2013/11/01 by Ittay Eyal, Emin Gun Sirer, Emin Gün Sirer +2 · 2 voices · 52 citations
Computer Science · #Blockchain #Blockchain Technology Applications and Security #Business #Compromise #Computer network #Computer science #Computer security #Cryptocurrency #Cryptography and Data Security #Currency #Economics #Finance #Incentive #Internet Traffic Analysis and Secure E-voting #Internet privacy #Law #Microeconomics #Monetary economics #Political science #Protocol (science) #Revenue #Sybil attack #cs.CR
paper · pdf · doi:10.48550/arxiv.1311.0243
published in arXiv (Cornell University) (Cornell University)
openalex publication_date 2013/11/01 · arxiv created 2013/11/15 · arxiv updated 2013/11/18 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/05
The Bitcoin cryptocurrency records its transactions in a public log called the blockchain. Its security rests critically on the distributed protocol that maintains the blockchain, run by participants called miners. Conventional wisdom asserts that the protocol is incentive-compatible and secure against colluding minority groups, i.e., it incentivizes miners to follow the protocol as prescribed. We show that the Bitcoin protocol is not incentive-compatible. We present an attack with which colluding miners obtain a revenue larger than their fair share. This attack can have significant consequences for Bitcoin: Rational miners will prefer to join the selfish miners, and the colluding group will increase in size until it becomes a majority. At this point, the Bitcoin system ceases to be a decentralized currency. Selfish mining is feasible for any group size of colluding miners. We propose a practical modification to the Bitcoin protocol that protects against selfish mining pools that command less than 1/4 of the resources. This threshold is lower than the wrongly assumed 1/2 bound, but better than the current reality where a group of any size can compromise the system.