Uncle Maker: (Time)Stamping Out The Competition in Ethereum
Aviv Yaish, Gilad Stern, Aviv Zohar
摘要
We present an attack on Ethereum's consensus mechanism which can be used by miners to obtain consistently higher mining rewards compared to the honest protocol. This attack is novel in that it does not entail withholding blocks or any behavior which has a non-zero probability of earning less than mining honestly, in contrast with the existing literature.
This risk-less attack relies instead on manipulating block timestamps, and carefully choosing whether and when to do so. We present this attack as an algorithm, which we then analyze to evaluate the revenue a miner obtains from it, and its effect on a miner's absolute and relative share of the main-chain blocks.
The attack allows an attacker to replace competitors' main-chain blocks after the fact with a block of its own, thus causing the replaced block's miner to lose all fees for the transactions contained within the block, which will be demoted from the main-chain. This block, although "kicked-out" of the main-chain, will still be eligible to be referred to by other main-chain blocks, thus becoming what is commonly called in Ethereum an uncle.
We proceed by defining multiple variants of this attack, and assessing whether any of these attacks has been performed in the wild. Surprisingly, we find that this is indeed true, making this the first case of a confirmed consensus-level manipulation performed on a major cryptocurrency.
Additionally, we implement a variant of this attack as a patch for Go Ethereum (geth), Ethereum's most popular client, making it the first consensus-level attack on Ethereum which is implemented as a patch. Finally, we suggest concrete fixes for Ethereum's protocol and implemented them as a patch for geth which can be adopted quickly and mitigate the attack and its variants.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Empirical Analysis of EIP-1559: Transaction Fees, Waiting Times, and Consensus SecurityYulin Liu, Yuxuan Lu, Kartik Nayak, Fan Zhang 等CCS 2022 · 被引用 78 次
- Blockchain CensorshipAnton Wahrstätter, Jens Ernstberger, Aviv Yaish, Liyi Zhou 等WWW 2024 · 被引用 60 次
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 被引用 4 次
- Maat: Analyzing and Optimizing Overcharge on Blockchain StorageZheyuan He, Zihao Li, Ao Qiao, Jingwei Li 等FAST 2025 · 被引用 3 次
- Mad-Dag: Protecting Blockchain Consensus From MEVRoi Bar Zur, Ittay Eyal, Aviv TamarS&P 2026 · 被引用 3 次
它引用的顶会 Paper12
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- On the Security and Performance of Proof of Work BlockchainsArthur Gervais, Ghassan O. Karame, Karl Wüst, Vasileios Glykantzis 等CCS 2016 · 被引用 1,668 次
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 等S&P 2020 · 被引用 607 次
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
- Lay Down the Common Metrics: Evaluating Proof-of-Work Consensus Protocols' SecurityRen Zhang, Bart PreneelS&P 2019 · 被引用 113 次
相关 Paper
- Forking the RANDAO: Manipulating Ethereum's Distributed Randomness BeaconÁbel Nagy, János Tapolcai, István András Seres, Bence LadóczkiCCS 2025 · 被引用 2 次
- Snapping Snap Sync: Practical Attacks on Go Ethereum Synchronising NodesMassimiliano Taverna, Kenneth G. PatersonUSENIX Security 2023
- Available Attestation: Towards a Reorg-Resilient Solution for Ethereum Proof-of-StakeMingfei Zhang, Rujia Li, Xueqian Lu, Sisi DuanUSENIX Security 2025
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 被引用 57 次
- Max Attestation Matters: Making Honest Parties Lose Their Incentives in Ethereum PoSMingfei Zhang, Rujia Li, Sisi DuanUSENIX Security 2024 · 被引用 20 次
