On the Instability of Bitcoin Without the Block Reward
Miles Carlsten, Harry A. Kalodner, S. Matthew Weinberg, Arvind Narayanan
Abstract
Bitcoin provides two incentives for miners: block rewards and transaction fees. The former accounts for the vast majority of miner revenues at the beginning of the system, but it is expected to transition to the latter as the block rewards dwindle. There has been an implicit belief that whether miners are paid by block rewards or transaction fees does not affect the security of the block chain. We show that this is not the case. Our key insight is that with only transaction fees, the variance of the block reward is very high due to the exponentially distributed block arrival time, and it becomes attractive to fork a "wealthy" block to "steal" the rewards therein. We show that this results in an equilibrium with undesirable properties for Bitcoin's security and performance, and even non-equilibria in some circumstances. We also revisit selfish mining and show that it can be made profitable for a miner with an arbitrarily low hash power share, and who is arbitrarily poorly connected within the network. Our results are derived from theoretical analysis and confirmed by a new Bitcoin mining simulator that may be of independent interest. We discuss the troubling implications of our results for Bitcoin's future security and draw lessons for the design of new cryptocurrencies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f1769e5f-9e4b-4007-b117-1cc6a6c604d7Cited by top-tier papers28
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
- Be Selfish and Avoid Dilemmas: Fork After Withholding (FAW) Attacks on BitcoinYujin Kwon, Dohyun Kim, Yunmok Son, Eugene Y. Vasserman et al.CCS 2017 · 248 citations
- REM: Resource-Efficient Mining for BlockchainsFan Zhang, Ittay Eyal, Robert Escriva, Ari Juels et al.USENIX Security 2017 · 124 citations
- The Gap GameItay Tsabary, Ittay EyalCCS 2018 · 119 citations
- MAD-HTLC: Because HTLC is Crazy-Cheap to AttackItay Tsabary, Matan Yechieli, Alex Manuskin, Ittay EyalS&P 2021 · 87 citations
Related papers
- Bitcoin Under Volatile Block Rewards: How Mempool Statistics Can Influence Bitcoin MiningRoozbeh Sarenche, Alireza Aghabagherloo, Svetla Nikova, Bart PreneelCCS 2025 · 1 citation
- BDoS: Blockchain Denial-of-ServiceMichael Mirkin, Yan Ji, Jonathan Pang, Ariah Klages-Mundt et al.CCS 2020 · 1 citation
- Modeling the Impact of Network Connectivity on Consensus Security of Proof-of-Work BlockchainYang Xiao, Ning Zhang, Wenjing Lou, Y. Thomas HouINFOCOM 2020 · 52 citations
- Power Adjusting and Bribery Racing: Novel Mining Attacks in the Bitcoin SystemShang Gao, Zecheng Li, Zhe Peng, Bin XiaoCCS 2019 · 81 citations
- Bitcoin vs. Bitcoin Cash: Coexistence or Downfall of Bitcoin Cash?Yujin Kwon, Hyoungshick Kim, Jinwoo Shin, Yongdae KimS&P 2019 · 51 citations
