Eclipse Attacks on Monero's Peer-to-Peer Network
Ruisheng Shi, Zhiyuan Peng, Lina Lan, Yulian Ge, Peng Liu, Qin Wang, Juan Wang
Abstract
—Eclipse attack is a major threat to the blockchain network layer, wherein an attacker isolates a target node by monopolizing all its connections, cutting it off from the rest of the network. Despite the attack’s demonstrated effectiveness in Bitcoin (Usenix’15, SP’20, Usenix’21, CCS’21, SP’23) and partially in Ethereum (NDSS’23, SP’23), its applicability to a wider range of blockchain systems remains uncertain. In this paper, we investigate eclipse attacks against Monero, a blockchain system known for its strong anonymity and pioneering the use of Dandelion++ (the state-of-the-art blockchain network layer protocol for transaction privacy protection). Our analysis of Monero’s connection management mechanism reveals that existing eclipse attacks are surprisingly ineffective against Monero. We accordingly introduce the first practical eclipse attack against Monero by proposing a connection reset approach, which forces the target node to drop all benign connections and reconnect with malicious nodes. Specifically, we outline two methods for executing such an attack. The first one exploits the private transaction mechanisms, while the second method leverages the differences in propagation between stem transactions and fluff transactions under Dandelion++. Our attack is not only applicable to Monero but to all blockchain systems utilizing Dandelion++ and similar connection management strategies. We conduct experiments on the Monero mainnet. Evaluation results confirm the feasibility of our attack. Unlike existing eclipse attacks, our connection reset-based approach does not require restarting the target node, significantly accelerating the attack process and making it more controllable. We also provide countermeasures to mitigate the proposed eclipse attack while minimizing the impact on Monero. In addition, we have ethically reported our investigation to Monero official team
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Eclipse Attacks on Ethereum's Peer-to-Peer NetworkRuisheng Shi, Yuxuan Liang, Zijun Guo, Qin Wang et al.WWW 2026
- Are Unreachable Nodes Truly Safe? Fully Eclipsing Monero's P2P Network!Ruisheng Shi, Jiaqi Zeng, Lina Lan, Shihan Zhang et al.CCS 2026
Builds on11
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- An Empirical Analysis of Anonymity in ZcashGeorge Kappos, Haaroon Yousaf, Mary Maller, Sarah MeiklejohnUSENIX Security 2018 · 171 citations
- A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer NetworkMuoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu et al.S&P 2020 · 126 citations
- Measurements, Analyses, and Insights on the Entire Ethereum Blockchain NetworkXi Tong Lee, Arijit Khan, Sourav Sen Gupta, Yu Hann Ong et al.WWW 2020 · 92 citations
- SABRE: Protecting Bitcoin against Routing AttacksMaria Apostolaki, Gian Marti, Jan Müller, Laurent VanbeverNDSS 2019 · 86 citations
Related papers
- On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by CryptocurrenciesPiyush Kumar Sharma, Devashish Gosain, Claudia DíazNDSS 2023
- On the Routing-Aware Peering against Network-Eclipse Attacks in BitcoinMuoi Tran, Akshaye Shenoi, Min Suk KangUSENIX Security 2021 · 28 citations
- SyncAttack: Double-spending in Bitcoin Without Mining PowerMuhammad Saad, Songqing Chen, David MohaisenCCS 2021 · 37 citations
- Partitioning Ethereum without Eclipsing ItHwanjo Heo, Seungwon Woo, Taeung Yoon, Min Suk Kang et al.NDSS 2023
- P2P Mixing and Unlinkable Bitcoin TransactionsTim Ruffing, Pedro Moreno-Sanchez, Aniket KateNDSS 2017 · 134 citations
