118 / 691SELF

Selfish mining

Selfish mining strategically withholds discovered blocks. A miner publishes selectively to waste competitors' work and increase its share of accepted blocks.

Selfish mining changes publication strategy, not block validity. Outcomes depend on hashrate, propagation, tie handling and others' behavior; no single universal threshold guarantees profit.

After finding a valid block, the miner starts a private branch rather than announcing it immediately. Others keep working on the public tip without knowing that block. [Eyal and Sirer — Majority is not Enough]

The strategy tracks the gap between private and public branches. Depending on subsequent discoveries it extends the lead, releases blocks or abandons its private branch. [Eyal and Sirer — Majority is not Enough] [Sapirshtein, Sompolinsky & Zohar — Optimal Selfish Mining Strategies in Bitcoin]

Selective publication when branches draw level can trigger a race between two valid branches. Which branch other miners extend helps determine the outcome. [Eyal and Sirer — Majority is not Enough] [Bitcoin Developer Guide — Block Chain]

Blocks on the losing branch remain outside accepted history and their rewards do not apply. The aim is for honest miners to waste proportionally more work than the attacker. [Eyal and Sirer — Majority is not Enough] [Satoshi NakamotoBitcoin whitepaper]

Eyal and Sirer's model compares the share of rewards for accepted blocks with the share of hashrate. A larger relative share is not automatically greater net hourly profit; difficulty, time and costs also matter. [Eyal and Sirer — Majority is not Enough] [Sapirshtein, Sompolinsky & Zohar — Optimal Selfish Mining Strategies in Bitcoin]

In the basic model α is the attacker's hashrate share and γ the fraction of honest hashrate that mines on its branch during a tie. Changing γ changes the advantage threshold, so hashrate percentage alone is insufficient. [Eyal and Sirer — Majority is not Enough] [Sapirshtein, Sompolinsky & Zohar — Optimal Selfish Mining Strategies in Bitcoin]

Relay speed and relationships between pools can change tie advantage. Model parameters are neither universal measurements of the real network nor proof of a particular pool's behavior. [Eyal and Sirer — Majority is not Enough] [Sapirshtein, Sompolinsky & Zohar — Optimal Selfish Mining Strategies in Bitcoin]

Withholding is risky: the public branch can overtake the private one and the attacker loses its block rewards. Merely starting the strategy does not guarantee success. [Eyal and Sirer — Majority is not Enough]

A Full Node still rejects invalid transactions and excess issuance. Selfish mining exploits competition between valid branches and grants no authority to spend others' coins. [Satoshi NakamotoBitcoin whitepaper] [The Bitcoin Backbone Protocol] [Bitcoin Core v29.0 — validation]

Defense research examines block propagation, tie handling, incentives and detection. A stale block alone is not evidence of an attack: natural concurrent discoveries produce a similar outcome. [Eyal and Sirer — Majority is not Enough] [Bitcoin Developer Guide — Block Chain] [Sapirshtein, Sompolinsky & Zohar — Optimal Selfish Mining Strategies in Bitcoin]

For the clearest picture, read this entry together with Block propagation, Compact block relay, Nakamoto consensus, Sybil attack. The reverse links also lead from Block withholding attack.

DOC · 001Eyal and Sirer — Majority is not EnoughPrimaryDOC · 002Satoshi Nakamoto — Bitcoin whitepaperPrimaryDOC · 003The Bitcoin Backbone ProtocolPrimaryDOC · 004Bitcoin Developer Guide — Block ChainDocumentationDOC · 005Bitcoin Core v29.0 — validationDocumentationDOC · 006Sapirshtein, Sompolinsky & Zohar — Optimal Selfish Mining Strategies in BitcoinDocumentation
Source-first · No investment advice