SquirRL: Automating Attack Analysis on Blockchain Incentive Mechanisms with Deep Reinforcement Learning
Charlie Hou, Mingxun Zhou, Yan Ji, Phil Daian, Florian Tramèr, Giulia Fanti, Ari Juels
Abstract
—Incentive mechanisms are central to the functionality of permissionless blockchains: they incentivize participants to run and secure the underlying consensus protocol. Designing incentive-compatible incentive mechanisms is notoriously challenging, however. As a result, most public blockchains today use incentive mechanisms whose security properties are poorly understood and largely untested. In this work, we propose SquirRL, a framework for using deep reinforcement learning to analyze attacks on blockchain incentive mechanisms. We demonstrate SquirRL’s power by first recovering known attacks: (1) the optimal selfish mining attack in Bitcoin [56], and (2) the Nash equilibrium in block withholding attacks [18]. We also use SquirRL to obtain several novel empirical results. First, we discover a counterintuitive flaw in the widely used rushing adversary model when applied to multi-agent Markov games with incomplete information. Second, we demonstrate that the optimal selfish mining strategy identified in [56] is actually not a Nash equilibrium in the multi-agent selfish mining setting. In fact, our results suggest (but do not prove) that when more than two competing agents engage in selfish mining, there is no profitable Nash equilibrium . This is consistent with the lack of observed selfish mining in the wild. Third, we find a novel attack on a simplified version of Ethereum’s finalization mechanism, Casper the Friendly Finality Gadget (FFG) that allows a strategic agent to amplify her rewards by up to 30% . Notably, [12] shows that honest voting is a Nash equilibrium in Casper FFG; our attack shows that when Casper FFG is composed with selfish mining, this is no longer the case. Altogether, our experiments demonstrate SquirRL’s flexibility and promise as a framework for studying attack settings that have thus far eluded theoretical and empirical understanding.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8fd7dd9d-dad1-45b8-93bd-f4948a2fc72cCited by top-tier papers11
- Impact and User Perception of Sandwich Attacks in the DeFi EcosystemYe Wang, Patrick Zuest, Yaxing Yao, Zhicong Lu et al.CHI 2022 · 52 citations
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement LearningSoyoung Lee, Seongil Wi, Sooel SonWWW 2022 · 34 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Uncle Maker: (Time)Stamping Out The Competition in EthereumAviv Yaish, Gilad Stern, Aviv ZoharCCS 2023 · 19 citations
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos et al.USENIX Security 2026 · 7 citations
Builds on4
- Emergent Tool Use From Multi-Agent AutocurriculaBowen Baker, Ingmar Kanitscheider, Todor M. Markov, Yi Wu et al.ICLR 2020 · 751 citations
- On the Instability of Bitcoin Without the Block RewardMiles Carlsten, Harry A. Kalodner, S. Matthew Weinberg, Arvind NarayananCCS 2016 · 387 citations
- Be Selfish and Avoid Dilemmas: Fork After Withholding (FAW) Attacks on BitcoinYujin Kwon, Dohyun Kim, Yunmok Son, Eugene Y. Vasserman et al.CCS 2017 · 248 citations
- Nearly Optimal Robust Secret Sharing Against Rushing AdversariesPasin Manurangsi, Akshayaram Srinivasan, Prashant Nalini VasudevanCRYPTO 2020 · 13 citations
Related papers
- BunnyFinder: Finding Incentive Flaws for Ethereum ConsensusRujia Li, Mingfei Zhang, Xueqian Lu, Wenbo Xu et al.NDSS 2026 · 5 citations
- WeRLman: To Tackle Whale (Transactions), Go Deep (RL)Roi Bar Zur, Ameer Abu-Hanna, Ittay Eyal, Aviv TamarS&P 2023
- SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement LearningSalim Al Wahaibi, Myles Foley, Sergio MaffeisUSENIX Security 2023
- Power Adjusting and Bribery Racing: Novel Mining Attacks in the Bitcoin SystemShang Gao, Zecheng Li, Zhe Peng, Bin XiaoCCS 2019 · 81 citations
- Bitcoin Under Volatile Block Rewards: How Mempool Statistics Can Influence Bitcoin MiningRoozbeh Sarenche, Alireza Aghabagherloo, Svetla Nikova, Bart PreneelCCS 2025 · 1 citation
