4 ms·
"Explaining the lack of such attacks in practice requires significant additional modeling assumptions." Yes, the main assumption being that burning such huge r
by Andrew_Quentin 11y ago
"Explaining the lack of such attacks in practice requires significant additional modeling assumptions."
Yes, the main assumption being that burning such huge resources would in any way be recouped by a simple double spend.
A double spending attack, as the name implies, simply allows you to spend twice the same amount of bitcoins. Thus, "an attacker [who] can purchase mining power" needs to be able to do so at a lower cost than the value of the bitcoins he will spend for the second time. Obviously, considering the hashrate and the fact that you need around 51% of it, or, 30% of it according to some calculations, I can't envisage any scenario where such a cost would in any way be justified by simply spending your own coins twice.
Moreover, one has to consider that if such hashing power was used to simply do what it is meant to do, then the attacker would be supplied with fresh new bitcoins, probably to the tune of far more than any amount he can double spend.
That is why "the Bitcoin protocol is a stable Nash Equilibrium."
- sp332 11y agoYou can convert BTC to cash. You can cash out all of your bitcoins twice instead of once. That means at least that everyone who is profitably mining bitcoins now should have an incentive to be doing this.
- hippich 11y agocashing large amount of bitcoins is slow process. cashing small amount does not make enough to cover processing power required to double spend.
- schoen 11y agoSince individual Bitcoin transactions can be as large as you like, you could conceivably double-spend tens of thousands of BTC in a single block. It's possible or even likely that there's nobody who would actually give you cash equivalents for tens of thousands of BTC without more precautions, but I don't see a clear limitation in the Bitcoin technology itself to limit how lucrative an isolated double spending attack could be.
- smokeyj 11y agoI think confirmation count does a good job of this, allowing processors to choose the balance between risk and convenience. No one's going to convert large fiat to btc without increasing confirmation count, and splitting smaller transactions will require setting up traceable account. Unless of course the attacker launders thru alt-coins, but then you might run into liquidity issues.
- sp332 11y agoI think confirmation count isn't so useful when one person or pool owns something close to 50% of the hashing power. Everyone gets complacent because they can't launch a 51% attack, but it's possible for someone with 40% of the power to effectively pull off the exact same attack for a span of six blocks. It is improbable, but not that improbable.
- smokeyj 11y agoWriting six blocks in a row doesn't mean you can double spend a transaction with six confirmations. Unless you meant something else.
- sp332 11y agoThat is pretty much what I meant. If you can write your own confirmations, why not?
- smokeyj 11y agoMiners would have to mine valid blocks secretly, risking never receiving a payout unless x-consecutive blocks have been mined. I mean it's technically possible, just economically infeasible.
- ISL 11y agoThere are social pressures, too. The payoff needs to be worth the risks associated with being "that person who attempted to double-spend". It's hard to rent half a network the size of bitcoin without someone from the mining community speaking up about it. It's in the miners' collective best interest to preserve the immutability of Bitcoin.