Routing Attacks on Cryptocurrency Mining Pools
Muoi Tran, Theo von Arx, Laurent Vanbever
Abstract
Mining pools have been the driving force for ensuring the security of multiple proof-of-work (PoW) cryptocurrencies. Under the de facto protocol Stratum, pools allow miners to collaborate, discover new blocks, and earn rewards collectively. Recently, the blockchain community has been promoting the adoption of a more secure Stratum protocol known as Stratum V2. In this paper, we introduce Erosion, a novel network-level attack that applies to both Stratum and Stratum V2 protocols. The essence of the Erosion attack lies in its ability to disrupt connections between miners and a targeted mining pool, significantly impairing the miners’ contributed PoWs and reducing the victim’s mining power. We also discover a vulnerability in the Stratum V2 protocol that allows the adversary to persistently disrupt a connection by tampering with a single packet, thus enhancing the attack’s stealthiness. Our survey shows that the Erosion adversary can readily execute attacks against a significant majority (e.g., 91%) of mining pools across the top ten cryptocurrencies. We also observe an extreme mining centralization that enables Erosion adversaries to simultaneously target multiple pools and cryptocurrencies. Furthermore, our focused evaluation of pooled mining in Bitcoin reveals that thousands of different adversaries can gain control over the majority of Bitcoin mining power, with one potentially malicious Autonomous System capable of taking down 96% of the total mining power.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 08c9d165-71be-49a5-8c68-9ee7db40faa1Cited by top-tier papers2
- Deanonymizing Ethereum Validators: The P2P Network Has a Privacy IssueLioba Heimbach, Yann Vonlanthen, Juan Villacis, Lucianna Kiffer et al.USENIX Security 2025
- Is My RPC Response Reliable? Detecting RPC Bugs in Blockchain Client under ContextZhijie Zhong, Yuhong Nan, Mingxi Ye, Qing Xue et al.ICSE 2026
Related papers
- A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer NetworkMuoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu et al.S&P 2020 · 126 citations
- BDoS: Blockchain Denial-of-ServiceMichael Mirkin, Yan Ji, Jonathan Pang, Ariah Klages-Mundt et al.CCS 2020 · 1 citation
- SmartPool: Practical Decentralized Pooled MiningLoi Luu, Yaron Velner, Jason Teutsch, Prateek SaxenaUSENIX Security 2017 · 144 citations
- Three Birds with One Stone: Efficient Partitioning Attacks on Interdependent Cryptocurrency NetworksMuhammad Saad, David MohaisenS&P 2023
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 26 citations
