4 ms·
I'd guess that the odds of bug discovery is roughly proportional to the number of people looking at the source code times the economic incentive to find a bug.
by nwiswell 3y ago
I'd guess that the odds of bug discovery is roughly proportional to the number of people looking at the source code times the economic incentive to find a bug.
Both of these are astronomically high in the case of Bitcoin and Ethereum, and it's been some time since any breaking bugs have been found, so the odds of any remaining exploitable bugs must be pretty low.
A new bug could be introduced, obviously, but I think the review period for new changes reduces the odds of that too.
- orionsbelt 3y agoIt already happened once: https://www.coindesk.com/markets/2018/09/21/the-latest-bitcoin-bug-was-so-bad-developers-kept-its-full-details-a-secret/ https://www.coindesk.com/markets/2018/09/21/the-latest-bitco...
- yao420 3y agoI actually think people haven’t found anything because few skilled hackers have dedicated time to it. If the project zero team or Tavis by himself dedicated time to reviewing bitcoin it would fall apart like any other software.
- tnel77 3y agoThen why not do it?
- zelda420 3y agoProbably not in scope for Project Zero? Or they find other stuff more interesting. Security researchers don't work for free. I did some light searching and I couldn't find any sanctioned audits against Bitcoin core. The Bitcoin team should hire someone like trail of bits to do a multiple month audit.
- npoc 3y agoBut the "security researchers" wouldn't be working for free. Bitcoin has had an enormous bounty on its head for at least 10 years: "hack me and get paid millions/billions". It would be naïve to think there aren't highly skilled people continuously trying to do that.
- idiotsecant 3y agoVery unlikely. There is a massive payday for the first person to find a major bug. Even if that bug does not result in extra crypto in your pocket, doesn't matter. Its trivial to make money on downward crypto price swings as well. Find bug, take short position, release bug, collect payday.
- latchkey 3y agoEthereum switched from PoW to PoS. While it has been very stable, it has a much much higher chance of having a catastrophic bug than Bitcoin, which has remained relatively stable for years now.
- bawolff 3y agoThat assumes you actually get to keep the bitcoin (no hard fork to reverse, no value collapse due to sudden lack of trust, no gov throwing you in jail for stealing, no angry mobsters putting a hit out on you). The ideal ecconomic outcome would be something small enough you don't get noticed. Whose to say that isn't already happening? By definition you wouldn't be able to tell.
- npoc 3y agoEven if that where the case - extremely unlikely given that every fragment of bitcoin can be openly traced to it's origin, and double-spending detection is built deeply into the fundamentals of the system - it wouldn't really be any different to how the current fiat money system works.
- voldacar 3y agoIt's probably proportional to log(number of people looking at the source code) since the parts of the source code that people tend to look at are not uniformly distributed.