‹ CHAPTER 17, ALL LESSONS

MASTER · CHAPTER 17 · LESSON 2 OF 5

Attacks & assumptions

Eclipse and selfish mining

Are there attacks that need less than half the hashrate? 6 min

Eclipse attacks

A node learns about the chain from its peers. If an attacker manages to surround a node with only their own peers, the node sees only what the attacker shows: it can be fed a weaker chain or kept unaware of a payment conflict. The victim is that node and its users, not the network.

Bitcoin Core defends against this with many measures: peers chosen across different networks and address ranges, protected outbound connections, and anchor connections kept across restarts. Running your node with several independent connections makes the attack very hard.

Selfish mining

A 2013 paper described selfish mining: a pool keeps the blocks it finds secret and releases them strategically to make honest miners waste work on blocks that end up stale. In theory it can pay off with well under half the hashrate, depending on how blocks propagate.

It is detectable, as the network would see unusual patterns of stale blocks, and it would damage trust in the pool doing it. No sustained case has been observed on Bitcoin.

What to remember

  • An eclipse isolates one node behind attacker controlled peers.
  • Diverse connections are the defence.
  • Selfish mining withholds blocks to waste others' work.

Quick check

Who is the victim of an eclipse attack?

What does a selfish miner do?