Corruptive majority attacks, in which mining power is distributed among miners and an attacker attempts to bribe a majority of miners into participation in a majority attack, pose a threat to blockchains. Budish bounded the cost of bribing miners to participate in an attack by their expected loss as a result of attack success. We show that this bound is loose. In particular, an attack may be structured so that under equilibrium play by most miners, a miner's choice to participate only slightly affects the attack success chance. Combined with the fact that most of the cost of attack success is externalized by any given small miner, this implies that if most mining power is controlled by small miners, bribing miners to participate in such an attack is much cheaper than the Budish bound. We provide a scheme for a cheap corruptive majority attack and discuss practical concerns and consequences.
翻译:腐败多数攻击是一种威胁区块链的攻击方式,在这种攻击中,挖矿能力在矿工之间分布,攻击者试图贿赂大多数矿工参与多数攻击。Budish将贿赂矿工参与攻击的成本上限设定为攻击成功导致的预期损失。我们证明这一上限是宽松的。特别是,攻击可以设计为:在大多数矿工采取均衡策略的情况下,单个矿工参与攻击的选择对攻击成功概率的影响微乎其微。结合攻击成功的大部分成本由任何小型矿工外部化的事实,这意味着如果大多数挖矿能力由小型矿工控制,则贿赂矿工参与此类攻击的成本远低于Budish上限。我们提出了一种廉价腐败多数攻击的方案,并讨论了实际问题和后果。