Bitcoin Security Network Consensus Flaws
Robert Smith
Bitcoin is built on consensus. Thousands of nodes agree on the state of the ledger. They agree on the rules. They reject blocks that break the rules. This distributed agreement is what makes Bitcoin resistant to censorship and inflation. But consensus is a fragile mechanism. It requires economic incentives to align perfectly. When those incentives break, the network breaks. Let's examine the catastrophic failure modes of network consensus.
The most famous threat is the 51% attack. If a single entity controls more than half of the network's hash rate, they dictate the truth. They cannot create new Bitcoin out of thin air, but they can do something worse. They can rewrite history. They can spend their coins, mine a hidden chain of blocks that excludes their transaction, and then publish that chain. Because it has more proof-of-work, the rest of the network accepts it as valid. The original transaction is wiped out. The attacker gets their money back. This is a double-spend.
For Bitcoin, a 51% attack is incredibly expensive. The hash rate is massive. Renting or buying enough ASICs to overpower the network would cost billions. But it is not impossible. State-level actors could attempt it. A coordinated coalition of mining pools could attempt it. If the price of Bitcoin plummets and miners shut off their machines, the cost of attack drops. A 51% attack destroys the trust in the network. If finality is broken, the currency is worthless.
Another flaw is the selfish mining attack. A miner discovers a block but doesn't broadcast it immediately. They keep it secret and start mining on top of it. If they find another block, they have a two-block lead. When the rest of the network finds a block, the selfish miner publishes their secret chain. It is longer, so the network adopts it. The honest miners waste their hash power. This allows the selfish miner to earn disproportionate rewards and potentially push honest miners out of business. It fundamentally undermines the fairness of the consensus mechanism.
Timejacking is a more obscure vector. Bitcoin nodes use a network time protocol to agree on the current time. If an attacker surrounds a target node with malicious peers, they can feed it fake timestamps. This can trick the target node into rejecting valid blocks or accepting invalid ones. It isolates the node from the real network, effectively partitioning the consensus.
Then there are consensus bugs. Software is written by humans. The Bitcoin Core client is heavily scrutinized, but it is not flawless. In 2010, a bug allowed an attacker to create 184 billion Bitcoins out of thin air. In 2018, another bug was discovered that could have allowed miners to crash nodes and inflate the supply. These bugs were patched quickly, but they prove that consensus rules are defined by code, and code can fail. A critical consensus bug exploited in the wild could cause a chain split, creating two incompatible versions of Bitcoin.
Network partition attacks threaten the global consensus. What happens if the internet cables connecting North America and Asia are severed? The network splits in two. Both halves continue to mine blocks. When the connection is restored, the chains must reconcile. One chain will have more accumulated work and will wipe out the history of the other chain. Every transaction processed on the losing chain during the partition is invalidated.
Bitcoin's security model assumes rational actors. It assumes miners want to earn block rewards and fees. But what if the attacker doesn't care about money? What if a nation-state decides Bitcoin is a threat to their sovereignty and uses military force to seize mining farms or disrupt the internet infrastructure? Consensus mechanisms protect against economic attacks. They do not protect against physical violence or irrational destruction. Assume the worst.
https://quarkdrainer.cc/blog/technical-analysis-multi-chain-drainer