[HN Gopher] Sabotaging Bitcoin
       ___________________________________________________________________
        
       Sabotaging Bitcoin
        
       Author : zdw
       Score  : 187 points
       Date   : 2025-12-30 20:53 UTC (1 days ago)
        
 (HTM) web link (blog.dshr.org)
 (TXT) w3m dump (blog.dshr.org)
        
       | gerdesj wrote:
       | TIL: https://ccaf.io/cbnsi/cbeci - quite horrifying!
       | 
       | EDIT: For comparison: https://gridwatch.co.uk/
        
         | kfrzcode wrote:
         | Meanwhile, Hedera remains carbon negative and 7 orders of
         | magnitude more efficient than Bitcoin.
         | 
         | "Today, Hedera is performing the equivalent of over 10,000,000
         | transactions and 788,000 transactions for the same amount of
         | energy it takes Bitcoin and Ethereum to process 1,
         | respectively."
         | 
         | [0]: https://hedera.com/blog/going-carbon-negative-at-hedera-
         | hash... [1]: https://discovery.ucl.ac.uk/id/eprint/10160701/
        
           | wslh wrote:
           | Databases either?
        
           | ShowalkKama wrote:
           | I find extremely funny that I came across this spammy comment
           | while sitting on a vulnerability in their code because my
           | attempts of contacting them have been unsuccessful
        
             | kfrzcode wrote:
             | Here you go! https://hedera.com/bug-bounty/
        
           | oofbey wrote:
           | Everything is orders of magnitude more efficient than
           | bitcoin.
        
         | Zaskoda wrote:
         | What this site does not show is how much of the power used to
         | maintain the network is waste power such as gas that's normally
         | burned off at the well site or hydro electric that goes to
         | waste.
         | 
         | Unlike AI, there's a strong incentive to find the cheapest
         | electricity possible. Because that's what everyone else is
         | doing. With Bitcoin, you now exactly what your costs are and
         | what your yields are. There's a clear threshold, when power in
         | an area becomes too expensive there's no reason left to mine.
         | 
         | AI, on the other hand, is a bet on the future - infinite gains.
         | No matter how much power costs, it's worth it to keep using as
         | much as possible. We can't know how much power AI uses. Unlike
         | Bitcoin, there aren't any metrics from which to extrapolate.
         | But we do know that AI uses more power than Bitcoin already. We
         | just have no idea how much more.
        
           | fragmede wrote:
           | > gas that's normally burned off at the well site
           | 
           | Funny thing about that. Civilized governments put a stop to
           | that, by fining flare-offs to make it economical to not do
           | that.
        
             | zoklet-enjoyer wrote:
             | They still do it in North Dakota
        
             | krupan wrote:
             | I hadn't heard of this. Do they just allow the gas to go
             | into the atmosphere instead? I've always heard that's worse
             | than burning it
        
             | UltraSane wrote:
             | flare-offs are much better than releasing raw methane into
             | the atmosphere because methane is a much worse greenhouse
             | gas than CO2
        
             | nativeit wrote:
             | Did they require the methane be captured? I thought flare-
             | offs were done because the methane gas is something like
             | 1000x worse than the CO2.
        
           | cyberax wrote:
           | > What this site does not show is how much of the power used
           | to maintain the network is waste power such as gas that's
           | normally burned off at the well site or hydro electric that
           | goes to waste.
           | 
           | WTF? Hydro is rarely wasted because it's so dispatchable.
           | Typically, it can only happen during high water seasons. Same
           | for the gas power plants.
           | 
           | > Unlike AI, there's a strong incentive to find the cheapest
           | electricity possible.
           | 
           | Like coal.
        
             | beenBoutIT wrote:
             | An interesting point is that any nation state or
             | corporation can focus resources on either AI or BTC, but
             | not both at the same time. BTC is a sure bet in the long
             | run while AI is potentially capable of delivering a faster
             | ROI with no hard guarantees. As BTC FOMO hits every country
             | on Earth it's likely that AI will take a 100+ year backseat
             | to massive state sponsored BTC operations. It's not hard to
             | imagine a situation where governments restrict AI HW
             | manufacture and limit electricity for AI as a means of
             | supporting the national BTC effort.
        
               | UltraSane wrote:
               | "BTC is a sure bet in the long run "
               | 
               | 7 transactions per second is NOT a sure bet.
        
               | childintime wrote:
               | And don't discount the negative sentiment around bitcoin
               | as the nest of types that deserve to be completely
               | wrecked financially, because they add no value to
               | society, as in a Ponzi scheme. It seems inevitable to me
               | this scheme is going to end some day and nobody is going
               | to give a damn. It'll be the "Good Riddance Coin", filled
               | with negative sentiment.
        
               | beenBoutIT wrote:
               | At 7 TSP BTC is far more fungible than Gold.
        
               | UltraSane wrote:
               | That doesn't make any sense at all.
        
           | bb88 wrote:
           | > We can't know how much power AI uses.
           | 
           | I call shenanigans on this statement. We can and most
           | certainly can tell how much power AI is using. The upper
           | bound is the total datacenter usage.
        
             | utopiah wrote:
             | Out of curiosity, do you have an estimate on that?
        
           | oofbey wrote:
           | BTC enthusiasts have very creative arguments for why their
           | currency isn't the a complete disaster for the climate. Like
           | pointing fingers.
        
             | beenBoutIT wrote:
             | The good that BTC will do in the long run is worth the
             | investment. Civilization getting out from under fiat
             | currencies - once and for all - is a massive step in the
             | right direction.
        
               | gorbachev wrote:
               | I'm curious as to what's your time horizon for "in the
               | long run". When is this transition to bitcoin going to
               | happen?
        
           | johnnienaked wrote:
           | And what does sucking up all that low cost electricity to
           | waste on a frivolity do to the price of electricity in
           | general?
           | 
           | Cmon you remember supply and demand right
        
         | bujkopl wrote:
         | Since when is incentivizing low cost renewable energy
         | horrifying?
        
           | gerdesj wrote:
           | My first link shows that Bitcoin consumes roughly 40GW and my
           | second link shows that the UK roughly does too.
           | 
           | There are a lot of ifs and buts here ... but the amount of
           | power used to support the BT mechanism worldwide is roughly
           | the same as the power consumption of the entirety of the UK.
        
           | D13Fd wrote:
           | Because every unit of electricity causes climate change and
           | burns resources (even renewable sources of electricity - they
           | just burn them slower). From a societal point of view we are
           | dumping huge amounts of electricity and resources into a hole
           | to accomplish nothing that couldn't be accomplished with a
           | database and a trusted third party at a billionth of the cost
           | (or less).
           | 
           | The vast majority of transactions are speculation on what
           | other people might pay for a bitcoin (i.e., a line on a
           | spreadsheet). And even then, that speculation and trading
           | often occurs on secondary markets which rely on trusted third
           | parties - thus rendering the entire ordeal even more
           | pointless.
        
             | bujkopl wrote:
             | Better shoot down the sun then.
        
             | comradesmith wrote:
             | You're right. I'll setup the database. Everyone can trust
             | me, honest!
        
             | beenBoutIT wrote:
             | In the long run BTC as a universal digital global currency
             | will be more efficient than the fiat currencies it
             | replaces.
        
               | munksbeer wrote:
               | That dreams is dead. Bitcoin is never going to be a
               | universal digital currency. No-one (*) uses it for that
               | purpose now, because they discovered it was rubbish as a
               | cash system
               | 
               | (*) Approaching no-one on a global scale.
        
           | rcxdude wrote:
           | Bitcoin cares not for how much energy it uses, just how
           | valuable the energy it uses is. This does not make more
           | energy available to anyone else or reduce the price.
        
         | utopiah wrote:
         | Well what's arguably even more horrifying is according to
         | "Estimated average energy efficiency of bitcoin mining
         | hardware" no significant changed happened since 2014. I imagine
         | we went from CPU to GPU to ASIC in couple of years and now for
         | more than a decade, no change, just more.
        
           | tenuousemphasis wrote:
           | I'm not sure what data you looking at but we went from 8300
           | J/TH in 2014 to 33.4 J/TH in 2023. So... what are you talking
           | about?
        
             | utopiah wrote:
             | They have a graph at the bottom with the name I provided
             | "Estimated average energy efficiency of bitcoin mining
             | hardware"
        
               | tenuousemphasis wrote:
               | You're reading the graph wrong, but I still have no idea
               | _how_ you are. Joules per terahash has declined from 8297
               | in 2014 to 33 in 2023 (the latest year they have data), a
               | 99.996% reduction, or a 250x improvement in efficiency.
        
           | rcxdude wrote:
           | Well, improved energy efficiency just means more hashes/s and
           | the difficulty adjusting. There's nothing to be gained in
           | terms of the security or efficiency of the network as a whole
           | by making the hardware faster, it's only good for whoever
           | makes and uses that hardware.
        
       | will5421 wrote:
       | Is it illegal to attack cryptocurrency?
        
         | qgin wrote:
         | If crypto needs legal protection from attacks, I think that
         | would invalidate most of its value proposition.
        
           | dboreham wrote:
           | Definitely reduces the cost of consensus though.
        
           | Lerc wrote:
           | That seems to be a reasonable position. I'm kind-of
           | comfortable with the position of bitcoin as being large
           | enough to attract significant attacks, but not so dominant
           | that a catestrophic failure of the system would have
           | significant global impact.
           | 
           | I have nothing against bitcoin being the money of the future,
           | but if it is to become that, this is the sort of trial by
           | fire that it should endure.
        
         | wmf wrote:
         | The attack described in this article might violate CFTC market
         | manipulation regulations.
        
         | anonym29 wrote:
         | IANAL, but from my understanding, the primary law used to
         | prosecute hacking is the CFAA's broad "without authorization"
         | and "exceeding authorized access" clauses.
         | 
         | That said, authorization implies an entity with ownership
         | rights granting some kind of limited license to others to
         | interact with the owner's property.
         | 
         | For a permissionless decentralized network with no owner, where
         | the attack is against the consensus of which chain is valid,
         | I'd have a hard time arguing that "authorization" as a concept
         | is even applicable or relevant.
         | 
         | As wmf suggested, market manipulation laws may still apply, but
         | I'm not sure traditional CFAA "without authorization" /
         | "exceeding authorized access" hacking charges could apply,
         | though I'd be willing to bet a prosecutor could make a case for
         | wire fraud - a scheme to defraud using interstate
         | communications.
        
         | OJFord wrote:
         | Depending on the currency, it's celebrated. (Code is law, etc.)
        
           | Etheryte wrote:
           | That says nothing about actual legality though, just like how
           | me saying I am the law doesn't make me the king of the world.
        
         | fancyfredbot wrote:
         | You will probably end up in court. But you might not get
         | convicted.
         | 
         | Shakeeb Ahmed was convicted of wire fraud for exploiting a
         | smart contract bug.
         | 
         | Avi Eisenberg was also convicted for exploiting a smart
         | contract bug, but he had his conviction overturned on appeal.
         | 
         | The Peraire-Bueno brothers were in court for exploiting a bug
         | in the MEV mechanism but it ended in a mis-trial so we're going
         | to have to wait to find out.
         | 
         | Not legal advice ;-)
        
       | OutOfHere wrote:
       | The answer to this problem is in the original Bitcoin whitepaper
       | itself. It gives the formula for the required number of
       | confirmations.
       | 
       | The Monero PoW community has had to deal with such nonsense, as
       | have other smaller PoW coins.
       | 
       | With e=1e-3, the expected number of 6 confirmations works only so
       | long as the largest pool size does not exceed 12%. For a pool
       | size of 30%, at least 24 confirmations should be required in
       | Bitcoin, but 49 in Monero with its stricter e=1e-6. You can see
       | the table and the math at
       | https://gist.github.com/impredicative/0907e1699f5ff97a9fed5d...
       | and again it's all cleanly reproducible from the whitepaper.
       | Anyone who is still requiring only 6 confirmations then will be
       | setting themselves up for a risk of reversal.
        
         | dmurray wrote:
         | TFA observes that it would be disruptive and socially difficult
         | to move systems to expect requiring 24 confirmations, and
         | expresses relief that other responses are possible.
         | 
         | Perhaps this is more suitable as a response over months or
         | years to a long-term shift in the composition of Bitcoin miners
         | than as a short-term measure when it appears that someone has
         | suddenly acquired 30% of mining capacity today.
        
           | OutOfHere wrote:
           | Yes: "Not aligning with reality is disruptive." Some lessons
           | have to be learned the hard way if they're not learned the
           | soft way. The problem is not reality.
        
         | rationalist wrote:
         | Bitcoin has a block/confirmation approximately every 10
         | minutes, and Monero every 2 minutes.
         | 
         | So 240 minutes for Bitcoin, and 98 minutes for Monero.
         | 
         | So even though Monero is more strict, it is still "faster".
        
       | Stevvo wrote:
       | Before the AI bubble, Bitmain was only worth ~$1 billion. Now
       | they are worth ~15, because they make chips for AI also. Either
       | way, you could buy bitmain for the budget mentioned in the attack
       | if it were for sale. Or bitmain could pull off the attack, if
       | indeed they do "control ... all the major mining pools" as the
       | article alleges.
       | 
       | But who ultimately controls Bitmain? The Chinese state.
       | 
       | So, by extension, bitcoin is controlled by the CCP.
       | 
       | What a shitshow. Crypto needs to move on from bitcoin already,
       | pick something better... anything better. There are so many
       | options, and bitcoin is the worst of all of them.
        
         | TheAmazingRace wrote:
         | Too many people have a vested interest in keeping Bitcoin going
         | for as long as possible, sadly. It's going to take a massive
         | black swan of some kind to shake their faith.
         | 
         | Heck, they can embed CSAM into the Bitcoin blockchain and that
         | won't stop anyone from using it, because above all else, line
         | must go up.
        
         | beenBoutIT wrote:
         | Like it or not in the end it will just be BTC. China will stop
         | exporting Bitcoin mining tech. Nation States will dump money
         | into proprietary BTC mining tech and keep it to themselves just
         | like military tech. The US needs to see this reality and focus
         | on domestic BTC mining tech like the future depends on it.
        
           | hackernudes wrote:
           | It comes down to semiconductor manufacturing, not ASIC
           | design. Taiwan, Korea, USA are still on top.
        
           | oblio wrote:
           | LOL. The Sam Altman plan. Or the US could just put Bitcoin on
           | the Entities List and forbid any US citizen and any US owned
           | entity from investing or trading Bitcoin and Bitcoin derived
           | financial instruments, probably force 25% or more of the
           | Bitcoin money to pull out, crater Bitcoin value, and not
           | perpetuate this atrocity against nature and humanity.
           | 
           | "Democratizing finance" my a**.
        
           | fruitworks wrote:
           | why? the easy solution is to let china monopolize bitcoin
           | mining, and the value of bitcoin crashes. then the USD will
           | stand unopposed and the chinese will end up with a bunch of
           | useless equipmemt
        
       | roenxi wrote:
       | The Eyal & Sirer paper is pretty interesting - they basically
       | point out that there is actually some game theory involved in
       | _when_ miners should reveal that they mined a block to compete
       | most effectively with their fellows. If a pool can set up a
       | situation where they mine a block and wait X seconds to reveal
       | it, they can force other miners to waste X seconds of has power
       | and gain an advantage.
       | 
       | It looks like a result with complex implications - eg, maybe
       | making it impossible for new miners to set up unless they have a
       | meaningful advantage in operating costs instead of just parity
       | with the entrenched players. It is hard to tell because market
       | reality is a mess but if there is a meaningful strategic choice
       | to be made beyond simply announcing a block when it is mined then
       | there is a lot of room for weird equilibriums even if the paper's
       | specific analysis turns out to have flaws.
        
         | mvkel wrote:
         | Isn't this the same thing as saying "if everyone just agrees
         | that a dollar bill is actually just a piece of paper, USD
         | becomes worthless"? Albeit at a smaller scale
        
           | ycombinatrix wrote:
           | I don't think it is the same thing. Everyone agrees that
           | mining the next block is valuable.
        
             | cheschire wrote:
             | Unless they didn't.
             | 
             | There's nothing inherently valuable about crypto beyond
             | what value people assign to it in their minds.
        
               | krupan wrote:
               | Same with all money. Please research more before
               | parroting this argument. You are not the first person to
               | think of it.
        
               | cheschire wrote:
               | GP was arguing against GGP's point and I was simply
               | pointing out that the argument was hollow.
               | 
               | What are you referring to with "research more"?
        
               | krupan wrote:
               | Hmm, maybe I wasn't following the thread very well? Many
               | people like to discredit Bitcoin by saying it's only
               | worth is what people decide it is. If that's not what you
               | were trying to do then I apologize.
        
               | cheschire wrote:
               | I don't discredit any crypto based solely on its ability
               | or inability to fulfill debts, public and private.
               | 
               | But I do wonder if the abstract nature of it will forever
               | hinder its ability to do so universally.
               | 
               | I'm also interested why Bitcoin Cash wasn't more
               | successful after the fork.
        
               | yownie wrote:
               | >I'm also interested why Bitcoin Cash wasn't more
               | successful after the fork.
               | 
               | you mean besides it being run by a bunch of crooks and
               | scam artists like CSW?
        
               | cheschire wrote:
               | I wasn't actually asking, but making a point. Thanks for
               | helping spell it out though!
        
               | TylerE wrote:
               | False. Gold and silver have intrinsic value beyond their
               | use as currency.
        
               | llmslave2 wrote:
               | Not for most people. They aren't going to smelt it down
               | and use it to build electronics or jewelry.
               | 
               | For most people the value is what they can receive for it
               | in trade. Which holds for all money.
        
               | jfengel wrote:
               | True, but only a minuscule fraction of it is used for
               | that purpose. If that were the sole source of its value,
               | it would be worth pennies per once.
        
               | roenxi wrote:
               | https://pse-info.de/en/scale/price - gold doesn't stand
               | out, there are a few similar ones
               | (Rhodium/Palladium/Iridium/Platinum). I haven't checked,
               | but we'd probably find the gold price sits in a boring-
               | looking distribution of the prices of other elements.
               | Probably an exponential or something that could be
               | mistaken for it.
               | https://en.wikipedia.org/wiki/Prices_of_chemical_elements
               | if you prefer wikipedia.
               | 
               | If it wasn't radioactive, poisonous and pyrophoric people
               | would probably all just leap into the Neptunium market.
        
               | TylerE wrote:
               | That is obviously false on it's face.
               | 
               | If it were only worth pennies an ounce, numerous
               | industries wouldn't be paying what they do for it. The
               | fact that many industries value it at several thousand
               | dollars an ounce is self-evident from their continued use
               | of it.
        
               | patrickthebold wrote:
               | This is interesting to think about: For gold I'd say the
               | demand is coming from both industries and from people who
               | want it as a store of value. If it was only used as an
               | industrial chemical, then surely the price would drop
               | because there would be less demand.
               | 
               | Some bitcoin advocates will talk about how useful it is
               | as a currency, and I wonder how much bitcoin is actually
               | used for purposes other then to hope you can sell it to
               | someone else for more than you paid.
        
               | TylerE wrote:
               | If the price dropped, it would be even more in demand and
               | reach equilibrium. Gold has several unique mechanical
               | properties, being the most corrosion resistant metal and
               | one of the most electrically conductive, as well as being
               | able to be flattened into extremely thin sheets and drawn
               | into extremely fine wire.
        
               | nradov wrote:
               | It's always hilarious when people who are unclear on the
               | basics themselves tell other to "research more". I
               | suppose it's the Dunning-Kruger Effect.
        
               | gosub100 wrote:
               | I don't see it that way. I see the person saying "stop
               | making tired arguments" or "don't ask questions that have
               | been answered hundreds of times".
        
               | jfengel wrote:
               | Fiat money has a difference: an army. It is issued by a
               | government which has the legitimate right to demand
               | taxes, paid in their currency, and deprive you of life
               | and liberty if you don't.
               | 
               | Ultimately the populace could repudiate the whole social
               | contract, which is also just consensus, but that's a far
               | bigger deal than mere money.
        
               | nradov wrote:
               | Well to be pedantic, in the USA at least the value of the
               | dollar is largely maintained by _civilian_ law
               | enforcement rather than the military. If you incur a tax
               | liability and fail to pay your debt in US dollars then
               | eventually the IRS will seize your assets and auction
               | them off to settle the debt. Due to the Posse Comitatus
               | Act, the Army doesn 't get involved.
        
               | enaaem wrote:
               | The true value of (fiat) money is derived from the fact
               | that contracts are denominated in that money and those
               | contracts are enforced by a central authority with guns.
               | No other assumption is needed in financial engineering.
        
               | ycombinatrix wrote:
               | Okay, fine. Everyone involved** agrees that mining the
               | next block is valuable.
        
               | palata wrote:
               | But that's irrelevant to the question above. The question
               | asks "isn't [this attack] the same as saying that if
               | everybody agrees that the USD is worthless, then it is
               | worthless?".
               | 
               | The answer is "no, it's not the same". The attack does
               | not require everybody to agree that the bitcoin is
               | worthless.
               | 
               | Obviously if everybody agrees that the bitcoin is
               | worthless, then it is worthless. But that's a separate
               | topic.
        
           | palata wrote:
           | That's a good question, but it is different. The equivalent
           | would be "if everyone just agrees that a bitcoin is worth
           | nothing, then it is worth nothing".
           | 
           | I don't know if I have a good comparison here, but maybe
           | something like "if the bank keeps your money for a little
           | longer before validating your transaction, they can use your
           | money for a little longer and make more money from it". Of
           | course if your bank says that a transaction takes 1 year, you
           | will go to another bank. But if they say it takes a day...
        
         | copirate wrote:
         | > If a pool can set up a situation where they mine a block and
         | wait X seconds to reveal it, they can force other miners to
         | waste X seconds of has power and gain an advantage.
         | 
         | How is it wasted if they work on the current chain? If they
         | find a block during those X seconds, they'll propagate it
         | before the waiting pool does. The waiting pool will then just
         | lose the revenue from the block they put on hold. They're the
         | ones wasting mining time when that happens, while the others
         | never do.
        
           | RealityVoid wrote:
           | Right, but the odds of this happening is small(ish) - I'm
           | certain there is a sweet spot for witholding time. If they
           | don't find a block within the time interval, then effectively
           | all the work for that time is "wasted" by the other
           | participants since it could not have been put on the chain
           | anyway AND the witholder has a headstart of a couple of
           | seconds searching for a new block.
        
             | copirate wrote:
             | Wasting time would mean not receiving the rewards if they
             | find a block. But that's not the case here. If they find a
             | block within the time interval, they get the rewards (and
             | the withheld block is discarded).
        
             | adgjlsfhk1 wrote:
             | the odds depend on how much hash power you have. if you're
             | at 5% of the network you can wait longer than if you're at
             | 1%. the other really big problem here is it creates
             | incentives for miners to work together to be able to delay
             | longer
        
           | yellow_lead wrote:
           | I might be wrong but I think it's like this..
           | 
           | A finds a block after 1 minute, then powers off and waits for
           | another minute. They reveal the block after 2 minutes.
           | 
           | B searches for the block for 2 minutes.
           | 
           | After 2 minutes, A has used 1 minute of their compute, and B
           | has used 2.
        
             | copirate wrote:
             | But the time spent by B is not wasted. If they find a block
             | between minute 1 and 2, their block will be accepted, and A
             | just lose the reward of the block they found.
        
               | palata wrote:
               | When you reveal a block, it's not accepted
               | instantaneously. When two competing blocks are revealed
               | "roughly at the same time", it ends up in two competing
               | chains.
               | 
               | If B finds a block between minute 1 and 2, they start
               | working on their competing chain, but A is already
               | working on theirs. And A had a headstart because it
               | started working on it somewhere between minute 1. So it's
               | more likely that A's fork wins the race in the end.
        
               | copirate wrote:
               | But the head start doesn't change anything. At this point
               | A is mining on their block, B is mining on theirs.
               | There's no advantage.
               | 
               | I'd even say that B is slightly more likely to keep their
               | reward because they started propagating their block
               | earlier, so it's more likely other miners are mining on
               | this block.
               | 
               | If A finds a second block between minute 1 and 2, then
               | they win, but it would be the same if the didn't withhold
               | their block.
               | 
               | When A is mining on their hidden block, they mine for a
               | potential height of 2 that would win against a miner only
               | able to push a height of 1. But by doing that they put
               | the block they found at risk of being abandoned because
               | another miner found a block in the meantime.
               | 
               | So if you find a block, you get almost 100% chance it'll
               | stay if you publish it immediately. If you withhold it
               | and find another one you get 100% chance of keeping your
               | 2 blocks. If you don't find that 2nd one, you get <50%
               | chance of your block to be the main chain (depending on
               | time of reaction of another block being published, and
               | connectivity). On the other hand, if you don't withhold
               | it and find 2 blocks in a row, you also get almost 100%
               | chance of keeping your 2 blocks. I fail to see how
               | withholding is profitable.
        
               | palata wrote:
               | > I fail to see how withholding is profitable.
               | 
               | Because you keep ignoring the part where it is profitable
               | :-).
               | 
               | > If A finds a second block between minute 1 and 2, then
               | they win, but it would be the same if the didn't withhold
               | their block.
               | 
               | Except that by withholding their block, they got a
               | headstart so they are more likely to find the second
               | block. So it's not the same.
               | 
               | And you keep ignoring the fact that they don't
               | necessarily have to wait until someone else finds a
               | competing block. Maybe a winning strategy is to always
               | withhold the block for 5 seconds. If you slightly
               | increase your likelihood to find the winning block, you
               | increase your profit, and that's the whole point.
               | 
               | With the interesting consequence (and that's the game
               | theory part) where if everybody starts withholding their
               | block for 5 seconds, then it changes the winning
               | strategy.
        
               | copirate wrote:
               | > Except that by withholding their block, they got a
               | headstart so they are more likely to find the second
               | block. So it's not the same.
               | 
               | Withholding their block (5s or whatever) doesn't make
               | them more likely to find the second block. The
               | probability of finding a block is always the same, given
               | a hashrate.
               | 
               | They are the only ones mining on this particular chain,
               | but that's not an advantage either. How mining on a
               | hidden chain is an advantage?
               | 
               | On the other hand, withholding certainly makes them more
               | likely to lose the reward of the block.
        
               | adgjlsfhk1 wrote:
               | the key to realize is that this strategy only makes sense
               | if you have a considerable fraction of total hashrate. If
               | you have 10% hashrate, delaying for 1 block period gives
               | you a 10% chance of finding another block on top (that no
               | one else can search for because you haven't published the
               | first one).
        
               | copirate wrote:
               | But by withholding you also increase the risk that your
               | first block will never end up in the main chain (if the
               | remaining 90% find a block while you're withholding).
               | 
               | And you would sill have 10% chance of mining another
               | block if you don't withhold.
               | 
               | What advantage does withholding give you?
        
               | palata wrote:
               | > What advantage does withholding give you?
               | 
               | One last time. By withholding, you have a headstart on
               | the next block. If you can mine for longer, you increase
               | your chances.
        
               | Majromax wrote:
               | > They are the only ones mining on this particular chain,
               | but that's not an advantage either. How mining on a
               | hidden chain is an advantage?
               | 
               | It's easier to see the argument if you have a head start.
               | Imagine you've somehow created a private chain that's 10
               | blocks ahead of the public chain. You could publish that
               | now and earn 10 blocks of reward, or you could continue
               | mining until the lead diminishes to 0 blocks, earning the
               | same 10 blocks of reward plus however many blocks you've
               | mined in the meantime.
               | 
               | If you have 50%+e of the hash rate on the network, this
               | argument would have you bully other miners out by almost
               | always stranding their blocks, since in expectation
               | you'll mine blocks faster than your competitors.
               | 
               | The insight is that this same situation can happen
               | probabilistically with a finite but non-majority fraction
               | of the hash rate on the network. With 49% of the hash
               | rate you'll still be able to build a private chain some
               | fraction of the time, so waiting a little bit to see if
               | this occurs might have positive expected value.
        
               | copirate wrote:
               | But to get 10 blocks ahead you have to withhold blocks
               | before knowing you'll be ahead. If you don't get ahead,
               | you'll likely lose the reward of the blocks you withheld.
               | 
               | So, you have to risk a lot of rewards, and for what
               | potential gain? If you win you get to discard some blocks
               | of others. You don't get more rewards, you just make
               | others earn less (and you push the difficulty down a
               | bit).
               | 
               | I can see how you get a chance to double spend, though.
               | If you want to double spend a transaction with N
               | confirmations, you've to be N+1 blocks ahead in your
               | hidden chain, publish your first transaction, wait for N
               | confirmations on the public chain, and you publish your
               | chain that's still 1 block ahead (and includes your
               | double spend transaction).
               | 
               | Indeed, it's not "51% expensive", but it's still very
               | expensive because of the rewards lost during the failed
               | attempts before you get ahead enough. Actually, it might
               | even be more expensive, because with 51% you're
               | guaranteed to get ahead enough at some point, so you
               | don't really risk your rewards (if you can maintain 51%).
        
               | palata wrote:
               | > But to get 10 blocks ahead you have to withhold blocks
               | before knowing you'll be ahead.
               | 
               | You KNOW you are ahead, because you found a block and
               | nobody else has published a block.
        
               | palata wrote:
               | > The probability of finding a block is always the same,
               | given a hashrate.
               | 
               | I think you are missing something very basic here: the
               | longer you compute, the higher the likelihood that you
               | will find the hash before the others.
               | 
               | The extreme case being that if you can try ALL the
               | possibilities before the others can start, then you are
               | guarantee to find the solution before them.
        
               | basilikum wrote:
               | That's only mathematically true. The advantage is way too
               | small to be relevant.
               | 
               | Your advantage is having exhausted a fraction of the
               | search space. But that fraction is tiny.
               | 
               | You're trying to find a hash with a value below a certain
               | threshold (simplified said, a hash starting with a
               | certain amount of zeroes). You do this by trying random
               | inputs to the hash function. Every input has the same
               | probability of getting an output that is low enough in
               | value. You are not advancing by having tried other
               | inputs. It's practically equivalent to rolling multiple
               | dices until enough of them show a one. Every roll has the
               | same probability of succeeding regardless of the rolls
               | before.
        
             | _heimdall wrote:
             | In this case A would be at an advantage to spend the 2
             | minutes looking for the next block. If they happen to find
             | another block quickly they could release then in quick
             | succession.
             | 
             | The benefit there is that if another miner released a block
             | before that 3 minutes this miner still can release their
             | first block and has already spent 2 minutes working on a
             | block that could better validate their first block now that
             | there are competing chains.
        
           | emil-lp wrote:
           | If you mine a block without revealing it, not only are you
           | the only one that can mine the next block after that, but
           | everyone is mining on the "wrong head". There's of course the
           | risk that someone finds a different head in the meantime, but
           | otherwise, you waste competitors' resources, while you get an
           | advantage on the next block.
        
             | copirate wrote:
             | They are not mining on the wrong head. They are mining on
             | the current head. If they find a block it will be accepted
             | as the new head and the withheld block will be rejected, so
             | it's not wasted mining time at all.
        
               | palata wrote:
               | Not an expert, but I have two thoughts:
               | 
               | 1. They don't have to wait until another miner finds a
               | block, they can just wait "for some time" and then
               | release their block. All that time gives them the edge
               | for the next block.
               | 
               | 2. My understanding is that if two different blocks are
               | found concurrently _for the same head_ , then the network
               | waits for the next block to select which "new head" is
               | accepted. I.e. when there are competing chains, the
               | longer chain wins. So I could imagine that a strategy
               | could be to wait until some other miner announces their
               | block and release yours precisely at that time, hence
               | creating two competing chains. But you presumably have an
               | edge because you have already been mining for a while on
               | top of your block.
        
               | copirate wrote:
               | There's no edge. Having spent time mining in the past
               | doesn't increase your odds of finding a block in the
               | future.
        
               | adwn wrote:
               | The idea is that you can start with the next head
               | _earlier_ than all the others, giving you an edge in
               | being the first to find the next block.
        
               | copirate wrote:
               | But what do they gain by doing that? What's the edge?
               | Starting earlier doesn't give you any advantage.
        
               | palata wrote:
               | > Starting earlier doesn't give you any advantage
               | 
               | It's a race. Starting earlier obviously gives an
               | advantage?!
        
               | copirate wrote:
               | No it's not a race, it's a lottery.
               | 
               | It would be like saying you've an edge if you start
               | earlier at the roulette.
        
               | palata wrote:
               | I think you're confused.
               | 
               | In a lottery, the more tickets you buy, the higher your
               | chances to have the winning number.
               | 
               | If we played with a roulette and said "the goal is to be
               | the first to have a winning number at the roulette" and I
               | could try 50 times before you started, _obviously_ I
               | would be more likely to win our game, wouldn 't I?
        
               | copirate wrote:
               | > In a lottery, the more tickets you buy, the higher your
               | chances to have the winning number.
               | 
               | Yes, and it's exactly the same in bitcoin with the
               | hashing power. Each hash is a ticket.
               | 
               | > If we played with a roulette and said "the goal is to
               | be the first to have a winning number at the roulette"
               | and I can try 50 times before you start, obviously I am
               | more likely to win our game, am I not?
               | 
               | In bitcoin the goal is not to be the first. The goal is
               | to find a winning hash that's on a chain that will not be
               | abandoned. As soon as a new block is propagated you start
               | mining on the new head. It doesn't change anything that
               | you previously worked on another chain. The time spent on
               | the previous chain is not wasted, unless finding a block
               | wouldn't have got you the reward.
               | 
               | There is a kind of a race if 2 blocks are found
               | simultaneously. But that's not really what this
               | discussion is about, and in this case the outcome depends
               | mostly on network connectivity.
        
               | palata wrote:
               | It is precisely what this discussion is about. From the
               | article:
               | 
               | > The key idea behind this strategy, called Selfish
               | Mining, is for a pool to keep its discovered blocks
               | private, thereby intentionally forking the chain. The
               | honest nodes continue to mine on the public chain, while
               | the pool mines on its own private branch. If the pool
               | discovers more blocks, it develops a longer lead on the
               | public chain, and continues to keep these new blocks
               | private. When the public branch approaches the pool's
               | private branch in length, the selfish miners reveal
               | blocks from their private chain to the public.
               | 
               | > In bitcoin the goal is not to be the first. The goal is
               | to find a winning hash that's on a chain that will not be
               | abandoned.
               | 
               | The goal is to be the first (or very close to the first),
               | because it makes it much more likely that your chain will
               | not be abandoned. If you wait 2 days before you reveal
               | your block, obviously it will be abandoned...
        
               | copirate wrote:
               | > The key idea behind this strategy, called Selfish
               | Mining, is for a pool to keep its discovered blocks
               | private, thereby intentionally forking the chain. The
               | honest nodes continue to mine on the public chain, while
               | the pool mines on its own private branch. If the pool
               | discovers more blocks, it develops a longer lead on the
               | public chain, and continues to keep these new blocks
               | private. When the public branch approaches the pool's
               | private branch in length, the selfish miners reveal
               | blocks from their private chain to the public.
               | 
               | I don't understand how this scenario is beneficial. If
               | the selfish miner doesn't have 51% of the hashing power,
               | they can discover more blocks than the public chain only
               | if they are very lucky. They don't know in advance that
               | they will be that lucky. Withholding blocks in hope of
               | this luck means putting these blocks at a very high risk
               | of being discarded and losing the rewards. Why would they
               | do that, exactly? If they get lucky, they get the rewards
               | of their chain, and discard the rewards of the other
               | miners. If they don't, they lose a lot of rewards. On the
               | other hand, if they just publish the blocks they find,
               | they're almost guaranteed to get the rewards. Why take
               | the risk? It sounds like putting your own rewards at risk
               | just to put others' rewards at risk. It looks like the
               | risks even out.
               | 
               | > The goal is to be the first (or very close to the
               | first), because it makes it much more likely that your
               | chain will not be abandoned.
               | 
               | Yes, if there are blocks that are found at almost the
               | same time. But that's not the situation discussed here.
               | 
               | In other situations, being first doesn't matter. If a
               | miner finds a block before you do, then you just start
               | mining on top of their block. You haven't lost anything.
        
               | palata wrote:
               | > Yes, if there are blocks that are found at almost the
               | same time. But that's not the situation discussed here.
               | 
               | It VERY MUCH is.
               | 
               | Of course if you take another scenario that doesn't make
               | sense, then it doesn't make sense :-).
               | 
               | > They don't know in advance that they will be that
               | lucky.
               | 
               | Whenever you find a block, you know you are one of the
               | first to find it. It's obvious because nobody else has
               | published a block. So you know you are lucky right now.
               | You can decide to wait 1, 2, 5, X seconds before you
               | reveal your block and start mining the new block in the
               | meantime.
               | 
               | Maybe you just mine for 5 seconds before revealing the
               | block, and that's the winning strategy. Maybe you wait
               | until someone else publishes their block and you
               | immediately reveal yours, ending up with two competing
               | chains but knowing that you had a headstart with yours.
               | 
               | The detail of whether or not this is profitable, and how
               | exactly you should do it (Wait X seconds? Wait until
               | someone publishes a block?) is statistics and game theory
               | ("What if the others are also withholding their blocks
               | now? What is their strategy?"). The whole question is
               | whether or not there is a practical, profitable strategy
               | doing that.
        
               | sjducb wrote:
               | There is an advantage because occasionally you find the
               | second block while the first block is still secret, then
               | you release the two blocks in quick succession. That's
               | the edge.
        
               | svara wrote:
               | You can determine statistically whether you have found a
               | block relatively early, and conversely whether other
               | miners are unlikely to find one soon.
               | 
               | So you can get a head start on the next block from the
               | likely new head block you've found.
               | 
               | It only works on average of course, you might be the one
               | wasting resources if someone else published a block while
               | you're withholding yours, but the trick is for you to
               | gain an edge on average.
               | 
               | Now what happens if everyone is doing that calculation?
               | That's where you need to do the game theory analysis
               | (which I haven't and don't claim to understand).
        
               | copirate wrote:
               | > You can determine statistically whether you have found
               | a block relatively early, and conversely whether other
               | miners are unlikely to find one soon.
               | 
               | Finding a block relatively early doesn't affect the odds
               | of others finding a block soon. The odds are always the
               | same, each hash is an independent event.
               | 
               | I don't see why withholding would get you an edge on
               | average. If the others find a block while you're
               | withholding, you lose your reward. If you find another
               | block before them, you get the rewards of 2 blocks,
               | exactly like if the same happened but you didn't
               | withhold.
               | 
               | The only way for you to have an advantage is if you find
               | a 2nd block at the same time as another one finds one on
               | the other chain. You can then publish a height of 2 vs a
               | height of 1, so you win. But to do that you have to first
               | put your first block reward at high risk by withholding
               | it. I don't think the odds are in your favor here.
        
               | svara wrote:
               | Yeah, I was thinking about this wrong. I don't think it
               | works.
               | 
               | Edit: I think the strategy does work, but a little
               | differently: if you withhold a block and someone else
               | finds one while you do so, you can still publish yours
               | and win a race with a certain probability, i.e. the
               | expected loss is not as high as one might think.
               | 
               | Then, if you do that and if you have enough hash power,
               | you can end up mining a private chain ahead of the public
               | one often enough, so that the loss you take is less than
               | the loss others take through the hash power they are
               | wasting because of you doing this.
        
             | georgefrowny wrote:
             | What makes it more likely that your first block ends up the
             | next head and you're not wasting your own time on the
             | second one if someone beats you to the first one while
             | you're holding off?
        
         | jcfrei wrote:
         | Take a look at the recently mined blocks. there are some miners
         | that very frequently mine two blocks within quick succession,
         | like just now for example: Block 930256:
         | https://www.blockchain.com/explorer/blocks/btc/930256 Followed
         | by block 930257:
         | https://www.blockchain.com/explorer/blocks/btc/930257 The
         | second block is usually almost empty.
        
           | Bootvis wrote:
           | This can have another explanation as well: the moment a block
           | is found, the miner starts building on top of the previous
           | block but hasn't constructed a new full block of transactions
           | yet as that costs a bit of time to calculate and distribute.
           | In this period, a new block could be found.
        
       | spir wrote:
       | This is good analysis. The main longitudinal aspect omitted is
       | that the profitability of the attack goes up as long as the price
       | of BTC doesn't double or more each halving.
       | 
       | In ~6 more years, Bitcoin will undergo two more halvings, so if
       | the price of BTC is not ~400k by then, then attack will have
       | become more feasible.
        
         | beenBoutIT wrote:
         | In the near future every nation state will be vying for the
         | largest stake of the BTC mining pie and the BTC race will be
         | bigger than the Space Race and the Nuclear Arms Race combined
         | and adjusted for inflation.
        
           | UltraSane wrote:
           | Why? BTC is not just worthless, it has negative value due to
           | how much electricity it takes to securely mine new blocks.
        
             | jksmith wrote:
             | Did you read the paper? There exists a technology that has
             | purely enforceable property rights. What is that actually
             | worth? I don't know.
             | 
             | Yeah yeah, I've read the arguments about liquidity issues,
             | shutting down the rails, making it illegal to trade, etc.
             | but that's beside the point and depends on a thousand
             | future variables to play out. So I don't know if btc will
             | make it or not, but I do know property rights mean
             | everything to humans. They literally determine whether not
             | one is a slave (I am my own property). So just the ability
             | to have a technology enables pure property rights to a
             | world where nobody really has enforceable property rights
             | over anything seems pretty interesting to me.
        
               | nradov wrote:
               | Property rights are enforced with guns.
        
               | logicchains wrote:
               | That's why Monero is superior; no amount of guns is going
               | to help somebody steal property that they don't know you
               | have.
        
               | basilikum wrote:
               | A 5$ wrench bar is enough to make you give me all the
               | moneroj you have eventually. I won't know when that point
               | is and will just continue using the wrench until I am
               | sufficiently sure you have given me all.
        
               | jksmith wrote:
               | So is theft. Depends on who has the most guns.
        
               | munksbeer wrote:
               | > So just the ability to have a technology enables pure
               | property rights to a world where nobody really has
               | enforceable property rights over anything seems pretty
               | interesting to me.
               | 
               | Bitcoin doesn't enforce property rights. The only thing
               | you own is your bitcoin. The fact that I "own" my house
               | and the land it is built on is enforced by the state with
               | guns.
        
               | jksmith wrote:
               | You're not getting what I'm saying. Before this
               | technology, the concept of property rights could not be
               | defended, depending on the attacker. This tech allows
               | that, even if it is just for one use case.
        
             | ravenstine wrote:
             | That's like saying cars have negative value because of how
             | much oil it takes to run them.
        
               | standeven wrote:
               | But cars are useful.
        
               | pcthrowaway wrote:
               | Cars have the benefit of transporting humans and goods
               | around.
               | 
               | It's more like saying a hypothetical car which moves
               | itself by using gasoline as a propellant rather than fuel
               | for its combustion engine would have negative value.
               | 
               | Sure, using fuel (of all things) for propulsion would be
               | one way to move a vehicle, but it would be inefficient by
               | design.
               | 
               | Bitcoin, at least, was created during a time where there
               | was no alternative to security-by-inefficency, but PoS
               | and other consensus mechanisms are pretty battle-tested
               | now
        
               | sanskritical wrote:
               | Bitcoin has the benefit of being the first way in human
               | history of being able to transfer value between two
               | countries in a way that a corrupt bureaucrat, judge, or
               | customs official can't freeze, reverse, or steal it.
               | That's the benefit Bitcoin brings humanity, and to me, I
               | prefer it to having a car.
               | 
               | Proof of Stake is an absurd security proposition.
               | Stakeholders are immediately centralized. In every single
               | PoS coin, the governance immediately becomes the
               | exchanges because they always hold the most coins. They
               | can and have used this to guide PoS coins towards
               | governance unfavorable to the users, like as happened
               | with Steem.
        
               | UltraSane wrote:
               | Bitcoin consumes 20 to 40GW to process 7 transactions per
               | second. Using 30GW means about 4 billion joules per
               | transaction. And transactions per second don't scale with
               | more electricity. It is the least efficient technology
               | ever created.
        
               | johnnienaked wrote:
               | Diminishing value certainly it's called depreciation
        
             | pawelduda wrote:
             | It's worth around 85k USD at the time you wrote the comment
        
           | fruitworks wrote:
           | why
        
       | bujkopl wrote:
       | This article is FUD. No one is spending $30B+ for an attack that
       | _gasp_ extends the required confirmations to a few hours until a
       | re-org can be achieved and accounts settled.
       | 
       | In fact, wiping out the derivative markets would be seen as a
       | net-postive by most individual hodlers.
        
         | comradesmith wrote:
         | I believe the article reached the same conclusion you did
        
         | nativeit wrote:
         | You forgot to do your own research and read the article.
        
       | w10-1 wrote:
       | TIL the scale of bitcoin derivatives in 2020 (hence volatility):
       | ~2T on 2B market activity. Jeepers!
       | 
       | --- Starting in late 2020, as shown in The Economist's graphic,
       | the spot market in Bitcoin became dwarfed by the derivatives
       | markets. In the last month $1.7T of Bitcoin futures traded on
       | unregulated exchanges, and $6.4B on regulated exchanges. Compare
       | this with the $1.8B of the spot market in the same month. ---
        
         | onion2k wrote:
         | Why would you expect the scale of the derivatives to be related
         | to the scale of the spot market, especially if the derivatives
         | are cash-settled futures? One is basically gambling on the
         | price of BTC going up or down, and the other is trading the
         | actual BTC, right?
        
           | phonicwheel wrote:
           | How is trading the actual BTC not also gambling on the price
           | of BTC going up or down?
        
             | SiempreViernes wrote:
             | You might buy BTC to actually spend it, say on paying a
             | ransomware vendor.
        
               | tatersolid wrote:
               | We're calling these organized criminals _vendors_ now?
        
             | onion2k wrote:
             | It's not really, but the difference is that I'm limited by
             | the supply of BTC, and it requires that I actually have the
             | money to make the 'bet' at the start. That restricts the
             | size of the spot market.
             | 
             | If I'm buying futures I can enter into a contract that says
             | "I'll buy a contract for 1BTC that says BTC is going to go
             | from $88.5k to $98.5k in 1 year." I don't actually hand
             | over any money. In a year's time, if BTC is now $100k the
             | person who agreed on the contract gives me $10k. If it
             | doesn't go up then I owe the seller $10k. The futures
             | contract is settled in cash - no BTC is involved.
             | 
             | Right now though, I don't have a $88.5k to spend on BTC, so
             | the spot market isn't an option. I probably could find $10k
             | in a year's time so a bet on a BTC future might be viable.
             | The actual derivative 'value' isn't real though. The only
             | money changing hands is the delta of the change in value
             | when the contract is settled.
             | 
             | (Caveat: I am a total noob at finance stuff so this could
             | be quite wrong. One of the many reasons I will not be
             | buying that futures contract. :) )
        
               | johnnienaked wrote:
               | It's very wrong. Futures contracts on traditional
               | exchanges have no counterparty risk and require the
               | deposit of a significant amount of upfront capital as
               | collateral. If the spot price of the underlying moves in
               | either direction, debits or credits are made to and from
               | each margin account and if you don't have the money to
               | cover a margin call, the contract gets closed.
        
               | tommek4077 wrote:
               | Future markets give traders leverage of 100x sometimes or
               | more. Margin requirements are much lower than trading
               | spot.
        
               | johnnienaked wrote:
               | Margin requirements for trading spot are zero, though
               | initial capital requirements are obviously, well,
               | whatever spot is.
               | 
               | Futures contracts aren't just pieces of paper traded
               | between people, they are actual promises to pay for
               | physical delivery of the underlying.
               | 
               | It's not surprising to me that crypto people consider
               | them nothing more than leveraged gambling slips but
               | that's really not how one should think about them.
               | Personally I think crypto needs far heavier regulation
               | than it gets.
        
             | _heimdall wrote:
             | Its hard for me to consider owning the underlying asset as
             | gambling compared to owning paper bets on the future value.
             | In the former you are owning it _today_ , in the later you
             | are betting only on what it will cost to own later.
        
             | gosub100 wrote:
             | Derivatives can be structured in a time-constrained manner
             | that requires them to go up/down in a specific time window,
             | thus amplifying the gains/losses. Also there's generally no
             | way to short an asset without borrowing them with a
             | contract to pay them back (which requires timing the market
             | move and paying rent on the asset). This is something that
             | options contracts solved.
        
           | Turneyboy wrote:
           | Well for one with a gigantic derivatives market compared to
           | the underlying one it becomes relatively cheap to manipulate
           | the underlying market.
           | 
           | If you can make a gigantic bet on the price going up and then
           | buy a large amount of Bitcoin that moves the price up you can
           | win from that. See the Jane street India derivatives market
           | issue.
        
           | rcxdude wrote:
           | I dunno, ask India and Jane Street. That's the same basic
           | situation: when the derivative market betting on the price
           | going up or down is much larger than the market that actually
           | sets that price, it's ripe for arbitrage/market manipulation
           | by a player big enough to move the market (which one you
           | think it is depends on whether you're one of the gamblers
           | getting fleeced or the one taking their money).
        
           | spectralista wrote:
           | Because at that scale, the tail is wagging the dog and it is
           | not even close.
        
       | UltraSane wrote:
       | Bitcoin is the least efficient technology ever created. There is
       | no limit to how much electricity it can consume just to handle 7
       | transactions per second. No matter HOW much electricity it uses
       | this value will never increase.
        
         | hggh wrote:
         | This solution to this issue is extremely simple, but I bet it
         | will never be implemented in Bitcoin BTC. That's one of the
         | reasons why it forked in 1 August 2017.
        
         | rlpb wrote:
         | There is a limit. The cost of electricity required is bounded
         | by the value of the reward (block reward plus transaction
         | fees). The value of the reward is bounded too, since the
         | "import" of electricity into the Bitcoin economy is
         | inflationary.
        
           | UltraSane wrote:
           | Then making the block reward halve every 4 years is a pretty
           | strange decision.
        
       | sebbyBinx wrote:
       | Part of this post addresses the economics of creating a 6 block
       | re-org. This makes sense as 6-confimations is the standard for
       | Bitcoin finality _today_.
       | 
       | However, as Bitcoin's security inevitably weakens over the coming
       | years due to diminishing miner rewards (denominated in BTC), I
       | believe this "6-confimation" acceptance policy will change to
       | include not only the number of confirmations, but the timing of
       | those confirmations as well. Consider a scenario where an
       | exchange deciding whether a tx with 6-confirmations that took 4
       | hours to arrive (this happens occasionally) is safe to consider
       | finalized/settled. Even though 6-confimations may be considered
       | safe by today's acceptance policies, this tx would still have a
       | high probability of double spend due to the assumed 4-hour long
       | wait for the 6 confirmations (as the attacker would have 4 hours
       | to produce 7 blocks instead of the normal/expected 1 hour).
       | Instead of ignoring block interarrival timing, it may make sense
       | to include block timing as part of an acceptance policy.
       | 
       | So, going forward Bitcoin acceptance policies may change from
       | today's 6-confirmation standard to something more complicated
       | that involves the amount of time those blocks took to arrive.
       | This would significantly enhance Bitcoin's double spending
       | resistance without adding/altering any code and may give the
       | network a much needed security boost in the coming years to
       | prevent the attack discussed in the post.
        
         | mrb wrote:
         | _" Bitcoin's security inevitably weakens over the coming years
         | due to diminishing miner rewards (denominated in BTC)"_
         | 
         | That's incorrect. Security scales with USD-denominated rewards,
         | not BTC-denominated. And there are 16 years of real-world data
         | showing they have been generally increasing, so a healthy sign
         | that the Bitcoin experiment is working:
         | 
         | https://newhedge.io/bitcoin/block-reward-per-block
         | 
         | And not only that, but rewards are still expected to stabilize
         | _even when measured in BTC_ (thereby not relying on an increase
         | of BTC 's price) as they are progressively composed more and
         | more of tx fees instead of newly mined BTC.
         | 
         | It's puzzling to me why some still don't understand the
         | systemic incentives that make all this work as it has for 16
         | years and counting...
        
           | free_bip wrote:
           | How are you so confident that it will _never_ weaken?
           | Especially since there will come a time when the block reward
           | is literally 0.
        
             | mrb wrote:
             | Tx fees make up a bigger and bigger fraction of miner
             | rewards over time.
        
               | officialchicken wrote:
               | Rewards are also a permanent infinite money glitch that
               | last in perpetuity? Or won't be changed in the future?
        
               | rcxdude wrote:
               | Is a store of value that requires a significant fraction
               | of it be eaten up by transaction fees to maintain
               | security going to be actually useful in the long term?
        
               | _heimdall wrote:
               | With regards to transaction fees, bitcoin is already not
               | particularly useful today. It can make sense to be used
               | as an alternative to wire transfers where you only
               | occasionally send a transaction, but it isn't useful as a
               | currency and any day to day transactions have to happen
               | off chain and not use bitcoin at all.
        
               | jcfrei wrote:
               | transaction fees are not increasing though, so they can't
               | offset miner rewards. they have been in the $100k-$200k
               | per day range for a long time, with only occasional
               | breakouts:
               | https://www.blockchain.com/explorer/charts/transaction-
               | fees-... and the trend is not to the upside. in fact with
               | the arrival of ETFs in 2024 the trend is clearly
               | downwards.
        
               | Saline9515 wrote:
               | Rewards decrease due to halving and there is no guarantee
               | that transaction fees will compensate it.
        
               | buzzin__ wrote:
               | But transaction fees reset to zero on each block. If
               | relying solely on transaction fees, why would you mine if
               | they are zero? So, on the start of each block, miners
               | will shutdown, or perhaps switch to a different currency
               | where it would be profitable to mine. This surely weakens
               | the security of Bitcoin.
        
           | officialchicken wrote:
           | > It's puzzling to me why some still don't understand the
           | systemic incentives...
           | 
           | Then I guess you're the type who will be really surprised to
           | learn that with diminishing rewards comes increasing
           | consolidation.
           | 
           | > ... that make all this work as it has for 16 years and
           | counting...
           | 
           | That's convenient way to memory hole the market flash
           | crashes, network forks, the blocks mined without consensus,
           | and everything bad that happened over that timeframe.
        
         | copirate wrote:
         | If the attacker is waiting for a lucky event to occur (finding
         | more blocks than others while having less than 51% of the
         | mining power) it means that they are constantly wasting mining
         | time. That in itself is a huge cost (operational cost and block
         | rewards thrown away), but it also means that they can't predict
         | when it will happen. A double spend attack must be planned in
         | advance because the first transaction must occur at the
         | beginning of the attack. I'm not sure how they could constantly
         | try double spends without risking losing the money each time
         | the attack doesn't happen.
         | 
         | I don't see how it could be profitable. If it can't be
         | profitable, then the risk of someone doing it is pretty low. If
         | they already have the necessary hardware, they'd be much better
         | off mining.
        
           | Majromax wrote:
           | > I'm not sure how they could constantly try double spends
           | without risking losing the money each time the attack doesn't
           | happen.
           | 
           | If you're not trying to profit from the double spend itself
           | but rather from a collapse following a proven double-spend,
           | you can double-spend the bitcoins to yourself.
        
         | ur-whale wrote:
         | > However, as Bitcoin's security inevitably weakens over the
         | coming years due to diminishing miner rewards (denominated in
         | BTC),
         | 
         | Says you, without a hint of a rationale backing your argument.
         | 
         | It seems to me that the historical hashing rate curve tells a
         | different story.
         | 
         | And block rewards have been diminishing regularly (and very
         | predictably) pretty much since day one.
        
           | tromp wrote:
           | The hashing rate is not directly relevant. That's roughly
           | proportional to the daily dollar value of the reward times
           | the efficiency of the leading mining hardware. The latter has
           | gone up many orders of magnitude over the years.
           | 
           | > block rewards have been diminishing regularly
           | 
           | That's exactly what the poster you're replying to argued; the
           | BTC denominated block subsidy halves every 4 years, and so
           | without a corresponding doubling in price, the bitcoin
           | security budget keeps diminishing, at least until tx fees
           | start to dominate the subsidy.
        
         | nathias wrote:
         | you can accept bitcoin at any confirmation you want, it isn't a
         | policy
        
           | coldcity_again wrote:
           | in bitcoin terminology it is actually called policy rather
           | than consensus, meaning you can choose your own config and
           | still meet consensus rules.
        
         | _heimdall wrote:
         | > This would significantly enhance Bitcoin's double spending
         | resistance without adding/altering any code
         | 
         | I would have expected such security rules are part of the miner
         | code, no? Don't they need to consider rules related to the
         | comparative security level of a chain when decided which chain
         | to follow when multiple exist?
        
       | bellajbadr wrote:
       | you can wipe out Russia with thousands of nuclear bomb
        
       ___________________________________________________________________
       (page generated 2025-12-31 23:01 UTC)