Live data from Hacker News

We can confirm that there was a successful 51% attack on Ethereum Classic

twitter.com

91–100 of 289 posts

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#91
post #89

Earlier quoted context omitted.

But you still get the prestige of having taken down a coin.

What makes you think there would be any such prestige earned?

It’s not very often you get a chance to take down a currency.

In 30 years from now you’ll be able to brag about how back in your day you took down entire cryptocurrencies with 51% attacks.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#92
post #65

This is inevitable. Ethereum Classic (ETC) isn't the only currency such attacks have been successful on. The site https://www.crypto51.app/ puts the cost of running a 51% attack on ETC at ~$5k per hour. The incentive for running these attacks for profit becomes higher as the market cap of these coins increases, making long-term 'investment' in these coins nonsensical.

Really surprised by the relatively low cost of attacking Bitcoin with 51% for one hour - claimed to be about $300k. Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.

> Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.

Sorry if this is confusing - the attack cost is calculated based on the cost of hashing power from NiceHash * the global hash rate. If the 'NiceHash-able' column is This page [0] has more details.

> Using the prices NiceHash lists for different algorithms we are able to calculate how much it would cost to rent enough hashing power to match the current network hashing power for an hour. Nicehash does not have enough hashing power for most larger coins, so we also calculated what percentage of the needed hashing power is available from Nicehash.

Note that this ignores the fact that large mining operations could easily switch coins to carry out attacks.

[0] https://www.crypto51.app/about.html

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#93
post #33

Earlier quoted context omitted.

In short, because they don't know that the chain they saw first is the chain that other nodes saw first (especially if they weren't online at the time). At least in theory, an attacker can exploit this to permanently fork the chain.

Hmm. The humans at the exchanges seem to be able to tell the difference. I wonder if it could be encoded.

I don't think that's feasible, to be honest.

I'd imagine that you would want to look for evidence of a double spend as that's the most likely goal of a 51% attack. But then the blockchain must have up-to-date knowledge of likely double spend targets (such as exchanges, OTC desks, etc), and be able to algorithmically and deterministically prove malicious intent with high certainty. Only then will you be able to maintain consensus and prevent unnecessary or accidental forks.

But since this is all open-source anyway, it would only be a matter of time before a slightly more sophisticated attacker read through the updated consensus algorithm and figured out how to game it. And so the cycle continues.

In truth, the only real strategy for mitigating attacks in PoW blockchains is hash power. It has proven to be very effective if you have enough of it (see BTC), and looking for other 51% resistance measures isn't really that productive unless you start from the ground up and rebuild the consensus mechanism on a different paradigm (e.g. PoS, which is still unproven afaik).

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#94

This is inevitable. Ethereum Classic (ETC) isn't the only currency such attacks have been successful on. The site https://www.crypto51.app/ puts the cost of running a 51% attack on ETC at ~$5k per hour. The incentive for running these attacks for profit becomes higher as the market cap of these coins increases, making long-term 'investment' in these coins nonsensical.

The tweet mentioned that it was a "chain reorganization". These happen all the time, even in Bitcoin, by design. The simplest way to defend against these is just to wait for more confirmations to arrive, thus making an attack more expensive. Many exchanges require a lot more confirmation for some of these smaller market cap coins.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#95

Earlier quoted context omitted.

Some of these numbers are very low. $30/h for Bitcoin Private? Seems inexpensive, what am I missing?

You're not missing anything. The coins are literally worthless other than to those who trade them on crypto exchanges, to steal each other's lunch money. Plus, launching an attack isn't just a case of paying $30 per hour. You need to have a client able to perform whatever your aim is for the attack, which requires a level of coding knowledge. And dev's at that level of knowledge are probably earning real money for th…

[deleted]

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#96

Earlier quoted context omitted.

> Because the market cap isn't truly $5M. That figure uses the naive calculation of "whatever coins sold for most recently times the total number of outstanding coins". Isn't that literally the definition of market capitalisation?

What works for companies doesn't work for cryptocurrencies. Companies have actual assets and cash flows, while cryptos do not. Companies are routinely acquired for a bonus above the total market cap (a premium on the share price times all shares outstanding). The same would never happen for cryptos. A better analogy would be to calculate the "market cap" of gold.

The guy you replied to is correct. The difference between how the market values companies and how the market values a cryptocurrency is irrelevant. Market capitalisation is independent of this distinction. Also, companies are acquired above market cap to entice shareholders to give up the desired proportion of the company to the buyer.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#97

Earlier quoted context omitted.

The most typical way to profit from this, is to have quite a bit of ETC, and then sell it on an exchange or buy something expensive. This transaction would then end up on the block chain, and eventually be considered secure / part of history. Privately, you are building a chain where said transaction did _not_ occur. Because your hash rate is high enough, you are generating blocks at at least the pace of the public c…

so to be safe, an exchange should require more confirmations depending on size of deposit. Basically the number of confirmations you could finance an attack for with the deposit.

Shouldn’t any sale/transaction be considered “not final” (goods can’t be shipped, for example) until the official chain has progressed to a point where you can be sure the cost of producing a censored fork is higer than the transaction in question? That is: you buy something expensive then it might not ship for a month or two.

I guess you could buy a hundred gadgets at $100 each from a hundred places in one day and then produce a fork censoring your whole $10k shopping spree?

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#98

Earlier quoted context omitted.

> That's like saying "this whole programming thing just keeps on giving" every time a bug is discovered in any program. No it's not. Programming is a tool to create programs with. Block chain is a technological buzzword being used (and implemented) wildly inappropriately. 51% attacks are a fundamental vulnerability in decentralization. It would be like inventing programming when everyone pretends bugs don't exist at…

Blockchains are just another datastructure. A poor implementation of one doesn't necessarily mean the whole idea is fundamentally useleas.

But a vast majority of them being garbage does mean the vast majority of them are garbage

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#99

Earlier quoted context omitted.

How can there be coins with $5M+ market cap where the cost of a 51% attack is $3.00 ?? In an efficient market, thieves should just immediately attack that. Or is the benefit too low?

Because the market cap isn't truly $5M. That figure uses the naive calculation of "whatever coins sold for most recently times the total number of outstanding coins". But if you tried to sell some significant fraction of the outstanding coins then the sale price would plummet, and you'd never actually reach $5M total. The actual depth of the order book at any given moment isn't close to $5M, plus a lot of outstanding…

>But if you tried to sell some significant fraction of the outstanding coins then the sale price would plummet, and you'd never actually reach $5M total.

You can't focus on sellers and ignore buyers when discussing the valuation of something. If many people want to sell and few people want to buy the price will of course go down. But if many people want to buy and few people want to sell then the price will go up. This isn't a particularly interesting observation.

To put it another way: you are right that if everyone who held a portion of this asset tried to sell right now they would not cumulatively get $5 million, BUT ALSO, if someone wanted to buy all of this asset they would pay significantly more than $5 million. It goes both ways. Changing the balance of supply and demand necessarily changes value.

I do agree that naively using the price of a single trade can be misleading and prone to manipulation.

Re: We can confirm that there was a successful 51% attack on Ethereum Classic

#100

Earlier quoted context omitted.

can we not do this here please? Nobody wants that, nobody is saying they want that, there are mitigations against that (like backups), and it's a stupid straw man that's not even trying to engage in a meaningful conversation on the topic.

Nobody wants to back up their money. Just use a bank and never worry about it.

Like how nobody wants to have their accounts frozen with no notice? Or how people don't want a private company to be able to dictate what they are allowed to buy and sell? Or how people don't want to have to be constantly vigilant to ensure their simple 16 digit number doesn't get into the wrong hands (or that the hands they are required to give it to don't misuse it) and if/when it does they quickly report it to the credit card company so they aren't on the hook for it.

All money systems have tradeoffs, cryptocurrencies are just another option.

Post reply on HN