SyncAttack: Double-spending in Bitcoin Without Mining Power
Muhammad Saad, Songqing Chen, David Mohaisen
摘要
The existing Bitcoin security research has mainly followed the security models in [22, 35], which stipulate that an adversary controls some mining power in order to violate the blockchain consistency property (i.e., through a double-spend attack). These models, however, largely overlooked the impact of the realistic network synchronization, which can be manipulated given the permissionless nature of the network. In this paper, we revisit the security of Bitcoin blockchain by incorporating the network synchronization into the security model and evaluating that in practice. Towards this goal, we propose the ideal functionality for the Bitcoin network synchronization and specify bounds on the network outdegree and the block propagation delay in order to preserve the consistency property. By contrasting the ideal functionality against measurements, we find deteriorating network synchronization reported by Bitnodes and a notable churn rate with 10% of the nodes arriving and departing from the network daily. Motivated by these findings, we propose SyncAttack, an attack that allows an adversary to violate the Bitcoin blockchain consistency property and double-spend without using any mining power. Moreover, during our measurements, we discover weaknesses in Bitcoin that can be exploited to reduce the cost of SyncAttack, deanonymize Bitcoin transactions, and reduce the effective network hash rate. We also observe events that suggest malicious nodes are exploiting those weaknesses in the network. Finally, we patch those weaknesses to mitigate SyncAttack and associated risks.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper8
- Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT ManipulationZheyuan He, Zihao Li, Ao Qiao, Xiapu Luo 等S&P 2024 · 被引用 21 次
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 被引用 4 次
- Eclipse Attacks on Monero's Peer-to-Peer NetworkRuisheng Shi, Zhiyuan Peng, Lina Lan, Yulian Ge 等NDSS 2025
- Eclipse Attacks on Ethereum's Peer-to-Peer NetworkRuisheng Shi, Yuxuan Liang, Zijun Guo, Qin Wang 等WWW 2026
- SoK: Decentralized Finance (DeFi) AttacksLiyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos 等S&P 2023
相关 Paper
- Revisiting Nakamoto Consensus in Asynchronous Networks: A Comprehensive Analysis of Bitcoin Safety and ChainQualityMuhammad Saad, Afsah Anwar, Srivatsan Ravi, David MohaisenCCS 2021 · 被引用 29 次
- Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better SecurityJannik Albrecht, Sébastien Andreina, Frederik Armknecht, Ghassan Karame 等S&P 2024 · 被引用 5 次
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 被引用 473 次
- Modeling the Impact of Network Connectivity on Consensus Security of Proof-of-Work BlockchainYang Xiao, Ning Zhang, Wenjing Lou, Y. Thomas HouINFOCOM 2020 · 被引用 52 次
- Tight Consistency Bounds for BitcoinPeter Gazi, Aggelos Kiayias, Alexander RussellCCS 2020
