A 51% attack is a threat or intrusion targeting proof-of-work or proof-of-stack blockchains, carried out by one or more miners holding more than 50% of the mining hash rate of a blockchain. It is also known as a Goldfinger attack.
From the outset, it is important to remember that owning more than half of the nodes in a network theoretically confers the power to modify the blockchain.
Why should we fear and prevent the 51% attack?
A miner controlling more than 50% of the nodes in a network could hinder the confirmation of new transactions, thus disrupting payments between some or all users. Furthermore, they could revoke transactions executed under their control , potentially leading to double-spending. This is a vulnerability that consensus mechanisms such as proof-of-work aim to prevent.
A 51% attack is very dangerous because it means that the miner or group controlling more than 50% of a blockchain's hashing power has the ability to introduce a modified version of the blockchain at a specific point in the network. Theoretically, this modification is accepted by the network because that miner or group of miners holds control.
As for old transactions locked before the attack began, they are proving extremely difficult. They are difficult to modify even during a 51% attack. The older a transaction is, the more difficult it becomes to modify. Transactions prior to a certain checkpoint, where they become permanent in the Bitcoin blockchain, remain unalterable.
Is it possible for a minor to lead the 51 attack?
It is a very tricky task to carry out a 51% attack on a popular blockchain with a high participation rate. First, cybercriminals should be able to control more than 51% of the nodes and have previously created an alternative blockchain that can be inserted at the right time. Then they should outperform the mainnet.
The cost of doing this is one of the most important factors preventing a 51% attack. And then, for what interest would a majority investor undermine its own company?
Let's imagine the worst scenario
Bitcoin's enemies are as numerous as the stars. They constantly predict a perilous end for Satoshi Nakamoto 's cute little brainchild . Let's imagine they're actually on the right track. It will take at least two major mining pools forming an alliance to bring the project down. Indeed, to date, no single miner owns 51% of Bitcoin's nodes.
Last June, the three main mining pools by hash rate were:
- FoundryUSA, with 106,16 exahashes per second (EH/s), representing 29,3% of the total hash rate of the Bitcoin network.
- AntPool, with 90,28 EH/s, covering 24,9% of the total hash rate of the Bitcoin network.
- F2Pool, with 45,98 EH/s, constituting 12,67% of the network's total hash rate.
These three pools accounted for 66,87% of the network's hash rate, representing an impressive 242,42 EH/s. To match this hash rate, cybercriminals would need significantly more. Fixed costs would be around $7,9 billion, in addition to expenses related to hosting, maintenance, electricity, and cooling. Therefore, it is unlikely that major cryptocurrencies, such as Bitcoin, will fall victim to a 51% attack due to the prohibitive cost of acquiring such hashing power. 51% attacks are generally limited to cryptocurrencies with lower participation and hashing power.
What about Ethereum?
Make no mistake, when it comes to security, Ethereum is just as robust as Bitcoin.
Following its transition to proof-of-stake , a 51% attack on the Ethereum blockchain has become even more expensive. To carry out this attack, an individual or group would need to hold 51% of the ETH staked on the network. While someone could potentially possess such a large amount of ETH, it remains highly improbable.
According to Beaconchain , over 19,3 million ETH were at stake. Therefore, an entity would need to possess more than 9,8 million ETH (worth over $20 billion at the time of writing) to attempt an attack. Furthermore, once the attack is launched, the consensus mechanism would likely detect it and immediately reduce the staked ETH, imposing significant costs on the cybercriminal. However, the community could vote to restore the "honest" chain, resulting in the attacker losing all their ETH, their efforts having been in vain.
What are the challenges of such an attack?
The success of a 51% attack goes beyond financial considerations. In addition to a huge investment, a miner or group of miners seeking to compromise a network using a 51% attack must not only gain control of more than half of the network, but also manage to introduce the modified blockchain at a particularly strategic time. Even with a 51% or more majority of the network hash rate, they may find themselves unable to synchronize their own chain with the rate of block creation. And they may be unable to insert it before the production of new valid blocks by the blockchain network considered to be “honest.”
This maneuver is easier on smaller cryptocurrency networks, characterized by less participation and lower hash rates. On the other hand, large networks make it virtually impossible to introduce a tampered blockchain.
Basically, despite its name, it is not imperative to hold 51% of a network's mining power to trigger an attack. However, such an undertaking would have significantly reduced chances of success.
The consequences of a successful attack
If, by some unfortunate chance, such an attack were to succeed, it must be admitted that the community would be in for a rude awakening. First, the criminals would have the power to disrupt other users' transactions, cancel them, and reuse the same cryptocurrency. This vulnerability, known as double-spending , is akin to perfect digital forgery. It represents the fundamental cryptographic challenge that blockchain consensus mechanisms strive to address.
Furthermore, cybercriminals could implement a denial-of-service (DoS) attack. They could block the addresses of other miners for the duration of their control over the network. This tactic would prevent "honest" miners from regaining control before the rogue chain becomes permanently established.
Which nodes and cryptos are at risk of attack?
The choice of mining hardware is also a crucial parameter, as mining networks secured by application-specific integrated circuits ( ASICs ) are less vulnerable than those using graphics processing units ( GPUs ). Furthermore, their processing speed is significantly higher. Cloud mining services , such as NiceHash , which position themselves as "hash power brokers," theoretically offer the possibility of launching a 51% attack using only rented hash power. This is particularly concerning for smaller networks that rely exclusively on GPUs.
Among likely victims, Bitcoin Gold is a prime target for cybercriminals due to its status as a smaller cryptocurrency in terms of hash rate. Since June 2019, the Digital Currency Initiative at the Michigan Institute of Technology has identified, observed, or been informed of more than 40 51% chain reorganization attacks targeting Bitcoin Gold, Litecoin, and other smaller cryptocurrencies.
Here's the main thing to remember about the 51% attack
The 51% attack represents an implausible scenario where a miner acquires more than half of a blockchain's hashing power. Although incidents of this type occur in smaller networks, they generally end in failure in larger networks like Bitcoin, due to their high level of security.
This attack materializes when a group of miners takes control of more than 50% of a blockchain's mining hash rate. Attackers with majority control over the network can hinder the creation of new blocks, preventing other miners from finalizing their transactions. It is important to note that modifying historical blocks remains impossible due to the information chain firmly anchored in the Bitcoin blockchain. Only smaller networks are regularly the target of attempted 51% attacks.
Learn more about ZoneBitcoin
Subscribe to get the latest posts sent to your email.