The Lightning Network (LN) has enjoyed rapid growth over recent years, and has become the most popular scaling solution for the Bitcoin blockchain. The security of the LN relies on the ability of the nodes to close a channel by settling their balances, which requires confirming a transaction on the Bitcoin blockchain within a pre-agreed time period. We study the susceptibility of the LN to mass exit attacks in case of high transaction congestion, in the presence of a small coalition of adversarial nodes that forces a large set of honest users to interact with the blockchain. We focus on two types of attacks: (i) The first is a zombie attack, where a set of k nodes become unresponsive with the goal of locking the funds of many channels for a period of time longer than what the LN protocol dictates. (ii) The second is a mass double-spend attack, where a set of k nodes attempt to steal funds by submitting many closing transactions that settle channels using expired protocol states; this causes many honest nodes to have to quickly respond by submitting invalidating transactions. We show via simulations that, under historically plausible congestion conditions, with mild statistical assumptions on channel balances, both attacks can be performed by a very small coalition. To perform our simulations, we formulate the problem of finding a worst-case coalition of k adversarial nodes as a graph cut problem. Our experimental findings are supported by theoretical justifications based on the scale-free topology of the LN.
翻译:闪电网络(LN)近年来发展迅速,已成为比特币区块链最流行的扩容方案。其安全性依赖于节点在预约定时间内通过比特币链上交易结算通道余额的能力。本文研究了在交易高度拥堵情况下,闪电网络面对由少数恶意节点组成的小规模联盟(迫使大量诚实用户与区块链交互)时,可能遭受的大规模退出攻击。我们重点分析两类攻击:(i)僵尸攻击:一组k个节点故意失联,旨在使多条通道资金被锁定超过闪电网络协议规定时间;(ii)大规模双花攻击:一组k个节点通过提交基于过期协议状态的结算交易来窃取资金,迫使大量诚实节点迅速提交无效交易以对抗。基于历史合理的拥堵条件,并采用关于通道余额的温和统计假设,仿真表明:一小撮联盟即可实施上述两种攻击。为执行仿真,我们将寻找最坏情况下k个恶意节点联盟的问题建模为图切割问题。实验结论得到了基于闪电网络无标度拓扑结构的理论论证支持。