6 ms·
Really surprised by the relatively low cost of attacking Bitcoin with 51% for one hour - claimed to be about $300k. Is this number for real? I can think of man
by danra 8y ago
Really surprised by the relatively low cost of attacking Bitcoin with 51% for one hour - claimed to be about $300k.
Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack.
- tgsovlerkhgsel 8y agoI believe the number assumes that you can get hashpower at the current price for (a small amount of) hashpower. However, as demand increases, the price goes up, making the attack more expensive in practice. Also, if people notice what you're doing, they'll probably stop selling hashpower to you (since you're attacking what makes their hardware valuable), driving your costs up further.
- tokai 8y agoThat is a really low cost. That's within crowdfunding territory. If a potato salad could make it big, why not fund a major event in web history? I'm thinking stretch goals like t-shirts and mugs.
- baddox 8y agoSeems like it would be very difficult to make back your $300k with a double-spend in one hour, based both on my intuition and the fact that it doesn't appear to be happening.
- michaelmrose 8y agoIf I'm reading it correctly you need 600k to have a 50/50 chance at double spending. So say you acquire 500k in bitcoin and you spend $600k to have your chance to double spend the 500k. Assuming your $600k in mining actually gets you $600k in bitcoins mined the expected result is. 50% chance spend 1.1 million get 1.1 million back minus substantial overhead. Say 10% overhead although I have no idea what the actual overhead would be. So negative 100k. 50% chance spend 1.1 million + 100k overhead get 1.6 million back. Net gain of 400k So average gain of 200k assuming you can find a market to move that much bitcoin that quickly and always assuming your creativity isn't rewarded with jail time. People with substantial resources can find way to make money that are repeatable and don't involve finding new and exciting ways to go to jail.
- deleted 8y ago[deleted]
- xur17 8y ago> Is this number for real? I can think of many actors for whom this is just small change, and who might have incentive to break trust in the Bitcoin network by successfully performing such an attack. Sorry if this is confusing - the attack cost is calculated based on the cost of hashing power from NiceHash * the global hash rate. If the 'NiceHash-able' column is <100%, NiceHash doesn't have enough hashing power to complete an attack (and thus the price is greyed out). This page [0] has more details. > Using the prices NiceHash lists for different algorithms we are able to calculate how much it would cost to rent enough hashing power to match the current network hashing power for an hour. Nicehash does not have enough hashing power for most larger coins, so we also calculated what percentage of the needed hashing power is available from Nicehash. Note that this ignores the fact that large mining operations could easily switch coins to carry out attacks. [0] https://www.crypto51.app/about.html https://www.crypto51.app/about.html
- zik 8y agoIt's worth pointing out that just getting 51% hash rate isn't enough to steal money. It's really just the entry point at which you _might_ be able to steal money. To actually steal money you need to falsify at least six blocks, which in turn means you need to mine six blocks in a row (roughly speaking). The probability of this being successful is (1.0-0.51)^6 - ie. about 1.5% chance of being successful. You can increase your chances by increasing your mining percentage. Make it a 75% attack and you have an 18% chance of success. To have a 50/50 chance of success you really need to mount about a 90% attack which is pretty ambitious.
- xur17 8y ago> You can increase your chances by increasing your mining percentage. Make it a 75% attack and you have an 18% chance of success. To have a 50/50 chance of success you really need to mount about a 90% attack which is pretty ambitious. I'm not sure this is accurate. You don't need to mine 6 blocks in a row on the existing chain. Clients are programmed to recognize the longest chain, so you just need to silently mine new blocks (and not share them with anyone) until you have more blocks than the main chain. Then publish these new blocks, and existing clients will recognize your chain of blocks as being the correct ones. You can double spend by making a transaction on the public chain while you quietly mine your own blocks on your private chain. Send the coins to an exchange on the public chain, but send them to your own address on your unpublished chain. After you steal funds from the exchange, publish your privately mined blocks.
- pryce 8y agoThe six-blocks-in-a-row problem seems less of an impedence to me - because the "legitimate" blocks are still available to the malicious actor. Therefore, if our malicious miner identifies that they have had poor luck and begun to fall behind the "legitimate" chain by a block or two they can start the make-a-longer-competing-chain process over again from the legitimate head with -as far as I can see- no downsides except for some lost time/resources; the main risk to them isn't really there until they commit by initiating their double-spend, something they would almost surely not do until they're confident they've acquired their own, longer competitor to the "legitimate" chain.