Are Unreachable Nodes Truly Safe? Fully Eclipsing Monero's P2P Network!
Ruisheng Shi, Jiaqi Zeng, Lina Lan, Shihan Zhang, Bing Han, Xiapu Luo, Qishu Jin, Wenliang Du, Qin Wang
Abstract
Eclipse attacks isolate a blockchain node by monopolizing its network connections. Existing attacks on Monero (NDSS'25), Bitcoin (USENIX'15/21, S&P'20) and Ethereum (WWW'26) implicitly assume that the adversary can establish inbound connections, thereby excluding a large and practically dominant class of nodes: unreachable nodes operating behind NATs. Such nodes are widely believed to enjoy stronger networks. We challenge this assumption and show that unreachability does NOT imply the expected resilience! We present the first eclipse attacks tailored to unreachable nodes in Monero's P2P network. Our attacks require no inbound access to the victim. Instead, they first poison the peerlist of reachable nodes, which subsequently act as propagation relays to contaminate unreachable nodes'whitelists. The adversary then exploits Monero's built-in outbound connection refresh logic to evict benign neighbors and eventually monopolize all outbound connections. We instantiate this strategy in two attacks: Nyx, which targets long-running unreachable nodes and achieves a complete and persistent eclipse through network-wide poisoning; and Moros, a stealthier attack that exploits the bootstrapping phase to rapidly eclipse newly joined unreachable nodes. We ethically evaluate both attacks. Nyx is validated via large-scale simulations on a Monero network constructed using the SEED Emulator, while Moros is demonstrated on the Monero mainnet against controlled targets. Our results show that unreachable nodes can be reliably driven into stable, long-lived eclipse states. We also propose countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6ceebe23-ec33-47d0-bea7-8431e4d62fd7Builds on14
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer NetworkMuoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu et al.S&P 2020 · 126 citations
- SABRE: Protecting Bitcoin against Routing AttacksMaria Apostolaki, Gian Marti, Jan Müller, Laurent VanbeverNDSS 2019 · 86 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- SyncAttack: Double-spending in Bitcoin Without Mining PowerMuhammad Saad, Songqing Chen, David MohaisenCCS 2021 · 37 citations
Related papers
- Eclipse Attacks on Ethereum's Peer-to-Peer NetworkRuisheng Shi, Yuxuan Liang, Zijun Guo, Qin Wang et al.WWW 2026
- Eclipse Attacks on Monero's Peer-to-Peer NetworkRuisheng Shi, Zhiyuan Peng, Lina Lan, Yulian Ge et al.NDSS 2025
- On the Routing-Aware Peering against Network-Eclipse Attacks in BitcoinMuoi Tran, Akshaye Shenoi, Min Suk KangUSENIX Security 2021 · 28 citations
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 26 citations
- Partitioning Ethereum without Eclipsing ItHwanjo Heo, Seungwon Woo, Taeung Yoon, Min Suk Kang et al.NDSS 2023
