A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer Network
Muoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu, Min Suk Kang
Abstract
Network adversaries, such as malicious transit autonomous systems (ASes), have been shown to be capable of partitioning the Bitcoin’s peer-to-peer network via routing-level attacks; e.g., a network adversary exploits a BGP vulnerability and performs a prefix hijacking attack (viz. Apostolaki et al. [3]). Due to the nature of BGP operation, such a hijacking is globally observable and thus enables immediate detection of the attack and the identification of the perpetrator. In this paper, we present a stealthier attack, which we call the EREBUS attack, that partitions the Bitcoin network without any routing manipulations, which makes the attack undetectable to control-plane and even to data-plane detectors. The novel aspect of EREBUS is that it makes the adversary AS a natural man-in-the-middle network of all the peer connections of one or more targeted Bitcoin nodes by patiently influencing the targeted nodes’ peering decision. We show that affecting the peering decision of a Bitcoin node, which is believed to be infeasible after a series of bug patches against the earlier Eclipse attack [29], is possible for the network adversary that can use abundant network address resources (e.g., spoofing millions of IP addresses in many other ASes) reliably for an extended period of time at a negligible cost. The EREBUS attack is readily available for large ASes, such as Tier-1 and large Tier-2 ASes, against the vast majority of 10K public Bitcoin nodes with only about 520 bit/s of attack traffic rate per targeted Bitcoin node and a modest (e.g., 5–6 weeks) attack execution period. The EREBUS attack can be mounted by nation-state adversaries who would be willing to execute sophisticated attack strategies patiently to compromise cryptocurrencies (e.g., control the consensus, take down a cryptocurrency, censor transactions). As the attack exploits the topological advantage of being a network adversary but not the specific vulnerabilities of Bitcoin core, no quick patches seem to be available. We discuss that some naive solutions (e.g., whitelisting, rate-limiting) are ineffective and third-party proxy solutions may worsen the Bitcoin’s centralization problem. We provide some suggested modifications to the Bitcoin core and show that they effectively make the EREBUS attack significantly harder; yet, their non-trivial changes to the Bitcoin’s network operation (e.g., peering dynamics, propagation delays) should be examined thoroughly before their wide deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 361ab559-7f2b-46d2-8115-e254754df15eCited by top-tier papers21
- Blockchain CensorshipAnton Wahrstätter, Jens Ernstberger, Aviv Yaish, Liyi Zhou et al.WWW 2024 · 60 citations
- On the Routing-Aware Peering against Network-Eclipse Attacks in BitcoinMuoi Tran, Akshaye Shenoi, Min Suk KangUSENIX Security 2021 · 28 citations
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 26 citations
- Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT ManipulationZheyuan He, Zihao Li, Ao Qiao, Xiapu Luo et al.S&P 2024 · 21 citations
- Using Throughput-Centric Byzantine Broadcast to Tolerate Malicious Majority in BlockchainsRuomu Hou, Haifeng Yu, Prateek SaxenaS&P 2022 · 17 citations
Builds on4
- On the Security and Performance of Proof of Work BlockchainsArthur Gervais, Ghassan O. Karame, Karl Wüst, Vasileios Glykantzis et al.CCS 2016 · 1,668 citations
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- SABRE: Protecting Bitcoin against Routing AttacksMaria Apostolaki, Gian Marti, Jan Müller, Laurent VanbeverNDSS 2019 · 86 citations
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang et al.S&P 2019 · 39 citations
Related papers
- Three Birds with One Stone: Efficient Partitioning Attacks on Interdependent Cryptocurrency NetworksMuhammad Saad, David MohaisenS&P 2023
- Routing Attacks on Cryptocurrency Mining PoolsMuoi Tran, Theo von Arx, Laurent VanbeverS&P 2024 · 7 citations
- Are Unreachable Nodes Truly Safe? Fully Eclipsing Monero's P2P Network!Ruisheng Shi, Jiaqi Zeng, Lina Lan, Shihan Zhang et al.CCS 2026
- Eclipse Attacks on Ethereum's Peer-to-Peer NetworkRuisheng Shi, Yuxuan Liang, Zijun Guo, Qin Wang et al.WWW 2026
- Eclipse Attacks on Monero's Peer-to-Peer NetworkRuisheng Shi, Zhiyuan Peng, Lina Lan, Yulian Ge et al.NDSS 2025
