Close Menu
    Trending
    • Bitcoin Market Caution Rises After Failed Breakout: Glassnode Data
    • Active Addresses Set New Record
    • Strive (ASST) Accumulates 13,600 Bitcoin Despite $393 Million Loss In First Six Months As Public Company
    • Elevate Your BTC by Integrating Bitcoin Everlight Shards Early
    • What Investors Need to Know
    • Grayscale Files For HYPE ETF – Here’s What To Know
    • These Key Ethereum Metrics Point To A Potential Liquidity Trap – What To Know
    • Bitcoin’s Quantum Risk May Be Real, But The Network Is Preparing: Report
    CryptoGate
    • Home
    • Bitcoin News
    • Cryptocurrency
    • Crypto Market Trends
    • Altcoins
    • Ethereum
    • Blockchain
    • en
      • en
      • fr
      • de
      • it
      • ja
    CryptoGate
    Home»Ethereum»Long-Range Attacks: The Serious Problem With Adaptive Proof of Work
    Ethereum

    Long-Range Attacks: The Serious Problem With Adaptive Proof of Work

    CryptoGateBy CryptoGateFebruary 15, 2026No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Our present proof of labor design, blockchain-based proof of work, is the second iteration of our try and create a mining algorithm that’s assured to stay CPU-friendly and immune to optimization by specialised {hardware} (ASICs) in the long run. Our first try, Dagger, tried to take the thought of memory-hard algorithms like Scrypt one step additional by creating an algorithm which is memory-hard to compute, however memory-easy to confirm, utilizing directed acyclic graphs (mainly, timber the place every node has a number of dad and mom). Our present technique takes a way more rigorous observe: make the proof of labor contain executing random contracts from the blockchain. As a result of the Ethereum scripting language is Turing-complete, an ASIC that may execute Ethereum scripts is by definition an ASIC for common computation, ie. a CPU – a way more elegant argument than “that is memory-hard so you may’t parallelize as a lot”. In fact, there are problems with “nicely, are you able to make particular optimizations and nonetheless get a big speedup”, however it may be argued that these are minor kinks to be labored out over time. The answer can also be elegant as a result of it’s concurrently an financial one: if somebody does create an ASIC, then others could have the inducement to search for varieties of computation that the ASIC can’t do and “pollute” the blockchain with such contracts. Sadly, nonetheless, there may be one a lot bigger impediment to such schemes basically, and one which is sadly to a point elementary: long-range assaults.

    A protracted-range assault mainly works as follows. In a conventional 51% assault, I put 100 bitcoins right into a contemporary new account, then ship these 100 bitcoins to a service provider in change for some instant-delivery digital good (say, litecoins). I anticipate supply (eg. after 6 confirmations), however then I instantly begin engaged on a brand new blockchain ranging from one block earlier than the transaction sending the 100 bitcoins, and put in a transaction as a substitute sending these bitcoins again to myself. I then put extra mining energy into my fork than the remainder of the community mixed is placing into the principle chain, and ultimately my fork overtakes the principle chain and thereby turns into the principle chain, so on the finish I’ve each the bitcoins and the litecoins. In a long-range assault, as a substitute of beginning a fork 6 blocks again, I begin the fork 60000 blocks again, and even on the genesis block.

    In Bitcoin, such a fork is ineffective, because you’re simply growing the period of time you would wish to catch up. In blockchain-based proof of labor, nonetheless, it’s a significant issue. The reason being that for those who begin a fork straight from the genesis block, then whereas your mining will probably be sluggish at first, after a couple of hundred blocks it is possible for you to to fill the blockchain up with contracts which can be very straightforward so that you can mine, however tough for everybody else. One instance of such a contract is just:

    i = 0
    whereas sha3(i) != 0x8ff5b6afea3c68b6cd68bd429b9b64a708fa2273a93ea9f9e3c763257affee1f:
    i = i + 1

    You already know that the contract will take precisely a million rounds earlier than the hash matches up, so you may calculate precisely what number of steps and the way a lot gasoline it would take to run and what the state will probably be on the finish instantly, however different folks could have no selection however to truly run by the code. An vital property of such a scheme, a obligatory consequence of the halting problem, is that it’s really unimaginable (as in, mathematically provably unimaginable, not Hollywood unimaginable) to assemble a mechanism for detecting such intelligent contracts within the common case with out really working them. Therefore, the long-range-attacker may fill the blockchain with such contracts, “mine” them, and persuade the community that it’s doing a large quantity of labor when it’s really simply taking the shortcut. Thus, after a couple of days, our attacker will probably be “mining” billions of occasions sooner than the principle chain, and thereby shortly overtake it.

    Discover that the above assault assumes little about how the algorithm really works; all it assumes is that the situation for producing a sound block depends on the blockchain itself, and there’s a big selection of variability in how a lot affect on the blockchain a single unit of computational energy can have. One resolution includes artificially capping the variability; that is accomplished by requiring a tree-hashed computational stack hint alongside the contract algorithm, which is one thing that can not be shortcut-generated as a result of even when you realize that the computation will terminate after 1 million steps and produce a sure output you continue to must run these million steps your self to provide all the intermediate hashes. Nevertheless, though this solves the long-range-attack drawback it additionally ensures that the first computation shouldn’t be common computation, however slightly computing tons and plenty of SHA3s – making the algorithm as soon as once more susceptible to specialised {hardware}.

    Proof of Stake

    A model of this assault additionally exists for naively carried out proof of stake algorithms. In a naively carried out proof of stake, suppose that there’s an attacker with 1% of all cash at or shortly after the genesis block. That attacker then begins their very own chain, and begins mining it. Though the attacker will discover themselves chosen for producing a block just one% of the time, they will simply produce 100 occasions as many blocks, and easily create an extended blockchain in that manner. Initially, I assumed that this drawback was elementary, however in actuality it’s a problem that may be labored round. One resolution, for instance, is to notice that each block should have a timestamp, and customers reject chains with timestamps which can be far forward of their very own. A protracted-range assault will thus have to suit into the identical size of time, however as a result of it includes a a lot smaller amount of forex models its rating will probably be a lot decrease. One other different is to require at the least some proportion (say, 30%) of all cash to endorse both each block or each Nth block, thereby completely stopping all assaults with lower than that p.c of cash. Our personal PoS algorithm, Slasher, can simply be retrofitted with both of those options.

    Thus, in the long run, it looks like both pure proof of stake or hybrid PoW/PoS are the way in which that blockchains are going to go. Within the case of a hybrid PoW/PoS, one can simply have a scheme the place PoS is used to resolve the difficulty described above with BBPoW. What we’ll go along with for Ethereum 1.0 could also be proof of stake, it is likely to be a hybrid scheme, and it is likely to be boring previous SHA3, with the understanding that ASICs won’t be developed since producers would see no profit with the approaching arrival of Ethereum 2.0. Nevertheless, there may be nonetheless one problem that arguably stays unresolved: the distribution mannequin. For my very own ideas on that, keep tuned for the following a part of this collection.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    CryptoGate
    • Website
    • Pinterest

    Related Posts

    Active Addresses Set New Record

    March 21, 2026

    These Key Ethereum Metrics Point To A Potential Liquidity Trap – What To Know

    March 21, 2026

    Policy Friday #6: SEC and CFTC Declare Most Crypto Assets Are Not Securities — What It Means for Enterprise Ethereum

    March 21, 2026

    XRP, Ethereum, Others Get SEC Shock: Analyst Says $4.7 Trillion Has Been Unlocked

    March 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Crypto Market Sees ‘Particularly Robust’ Q3 Performance – Report

    October 23, 2025

    SharpLink Doubles Down On Ethereum, Buys Another 56,533 ETH To Enhance Reserves

    August 28, 2025

    Europe’s Amundi Debuts First Ethereum-Based Tokenized Fund

    November 29, 2025

    Bitcoin Candlestick Structure That Led To Crash To Below $20,000 Last Cycle Just Appeared Again

    March 10, 2026

    Strategy ($MSTR) Spends $2.13 Billion To Buy 22,305 Bitcoin

    January 20, 2026
    Categories
    • Altcoins
    • Bitcoin News
    • Blockchain
    • Crypto Market Trends
    • Crypto Mining
    • Cryptocurrency
    • Ethereum
    About us

    Welcome to cryptogate.info — your trusted gateway to the latest and most reliable news in the world of cryptocurrency. Whether you’re a seasoned trader, a blockchain enthusiast, or just curious about the future of digital finance, we’re here to keep you informed and ahead of the curve.

    At cryptogate.info, we are passionate about delivering timely, accurate, and insightful updates on everything crypto — from market trends, new coin launches, and regulatory developments to expert analysis and educational content. Our mission is to empower you with knowledge that helps you navigate the fast-paced and ever-evolving crypto landscape with confidence.

    Top Insights

    How Low Can XRP Price Go After Dropping Below $3 Again?

    September 22, 2025

    Not A Fan Of Ethereum? ARK Invest’s CEO Cathie Wood Reveals Favorite Crypto

    September 30, 2025

    Coinbase’s Base faces brief outage

    August 5, 2025
    Categories
    • Altcoins
    • Bitcoin News
    • Blockchain
    • Crypto Market Trends
    • Crypto Mining
    • Cryptocurrency
    • Ethereum
    YouTube
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Impressum
    • About us
    • Contact us
    Copyright © 2025 CryptoGate All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.