to do it.
So it's not surprising it hasn't been tried yet, and that's not a proof that it's a canard as I said before (but it's not a proof of the opposite, either). Absence of evidence does not imply evidence of absence. So I'll concede and leave that point alone. I was wrong.
---
Now, when I said that the 49% can still use the 51%'s blocks, that's not entirely correct. It's correct only until the blockchain splits, then it's not correct. So my position wasn't entirely correct, but it still has value to this discussion. Let me illustrate with a randomly-generated timeline.
Let's make it easy and say 66% are censoring miners, and 33% are non-censoring miners.
We haven't discussed this yet, but let's also assume that the exchanges and non-mining users reflect this proportion. This is an unfounded assumption. But I'm steelmanning.
The 33% are in miner pool 1, and the 66% are in miner pool 2 and 3. The dots represent 5-minute intervals. Just like in Bitcoin, a block is mined roughly once every 20 minutes. Observe the moment at "X".
..3..........2...X1.3......1...1..........2......2..
At this point, the blockchain looks like this.
100% 3--2
You might ask, "Why is it not forked at this point? Miner pools 3 and 2 are the malicious actors, and they had two blocks in a row." Because 1 has no reason to fork. All previous blocks are valid according to Miner pool 1.
Now, observe the point at X:
..3..........2....1X3......1...1.......X..2......2..
At this point, the blockchain has forked. It looks like this.
66% 3--2
33% 3--2--1
Notice, 33% has the longer chain, but the 66% do not accept the 33%'s block because it contains censored transactions, so a re-org does not occur. This situation will continue as long as the 33% chain is equal to or longer than the 66%, which could be a while.
But how can that be possible if the 66% has more hashpower?
Observe the point at X:
..3..........2....1.3X.....1...1..........2......2..
Chains:
66% 3--2--3
33% 3--2--1
They are equal. No re-org happens.
One should question at this point what's going on in the mempool here? One can assume the 66% censoring miners are not transmitting the censored transactions to the mempool. But how many censored transactions are we talking about? How much of a fee is each side collecting? Is this still in the coinbase reward era or after? Are the 33% smart enough to route around the 66%? Or punish them by kicking them off the mempool? Not sure. All of these variables can mitigate this attack. But I will not explore that now.
Although there are now two rival chains, for simplicity's sake, lets just assume the same timeline holds, and remove each of the two side's blocks from the other's chain starting from at the time of the fork.
66% ..3..........2....1.3.....................2......2..
33% ..3..........2....1........1...1....................
Now, observe the point at X:
66% ..3..........2....1.3.....................2......2.X
33% ..3..........2....1........1...1...................X
Chains:
66% 3--2--3--2--2
33% 3--2--1--1--1
3 hours later, the 66% still have not overtaken the 33%.
One should wonder even more, what is going on in the mempool and ~$250B Bitcoin economy during this time?
In this example, only two blocks by the 33% are mined consecutively. What about 3 or 4? Could it be days before the 66% overtakes the 33%? I think it's possible.
On the other hand, the mining of consecutive blocks by the 66% does not create a contention between the two sides. So all miners are unified until the 33% gain an advantage. This is my point.
From the POV of the censored Bitcoin transactions, the 66% will succeed in censoring them until the issue is resolved. But I don't think you can say that the 66% have control of the network at this point. They've only succeeded in disrupting the network until more non-censoring miners come online, or something else happens.
Consider also that the attacker has to either possess 66% of all computing power devoted to Bitcoin in the known universe OR an incentive more attractive than the BTC block incentive for the operators of 66% of miners. Even for 51%, that's an impressive achievement.
It's a very interesting scenario but I still say it does not constitute a credible threat to Bitcoin. More of a thought experiment.