Live data from Hacker News

Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

ccn.com

71–80 of 555 posts

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#71

Crypto currencies are worthless unless they have an enormous amount of hashing power behind them. We could really do with a webpage with a list of crypto currencies, the hashing power currently behind them, and how much it would cost somebody to take over 50% of the network. Or does that already exist?

So, that's an interesting pair of ideas, in that it gets me thinking that any Bitcoin-style cryptocurrency might ultimately be doomed by its own design. Shooting from the hip: They've go this 51% vulnerability that is well known and hypothetically cannot be truly closed. Instead, we rely on the idea that mounting such an attack would be "too expensive". But at the same time, the cost/benefit of mounting such an attac…

> They've go this 51% vulnerability that is well known and hypothetically cannot be truly closed. Instead, we rely on the idea that mounting such an attack would be "too expensive". But at the same time, the cost/benefit of mounting such an attack is fairly easy to estimate using public data - all you really need to know is the cost to get to 51% and stay there for a given amount of time, which you can infer by monitoring mining activity, and the current price of the currency you'd want to attack. And you have to assume that whenever the cost of mounting such an attack dips below the benefit, such a thing _will_ happen.

Or, to turn this around, if X is the amount of money needed to sustain a 51% attack for 1 block, then you have to wait for 1 confirmation for every X amount of coins received.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#72

Crypto currencies are worthless unless they have an enormous amount of hashing power behind them. We could really do with a webpage with a list of crypto currencies, the hashing power currently behind them, and how much it would cost somebody to take over 50% of the network. Or does that already exist?

So, that's an interesting pair of ideas, in that it gets me thinking that any Bitcoin-style cryptocurrency might ultimately be doomed by its own design. Shooting from the hip: They've go this 51% vulnerability that is well known and hypothetically cannot be truly closed. Instead, we rely on the idea that mounting such an attack would be "too expensive". But at the same time, the cost/benefit of mounting such an attac…

> all you really need to know is the cost to get to 51% and stay there for a given amount of time

That's actually, if anything, underestimating the likelihood of a 51% attack. It seems that the more likely path to that situation is collusion between segments of the existing mining community. For such a cartel, the "cost" is zero, it's just a matter of trust.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#73

Crypto currencies are worthless unless they have an enormous amount of hashing power behind them. We could really do with a webpage with a list of crypto currencies, the hashing power currently behind them, and how much it would cost somebody to take over 50% of the network. Or does that already exist?

So, that's an interesting pair of ideas, in that it gets me thinking that any Bitcoin-style cryptocurrency might ultimately be doomed by its own design. Shooting from the hip: They've go this 51% vulnerability that is well known and hypothetically cannot be truly closed. Instead, we rely on the idea that mounting such an attack would be "too expensive". But at the same time, the cost/benefit of mounting such an attac…

Decred appears to have solved the PoW 51% attack via a hybrid PoW/PoS consensus mechanism. It's practically unfeasable to attack at this point.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#74
post #36

Earlier quoted context omitted.

There's a hidden cost of trust there, though, which vanishes with bitcoin (or at least reduces its cost). Maybe the value of bitcoin is more apparent from the perspective of venezuela at the moment, where the risk involved with traditional banks, currency, and security is more apparent. I am emphatically not taking a stance on which I prefer here, I might add, just pointing out that there are more variables here than…

Bitcoin and other cryptocurrencies require even more trust than normal currency. With a normal currency transaction, you need only trust at most 2 other entities entities: your counterpart to the transaction and the government issuing the currency. With a blockchain, you still need to trust the counterparty, but now you also need to trust that the coders have properly designed and programmed the system, and that the…

I think there are fundamentally different ways we're talking about trust: you "only" need to trust a government, you "only" need to trust a bank, vs trusting a certain proportion of miners to be following the same bitcoin specs you are, as well as trusting that people will value it tomorrow. Both of bitcoin and government-issued currency requires trust, and building that trust is fundamentally difficult, depending on your needs, and comes with tradeoffs. It seems like you're only acknowledging one end of these tradeoffs.

One obvious tradeoff you're not considering is that of a criminal getting its assets frozen, for instance. There are less black and white situations where you might prefer bitcoin as well, if you have a little imagination. If you could address that, I'd probably appreciate your comments more.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#75
post #68
post #61

Earlier quoted context omitted.

Not necessarily, non-hashing consensus seems to be where most blockchain projects are going. So these would require a stake of assets or similar, instead of wasting computing cycles.

Creating a proof-of-stake algorithm that doesn't degenerate to proof-of-work and that doesn't require a central authority (checkpoints, etc) is still an open problem.

I'm waiting for the cardano guys on this one, testnet with PoS will start soon and they don't make bullshit hype announcements ever

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#76
post #70
post #33

>Obtaining this much hashpower is incredibly expensive Is it? Presumably you only need to maintain it for a short amount of time. Sounds like something one could smash with google cloud preemptible GPUs or similar. Especially since such an attacker is presumably not above using a stolen CC or three.

Well, under the standard assumptions of blockchains like Bitcoin, yes it's incredibly expensive to obtain enough hashing power to do a 51% attack. There's a lot of nuance to it though. In this case, Bitcoin Gold chose to have an "ASIC Resistant" algorithm, Equihash, and likely was only protected by GPUs mining the network. Bitmain has recently released an ASIC for Equihash that is substantially cheaper and more energ…

but hashrate on BTG has been falling consistently since inception, it doesnt look like someone invested in a load of ASIC devices to perform this attack, more like they kept the same operation and watched its % grow as other miners left the chain for a more profitable coin.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#77
post #56
post #30

Earlier quoted context omitted.

Interesting point. The cryptocurrency energy consumption problem will never be solved, since if it is, it will be economically feasible to attack. So cryptocurrency adoption in the mainstream will require massive electricity consumption.

You might even say it will ultimately require at least 51% of worldwide electricity production, to ensure no actor (including nation-states) can suddenly on-line additional capacity to seize control. And then if that's true, one might dream of a power plant arms race, where two competing nations build additional power plants as fast as possible to prevent the other from gaining enough electrical capacity to attack th…

There's a great sci-fi plot here

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#78
post #33

>Obtaining this much hashpower is incredibly expensive Is it? Presumably you only need to maintain it for a short amount of time. Sounds like something one could smash with google cloud preemptible GPUs or similar. Especially since such an attacker is presumably not above using a stolen CC or three.

Under normal free market assumptions, the cost of double spending is simply the expected reward of each block multiplied by the number of blocks that need to be mined. For bitcoin, where the reward for finding a block is currently ~$100,000, that means you should be able to double spend by mining 6 blocks at a cost of less than a million dollars. The question is: are bitcoin miners subject to the usual free market as…

As a miner, you are likely not going to accept because your entire revenue stream comes from the cryptocurrency being stable. If someone uses your hashrate to launch an attack, it's a direct threat to your future revenue especially if the attack discredits the security of the token you mine.

In this case though, Bitcoin Gold shares a hashing algorithm (Equihash) with many other blockchains. It is possible that some Zcash mining farm decided to attack Bitcoin Gold because they felt the revenue from attacking Bitcoin Gold was greater than the potential damage to their income, which is primarily Zcash based.

I'm just grasping at straws here, but generally speaking it's a bad idea to share hashing algorithms with another cryptocurrency, especially if that cryptocurrency is substantially more valuable (in terms of monthly block reward) than your own.

And, all GPU-mined coins are essentially sharing one algorithm, because the hardware can jump between them easily. So all GPU based coins share this vulnerability, where the tiny GPU mined coins could easily be attacked or wiped out by a large Ethereum farm at any point.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#79
post #58
post #8

Satoshi really downplayed 51% attacks in his/her original whitepaper[1]: > The incentive may help encourage nodes to stay honest. If a greedy attacker is able to assemble more CPU power than all the honest nodes, he would have to choose between using it to defraud people by stealing back his payments, or using it to generate new coins. He ought to find it more profitable to play by the rules, such rules that favour h…

But wouldn't the long-term honest mining be more profitable than a single hit and run? Kinda the same reason that when you go to a restaurant the restaurant owners almost always exchange food for money rather than rob you and leave town forever. If you own a restaurant it's generally more profitable to run it honestly than run away with a one-time dishonest payoff.

Because you don't have to pay for the long term mining equipment and instead can just rent them from AWS/GCP/Azure for the attack.

If you did buy them though, you could attack cryptocurrencies one by one stealing money from a bunch of different ones.

I think both situations would be more profitable.

Re: Bitcoin Gold Hit by Double Spend Attack, Exchanges Lose Millions

#80
post #56
post #30

Earlier quoted context omitted.

Interesting point. The cryptocurrency energy consumption problem will never be solved, since if it is, it will be economically feasible to attack. So cryptocurrency adoption in the mainstream will require massive electricity consumption.

You might even say it will ultimately require at least 51% of worldwide electricity production, to ensure no actor (including nation-states) can suddenly on-line additional capacity to seize control. And then if that's true, one might dream of a power plant arms race, where two competing nations build additional power plants as fast as possible to prevent the other from gaining enough electrical capacity to attack th…

...this is an intriguing start for a sci-fi novel.
Post reply on HN